Monitor vulnerabilities that affect your stack.
Sign up free to get alerts when software you use is affected.
CVE Vulnerabilities - 16 February 2026
RSS90 vulnerabilities published on 16 February 2026
Severity:
MindsDB's File Upload Function Allows Remote Attackers to Forge Requests
CVE-2026-2531
GHSA-6xw9-2p64-7622
MindsDB's file upload feature has a security flaw that could let attackers trick the server into making unintended requests. This could happen remotely, without needing direct access to the server. Up...
2.1
OpenCC JFlow Workflow Engine Allows Remote XML Injection Attack
CVE-2026-2536
A security issue exists in OpenCC JFlow, a workflow management tool, that can be exploited by an attacker to inject malicious XML code remotely. This could potentially lead to unauthorized data access...
5.3
Smoothwall Express: Attackers Can Inject Malicious Code in Browser
CVE-2019-25395
A security issue in Smoothwall Express allows attackers to inject malicious code into the browser of users who access the preferences page, potentially leading to unauthorized access or data theft. Th...
5.3
Smoothwall Express: Malicious Scripts Can Be Injected via Web Interface
CVE-2019-25394
The Smoothwall Express web interface has multiple security weaknesses that allow hackers to inject malicious code into users' web browsers. This could lead to unauthorized access to sensitive informat...
5.3
Smoothwall Express: Malicious Code Injection Through Web Request
CVE-2019-25393
Attackers can inject malicious scripts into Smoothwall Express 3.1-SP4-polar-x86_64-update9 by sending a specially crafted web request, potentially allowing them to take control of user sessions or st...
5.1
Smoothwall Express exposes sensitive data to malicious scripts
CVE-2019-25392
Smoothwall Express 3.1-SP4-polar-x86_64-update9 has a security weakness that lets hackers inject malicious code into legitimate websites. Unprotected users may have their browsers hijacked, allowing u...
5.1
Smoothwall Express Admin Interface Cross-Site Scripting Flaw
CVE-2019-25390
Smoothwall Express's admin interface has a security flaw that could allow hackers to inject malicious code into the system, potentially taking control of administrator sessions. This issue affects adm...
4.8
Smoothwall Express Allows Unauthenticated Script Injection via User Input
CVE-2019-25389
An attacker can inject malicious scripts into Smoothwall Express by manipulating user input, potentially allowing them to execute arbitrary JavaScript in users' browsers. This could lead to unauthoriz...
5.1
Smoothwall Express: Unauthenticated Attackers Can Inject Malicious Scripts
CVE-2019-25388
The Smoothwall Express firewall's web interface has a security flaw that allows hackers to inject malicious code into users' web browsers without needing a password. This could lead to unauthorized ac...
5.1
Smoothwall Express 3.1-SP4 allows attackers to inject malicious scripts
CVE-2019-25387
A security issue in Smoothwall Express 3.1-SP4 allows hackers to inject harmful code into websites visited by users who interact with the affected system. This could lead to unauthorized actions being...
5.1
Smoothwall Express: Vulnerability Allows Malicious Script Injection
CVE-2019-25386
Smoothwall Express has a security flaw that allows hackers to inject malicious code into users' browsers if they visit a specially crafted website. This can lead to unauthorized access to sensitive in...
5.1
Smoothwall Express: Malicious scripts can be injected into users' browsers
CVE-2019-25385
An attacker can trick users into running malicious code in their web browser, potentially stealing sensitive session data. This happens when the system doesn't properly filter certain inputs. To prote...
5.1
Smoothwall Express: Unvalidated Input in Web Interface
CVE-2019-25384
An attacker can inject malicious scripts into the web interface of Smoothwall Express, potentially allowing them to control users' browsers. This can happen when an attacker sends specially crafted re...
5.1
Smoothwall Express: Malicious scripts can be injected through web form entries
CVE-2019-25383
Smoothwall Express has a security flaw that allows hackers to inject malicious scripts into your web browser if you fill out certain forms on the Smoothwall Express website. This could allow the hacke...
5.1
Smoothwall Express: Malicious Scripts Can Run in Users' Browsers
CVE-2019-25382
An attacker can inject malicious scripts into Smoothwall Express by sending a specially crafted request to the time.cgi endpoint. This can allow the attacker to run code in users' browsers without the...
5.1
Smoothwall Express: Malicious Scripts Injected via Web Interface
CVE-2019-25381
The Smoothwall Express web interface has a security weakness that allows hackers to inject malicious code into a user's web browser if they submit a specially crafted request. This could potentially a...
5.1
Smoothwall Express: Malicious Scripts Can Be Injected via DHCP Configuration
CVE-2019-25380
A flaw in the Smoothwall Express configuration tool allows hackers to inject malicious scripts into user browsers. This can happen when a user visits a specially crafted webpage. To protect your syste...
5.1
Smoothwall Express Proxy Configuration Page Allows Malicious Script Injection
CVE-2019-25378
An attacker can inject malicious scripts into the Smoothwall Express proxy configuration page, potentially allowing them to steal data or take control of users' browsers. This happens when a user acce...
5.1
Kubysoft: Malicious Script Injection in Node Procedures
CVE-2025-59905
Kubysoft's node procedure endpoint can inject malicious scripts into users' browsers, allowing attackers to steal sensitive info or take control of user sessions. This happens when malicious data is p...
4.8
LigeroSmart 6.1.26: Cross-site scripting in AgentDashboard
CVE-2026-2547
An attacker can inject malicious code into LigeroSmart's dashboard by manipulating certain inputs, potentially allowing them to steal sensitive information or take control of user sessions. This vulne...
5.1
LigeroSmart Index Page XSS Vulnerability - Remote Attack Possible
CVE-2026-2546
A weakness in LigeroSmart's index page makes it possible for hackers to inject malicious code into the page, potentially allowing them to steal sensitive information or take control of your system. Th...
5.1
LigeroSmart up to 6.1.26 allows remote attackers to inject malicious code
CVE-2026-2545
A vulnerability in LigeroSmart's ticket search function allows an attacker to inject malicious code. This could happen when a user interacts with the system in a specific way. Update to the latest ver...
5.1
Pretix Emails Can Leverage Customer Data to Expose System Details
CVE-2026-2415
GHSA-r8p8-qw9w-j9qv
Pretix, a ticketing software, can mistakenly reveal sensitive information about its system configuration through emails, potentially exposing database passwords or API keys. Users of the software can ...
7.5
Mattermost Fails to Protect Sensitive User Data in Websocket Messages
CVE-2025-13821
GHSA-pp9j-pf5c-659x
Versions of Mattermost up to 11.1.2, 10.11.9, and 11.2.1 contain a security flaw that allows attackers to steal sensitive information like passwords and two-factor authentication secrets. Affected use...
5.7
CSKefu File Upload Function Allows Remote Code Execution
CVE-2026-2557
A security weakness in CSKefu's file upload feature allows an attacker to inject malicious code, potentially causing harm to your website or customers. This weakness can be exploited remotely, so it's...
5.1