Monitor vulnerabilities that affect your stack. Sign up free to get alerts when software you use is affected.

CVE Vulnerabilities - 18 February 2026

RSS

331 vulnerabilities published on 18 February 2026

Severity:
Keybase.io WordPress Plugin Allows Unauthorized Settings Changes
CVE-2026-1072
The Keybase.io Verification plugin for WordPress has a security flaw that lets attackers trick site administrators into making unwanted changes to the plugin settings. This could lead to unauthorized ...
4.3
Tickera Plugin Allows Attackers to Change Event Status
CVE-2025-12356
The Tickera plugin for WordPress doesn't properly check who can change event statuses. This means a hacker with a subscriber-level account or higher can change event statuses without permission. Updat...
4.3
EmailKit Plugin Allows Unapproved Changes to Posts
CVE-2026-1925
A security issue in the EmailKit plugin for WordPress allows attackers to modify post titles, including posts, pages, and custom post types, without permission. This could lead to unauthorized changes...
4.3
Order Splitter for WooCommerce plugin: Unauthorized access to order data
CVE-2025-12075
Authenticated users with Subscriber-level access and above can view information about other users' orders. This is due to a mistake in the plugin's code, specifically on the 'wos_troubleshooting' endp...
4.3
Frontend User Notes plugin allows attackers to modify notes
CVE-2025-12071
The Frontend User Notes plugin for WordPress is at risk. An attacker with a Subscriber-level account or above can modify notes that belong to other users. To fix this, update the plugin to version 2.1...
4.3
WP All Export plugin allows unauthorized access to sensitive data download
CVE-2026-1582
The WP All Export plugin for WordPress is vulnerable to unauthorized access to sensitive data files. This means that attackers can download sensitive information, such as personal data or business rec...
3.7
OpenClaw: Stale Sandboxes Reused Due to Config Order Change
CVE-2026-27007 GHSA-xxvh-5hwj-42pp
OpenClaw, a sandboxing tool, has a bug where it mistakenly treats order changes in configuration arrays as no changes. This can lead to old sandbox containers being reused, which can cause issues. To ...
4.8
QEMU UEFI Virtual Device Leaks Sensitive Information
CVE-2025-8860
A flaw in QEMU's UEFI virtual device can leak sensitive information from the guest operating system, compromising its security. This occurs when the guest writes to a certain register, causing the dev...
3.3
The Silver Searcher (2.2.0) Crashes on Malicious Input
CVE-2026-2642
A bug in The Silver Searcher, a code search tool, can cause it to crash if it's given certain types of input. This could potentially allow an attacker to make the tool malfunction, but it requires the...
4.8
Universal-ctags Allows Uncontrolled Recursion on Local Host
CVE-2026-2641
A flaw in the universal-ctags ctags tool allows an attacker to cause the tool to enter an infinite loop on the local system. This could potentially be exploited by a malicious actor. Users should upda...
4.8
WP-DownloadManager Plugin Allows Attackers to Access Server Files
CVE-2026-2419
The WP-DownloadManager plugin for WordPress is vulnerable to a security risk that allows attackers to access sensitive files on the server if they have an administrator account. This is due to a mista...
2.7
Unauthorized Email Plugin Installation in YayMail for WooCommerce
CVE-2026-1831
The YayMail plugin for WooCommerce is insecure, allowing an attacker with manager-level access to install and activate a different email plugin without permission. This could lead to malicious email s...
2.7
ChaiScript, up to 6.1.0, Exposes Data After It's Been Freed
CVE-2026-2656
A security flaw in ChaiScript, a JavaScript-like scripting language, can allow an attacker with local access to access data that has already been deleted. This could lead to unpredictable behavior or ...
2.0
Google Chrome 120: Fingerprinting Exposes User Data
CVE-2026-26995 GHSA-rrxv-pmq9-x67r
A security issue in Chrome 120 allows websites to potentially identify users by their browser configuration. This affects users who have a non-default browser fingerprint. To protect user data, update...
2.3
filippo.io/edwards25519 MultiScalarMult produces incorrect or undefined results
CVE-2026-26958 GHSA-fw7p-63qq-7hpr
The filippo.io/edwards25519 library has a bug in its MultiScalarMult function. If you use this function with a point that's not the default or zero value, it might produce incorrect results. This is a...
1.7
Duplicate Vulnerability in Unknown Software
CVE-2025-13965
This is a duplicate report of a known vulnerability, so there's no new information to worry about. You should use the original report instead. If you've already taken steps to address the original iss...
Do not use this vulnerability number, use CVE-2025-12500 instead
CVE-2025-13933
This vulnerability was marked as a duplicate of CVE-2025-12500. To avoid confusion, do not use this number and instead reference CVE-2025-12500. All information related to this duplicate number has be...
Incorrect Vulnerability Report Issued in Error
CVE-2025-13602
This report was mistakenly sent and has no actual security issue. It has been removed to prevent confusion. No action is needed.
Linux Kernel: SMB Client Data Corruption Risk
CVE-2026-23230
A bug in the Linux kernel's SMB client could cause data corruption. This happens when multiple threads access and change the same data simultaneously, potentially leading to incorrect results. To fix ...
Linux Kernel: Hangs with OpenSSL Benchmark with Virtio-Crypto
CVE-2026-23229
A Linux kernel issue causes OpenSSL benchmark tests with multiple processes to hang when using the virtio-crypto device. This has been fixed in the latest kernel update. If you're using the virtio-cry...
Linux Kernel: SMB Server Connection Leak Fixed
CVE-2026-23228
A fix has been made to prevent a rare situation where a Linux server's count of active network connections could become incorrect. This could potentially lead to issues with connection tracking and ma...
Exynos Virtual Display Driver Memory Allocation Issue Fixed
CVE-2026-23227
A bug in the Exynos Virtual Display driver for Linux could have caused problems with memory allocation and deallocation. This could lead to unexpected behavior or crashes, especially in situations wit...
Linux Kernel: Potential Data Corruption from Task Exit
CVE-2026-23225
A Linux kernel bug could cause data corruption when a task exits, potentially leading to system instability. This issue has been fixed in a recent update. Upgrade your Linux kernel to the latest versi...
Linux Kernel: Uninitialized File Access When Mounting Directly
CVE-2026-23224
A bug in the Linux kernel's file system could cause it to access memory that hasn't been properly initialized. This can happen when using a specific option to mount a file system directly. To fix this...
Linux Kernel xfs: Fix Crash from Incorrect Block Owner Check
CVE-2026-23223
A security issue has been fixed in the Linux kernel's xfs file system. This issue could have caused a crash if the system was handling certain file operations. The fix ensures the correct order of ope...