Monitor vulnerabilities that affect your stack. Sign up free to get alerts when software you use is affected.

CVE Vulnerabilities - 16 February 2026

RSS

90 vulnerabilities published on 16 February 2026

Severity:
SOLIDWORKS eDrawings: Malicious EPRT files can execute arbitrary code
CVE-2026-1334
If you use SOLIDWORKS eDrawings, be aware that a vulnerability in the software can allow an attacker to run malicious code on your computer. This can happen when opening a specially crafted EPRT file....
7.8
SOLIDWORKS eDrawings Uninitialized Variable Error when Opening Certain Files
CVE-2026-1333
Certain versions of SOLIDWORKS eDrawings can be tricked into executing malicious code when opening a specially designed file. This could lead to unauthorized actions on your computer. Update to the la...
7.8
Mattermost Desktop App: Malicious Server Can Run Executable Code
CVE-2026-1046
If you use the Mattermost Desktop App, a malicious Mattermost server can trick you into running arbitrary code on your computer if you click on certain help links. This is a serious security risk. Upd...
7.6
Perl Crypt::URandom versions 0.41-0.54 may crash if given incorrect input
CVE-2026-2474
A bug in Perl's Crypt::URandom module can cause a crash if the application is given an incorrect length for random data. This issue is most likely to affect applications that pass untrusted input to t...
7.5
Red Hat Go Library Security Update: Remote Code Execution Risk
RHSA-2026:2706
A security update is available for the Go library on Red Hat systems, which fixes a flaw that could allow an attacker to execute code remotely. This update is recommended for all users to install, as ...
7.5
Free5GC PFCP UDP Endpoint Denial of Service
CVE-2026-2525
A vulnerability in Free5GC's PFCP UDP Endpoint can be exploited remotely, causing a denial of service. This means the system may become unresponsive or crash. Update to the latest version of Free5GC t...
5.5
Open5GS: Remote Denial of Service via MME Component
CVE-2026-2524
A flaw in Open5GS 2.7.6 can allow an attacker to remotely take down the system. This could happen if an attacker exploits a published vulnerability in the MME component. Businesses using Open5GS 2.7.6...
5.5
Open5GS 2.7.6: Assertion Error Allows Remote Attack
CVE-2026-2523
A security weakness in Open5GS versions up to 2.7.6 can be exploited by hackers to access or disrupt the system remotely. This means an attacker can potentially take control of or crash the system. We...
5.5
Zhanghuanhao Library System 1.1.1: Unrestricted Access to User Data
CVE-2026-2549
A security issue was found in Zhanghuanhao Library System version 1.1.1 that could allow an attacker to access sensitive information without permission. This is a significant concern because it could ...
6.9
LuLu UI up to 3.0.0 allows remote attackers to run malicious commands
CVE-2026-2544
The LuLu UI up to version 3.0.0 has a security flaw that lets hackers remotely execute unauthorized system commands. This means a hacker could potentially take control of your system or steal sensitiv...
6.9
Tosei Self-service Washing Machine 4.02 Can Be Hacked Remotely
CVE-2026-2533
A bug in the Tosei Self-service Washing Machine's software can be exploited by a hacker to remotely access and control the machine. This could allow unauthorized access to sensitive information and po...
6.9
Wavlink Router Allows Remote Attackers to Overwrite Memory
CVE-2026-2567
A security issue has been found in the Wavlink WL-NU516U1 router. Attackers can potentially take control of the device by sending a specially crafted request to the router, which could let them access...
7.3
Wavlink WL-NU516U1: Firmware URL Manipulation Can Cause Crash
CVE-2026-2566
A security flaw in the Wavlink WL-NU516U1 device's management interface allows an attacker to remotely crash the device by manipulating a specific setting. This can happen if the device is not properl...
7.3
Smoothwall Express: Malicious Script Injection via URL Filter
CVE-2019-25379
Smoothwall Express has a security weakness that allows hackers to inject malicious code into users' browsers. This can happen when a user visits a website that sends a specific request to the Smoothwa...
5.3
SmarterMail allows attackers to inject malicious scripts via email
CVE-2026-26930
SmarterMail's email software has a security flaw that lets attackers inject malicious code into emails. This could allow them to take control of your email account or steal sensitive information. Upda...
7.2
Comfast CF-E4: Unauthenticated Remote Command Injection via HTTP Request
CVE-2026-2537
A security flaw in Comfast CF-E4 allows an attacker to execute unauthorized commands on the device by sending a malicious request, potentially allowing them to access or manipulate sensitive data. Thi...
5.1
Total VPN on Windows May Allow Unwanted Programs to Run
CVE-2026-2542
A flaw in Total VPN 0.5.29.0 on Windows could allow an attacker to run unauthorized programs on a user's computer. This could happen if a user interacts with the Total VPN service in a certain way. We...
7.3
Notepad2 for Windows: Uncontrolled Search Path Leads to Local Attack
CVE-2026-2538
A security issue affects Notepad2 4.2.22 to 4.2.25 on Windows. An attacker with local access can potentially exploit this flaw to execute malicious code. Users are advised to update to a fixed version...
7.3
Wavlink Router's Admin Feature Can Be Abused Remotely
CVE-2026-2565
A security flaw in a Wavlink router's admin feature can be exploited remotely, potentially allowing an attacker to take control of the router. This could happen if the router's software is not updated...
6.6
Pretix Exposes Sensitive System Information in Emails
CVE-2026-2452
Pretix email templates can leak sensitive system info to attackers. Anyone with access to the backend can create malicious email templates that reveal database passwords and API keys. To stay safe, up...
7.5
Pretix exposes sensitive system data through emails
CVE-2026-2451
A bug in Pretix's email placeholder feature allowed attackers to extract sensitive system information, including passwords and API keys. This was possible through specially crafted placeholder names. ...
7.5
Kodbox Media File Preview Plugin Allows Remote Code Execution
CVE-2026-2560
A security flaw in Kodbox's Media File Preview Plugin can allow hackers to execute malicious code on a website, potentially leading to data breaches or unauthorized access. This vulnerability affects ...
5.3
GeekAI Download Function Allows Hackers to Execute Malicious Requests
CVE-2026-2558
GeekAI versions up to 4.2.4 have a security flaw in their Download function that allows hackers to trick the server into executing malicious requests. This could be exploited remotely, and exploit cod...
5.3
CSKefu MediaController Vulnerability Allows Remote Attack
CVE-2026-2556
A security flaw in CSKefu version 8.0.1 and earlier can let attackers trick the server into performing unauthorized actions. This could happen if a hacker sends a specially crafted request to the CSKe...
5.3
Tushar-2223 Hotel Management System SQL Injection Flaw
CVE-2026-2553
A bug in the Tushar-2223 Hotel Management System allows hackers to inject malicious code into the system by manipulating user input, potentially giving them access to sensitive data. This affects user...
5.3