Monitor vulnerabilities that affect your stack. Sign up free to get alerts when software you use is affected.

CVE Vulnerabilities - 18 February 2026

RSS

331 vulnerabilities published on 18 February 2026

Severity:
LibreNMS Stored Cross-Site Scripting in Custom OID Unit Field
CVE-2026-27016 GHSA-fqx6-693c-f55g
LibreNMS's Custom OID feature is vulnerable to a type of cyber attack called Stored Cross-Site Scripting. This means that a malicious script can be injected into the system, potentially allowing an at...
5.4
Unauthenticated users can execute malicious code on WordPress sites with SiteOrigin Widgets Bundle
CVE-2026-2127
A security flaw in the SiteOrigin Widgets Bundle plugin for WordPress allows attackers to execute unauthorized code on sites using the plugin, potentially leading to data theft or site compromise. To ...
5.4
Delinea Cloud Suite: SQL Attack Risk Through Malformed Input
CVE-2025-12812
Delinea's Cloud Suite and Privileged Access Service contain a security weakness that could allow an attacker to inject malicious SQL code. This could lead to unauthorized access to sensitive data or s...
5.3
Chrome Parrot in uTLS Can Be Identified by Attackers
CVE-2026-27017 GHSA-7m29-f4hw-g2vx
A bug in Chrome's behavior within uTLS can reveal a user's browser type to attackers, even when they're trying to hide it. This happens when using a specific encryption method called GREASE ECH. To pr...
2.3
Tsinghua Unigroup Archives System Allows Remote File Access
CVE-2026-2672
A security flaw in the Tsinghua Unigroup Archives System lets hackers access and download sensitive files on your system from anywhere. This is a serious issue because it allows attackers to access an...
5.3
Nokogiri's XML Parsing Fails on Invalid Input, Disrupts SAML Signature Validation
GHSA-wx95-c6cv-8532
Nokogiri, a popular XML parsing library, has a bug that can cause it to accept invalid XML, which can allow attackers to bypass security checks in some systems. This can lead to security issues in cer...
5.3
Rongzhitong Visual Integrated Command and Dispatch Platform Allows Remote Access
CVE-2026-2667
A security issue in Rongzhitong Visual Integrated Command and Dispatch Platform could allow hackers to access sensitive data remotely. This means that someone could potentially gain unauthorized acces...
5.5
OpenClaw CLI: Unintended Process Termination on Shared Hosts
CVE-2026-27486 GHSA-jfv4-h8mc-jcp8
The OpenClaw CLI process cleanup feature can accidentally kill other processes on a shared host if their names match a pattern. This could cause unexpected downtime or data loss. To fix this, the Open...
4.3
Doruk Wispotter Password Guessing Attack Allowed, Data Theft Risk
CVE-2025-7630
A flaw in Wispotter allows hackers to guess passwords multiple times, potentially giving them access to sensitive information. This affects all versions of Wispotter up to v2025.10.08.1, so you should...
5.3
WordPress RegistrationMagic Plugin Allows Unauthorized Paid Registration
CVE-2025-14444
The RegistrationMagic plugin for WordPress does not properly verify payment information, allowing attackers to complete paid registrations without actually paying. This could allow unauthorized users ...
5.3
WordPress User Submitted Posts plugin allows unauthorized category changes
CVE-2026-2126
The User Submitted Posts plugin for WordPress has a flaw that lets attackers change the category of a post without permission. This could allow attackers to put posts in restricted categories. Update ...
5.3
Business Directory Plugin for WordPress: Unauthorized Changes Possible
CVE-2026-1656
The Business Directory Plugin for WordPress, used by many sites, has a security flaw that lets anyone modify listing information without needing a password. This could lead to fake or incorrect busine...
5.3
YayMail – WooCommerce Email Customizer plugin: Unauthorized License Deletion
CVE-2026-1938
If an attacker with Shop Manager-level access gets the necessary code, they can delete the plugin's license key, which could cause the plugin to stop working. This affects the YayMail – WooCommerce Em...
5.3
Context Blog Theme for WordPress Exposes Sensitive Posts Data
CVE-2025-12074
The Context Blog theme for WordPress, versions 1.2.5 and earlier, allows unauthorized users to view sensitive posts, including password-protected, private, or draft content. This means that sensitive ...
5.3
Splunk Enterprise: Unauthorized access to SAML configurations
CVE-2026-20144
Splunk Enterprise users with certain permissions may be able to see sensitive SAML configuration details in log files. This could allow an attacker to gain unauthorized access to your system. Update t...
4.9
Splunk Enterprise: Exposed RSA access keys in internal index
CVE-2026-20142
A user with certain access rights in a Splunk Search Head Cluster deployment can view sensitive RSA access keys in plain text. This is a concern because it could allow unauthorized access to your syst...
4.9
Splunk Enterprise: Exposure of sensitive Duo authentication keys
CVE-2026-20138
Some users with access to a specific Splunk index can view sensitive Duo authentication keys, which could be misused to access accounts. This affects specific versions of Splunk Enterprise. To protect...
4.9
Bookster WordPress Plugin Exposes Administrator Data
CVE-2025-8781
The Bookster WordPress plugin contains a security flaw that allows attackers to extract sensitive data from the database if they have Administrator access. This is a concern for businesses that rely o...
4.9
InvoicePlane: Attacker Can Steal Admin Session with Malicious Invoice
CVE-2026-25596
A hacker can inject malicious code into InvoicePlane's admin panel, stealing sensitive information or taking control of the system when an admin views an invoice with the malicious code. This only aff...
4.8
InvoicePlane: Malicious Code Can Be Injected into Invoices
CVE-2026-25595
A security flaw in InvoicePlane 1.7.0 allows attackers to inject malicious code into invoices, which can be executed by other administrators. This could lead to unauthorized access or data theft. Upda...
4.8
InvoicePlane 1.7.0: Malicious Names Can Harm Admins
CVE-2026-25594
A security issue in InvoicePlane 1.7.0 lets attackers inject malicious code into the application, which can affect administrators. This can happen when an administrator creates a new family with a spe...
4.8
LibreNMS Port Group Name Stored Cross-Site Scripting Risk
CVE-2026-26992 GHSA-93fx-g747-695x
LibreNMS has a security issue that allows attackers with admin privileges to inject malicious code into the system. This can happen when an attacker creates a port group with a specially crafted name....
5.1
LibreNMS Stored Cross-Site Scripting in Device Group Names
CVE-2026-26991 GHSA-5pqf-54qp-32wx
LibreNMS users with admin privileges can be tricked into deleting a device group by clicking on a malicious link in the group's name. This can happen when a user with admin privileges views a device g...
5.1
glibc's Random Number Generator May Generate Predictable Numbers After Forks
CVE-2025-0577
The getrandom and arc4random functions in glibc may produce predictable random numbers if used after a process is forked, which can lead to security issues. This affects systems using these functions ...
4.8
Slack Bot Allows Unintended Users to Run Privileged Commands
CVE-2026-28392 GHSA-v773-r54f-q32w
A vulnerability in OpenClaw Slack allows any user who can direct message the bot to run sensitive commands. This could happen if the bot's DMs are set to allow open access. To fix this, update your Op...
8.2