Monitor vulnerabilities that affect your stack.
Sign up free to get alerts when software you use is affected.
CVE Vulnerabilities - 15 February 2026
RSS33 vulnerabilities published on 15 February 2026
Severity:
OPNsense 19.1: Attackers can inject malicious JavaScript in user browsers
CVE-2019-25370
OPNsense 19.1 is affected by a security issue that allows attackers to inject malicious code into users' web browsers. This can happen if an attacker sends a specially crafted request to a specific pa...
5.1
Micca KE700 Car Alarm System Sends Sensitive Info Unencrypted
CVE-2026-2539
The Micca KE700 car alarm system sends sensitive information, like authentication details, in plain text over the air. This makes it possible for an attacker with the right equipment to intercept and ...
5.7
OPNsense 19.1: Malicious scripts can be injected via firewall rule editing
CVE-2019-25373
A security issue in OPNsense 19.1 allows an attacker to inject malicious scripts into the browsers of other users who view firewall rule pages. This can happen if an attacker is authenticated and subm...
5.1
OPNsense allows attackers to inject malicious scripts via system settings
CVE-2019-25369
A vulnerability in OPNsense's system settings allows attackers to inject malicious scripts that can be executed when an authenticated user views the settings. This means that if an attacker can trick ...
5.1
OPNsense 19.1 allows malicious script injection via diag_backup.php
CVE-2019-25368
An attacker can inject malicious scripts into OPNsense 19.1's diag_backup.php endpoint, allowing them to execute code in the context of an administrator session. This could enable unauthorized access ...
4.8
ArangoDB Community Edition: Unauthenticated JavaScript Injection through Web Interface
CVE-2019-25367
ArangoDB's web admin interface has a weakness that allows attackers to inject malicious scripts into users' browsers, potentially stealing sensitive information or taking control of the user's session...
4.8
CGA-3mhf-vgh6-9vg5
CGA-3mhf-vgh6-9vg5
CGA-3mhf-vgh6-9vg5