Monitor vulnerabilities that affect your stack.
Sign up free to get alerts when software you use is affected.
CVE Vulnerabilities - 19 February 2026
RSS391 vulnerabilities published on 19 February 2026
Severity:
Microsoft Semantic Kernel Python SDK InMemoryVectorStore allows hackers to take control of your server
CVE-2026-26030
GHSA-xjw9-4gw8-4rqx
A security flaw in Microsoft's Semantic Kernel Python SDK allows hackers to potentially take control of your server if you're using a specific feature. To fix this, update to version 1.39.4 or later o...
10.0
DynamicWeb allows attackers to execute code via simple web requests
CVE-2026-2731
DynamicWeb versions 8 and 9, up to certain patches, have a security flaw that allows anyone to execute unauthorized code on the system. This means an attacker can potentially take control of the serve...
10.0
OGP-Website: Old Installs Open to Passwordless Access
CVE-2025-15586
If exploited, a security flaw in older versions of OGP-Website could allow an attacker to access your account without needing your password. This is a serious issue, as it means sensitive information ...
10.0
Kargo API Allows Attackers to Create Unauthorized Resources
CVE-2026-27112
GHSA-7g9x-cp9g-92mr
Kargo's API has a bug that lets attackers create resources in a project without permission. This can lead to more serious security problems, such as taking control of the project or even stealing sens...
9.4
Dagu: Unauthenticated Remote Code Execution Possible with Default Configuration
GHSA-6qr9-g2xw-cw92
Dagu's default settings leave it open to remote code execution by anyone who can connect to the system. This means an attacker can access and control the system without needing a password. To protect ...
9.8
RustFly 2.0.0 Remote Control Allows Malicious Commands
CVE-2026-27476
RustFly's remote control feature accepts commands without checking them for safety. This allows hackers to send commands that can harm the system. Update RustFly to a fixed version to prevent this.
9.3
RUCKUS Network Director OVA appliance: hardcoded SSH keys exposed
CVE-2025-67305
A security risk exists in older versions of RUCKUS Network Director, where the same SSH key is hardcoded in all installations. This allows an attacker with network access to gain access to the databas...
9.8
D-Tale: Publicly Hosted Sites at Risk of Malicious Code Execution
CVE-2026-27194
GHSA-c87c-78rc-vmv2
D-Tale users hosting their sites publicly may be at risk if they haven't updated to the latest version. This could allow attackers to run malicious code on the server. To protect your site, update to ...
8.1
Ruckus Network Director (RND) Stored Database Credentials Exposed
CVE-2025-67304
The Ruckus Network Director uses a default database username and password that can be accessed remotely, potentially allowing an attacker to gain full control of the database and the web interface. Th...
9.8
Hyland Alfresco Transformation Service: Unauthenticated Remote Code Execution
CVE-2026-26339
An attacker can execute malicious code on the server without needing a password. This can happen when processing certain documents. Update the software to the latest version to fix the issue.
9.3
Alfresco Transformation Service allows unauthenticated attackers to access servers
CVE-2026-26338
The Alfresco Transformation Service may allow attackers to trick the system into making unauthorized requests to external servers. This could lead to sensitive data being exposed or compromised. Updat...
6.9
SPIP Saisies Plugin Allows Attackers to Run Code on Your Server
CVE-2025-71243
If you're using the Saisies plugin with SPIP versions 5.4.0 to 5.11.0, an attacker can potentially run malicious code on your server. This is a serious security threat. To protect yourself, update SPI...
9.3
Databank Accreditation Software lets attackers access unauthorized data
CVE-2025-9953
The Databank Accreditation Software from DATABASE Software Training Consulting Ltd. has a security flaw that allows unauthorized access to sensitive data. This is a serious issue because attackers can...
9.8
BiEticaret CMS: Unsecured Access to Critical Function
CVE-2025-8350
An issue in certain versions of BiEticaret CMS makes it possible for an attacker to bypass the login process and access sensitive areas of the website without a password. This could lead to unauthoriz...
9.8
NesterSoft WorkTime allows unauthenticated command injection via API endpoint
CVE-2025-15559
An attacker can access sensitive data or take control of the server by exploiting a security weakness in the WorkTime API. This is a serious issue that allows a malicious person to execute commands on...
9.8
WpEvently 5.1.1 and earlier allows malicious code execution
CVE-2026-23549
An attacker can inject malicious code into the WpEvently plugin on your WordPress site, potentially allowing them to access or modify sensitive data. This issue affects versions of WpEvently up to 5.1...
9.8
Grand Restaurant Data Injection Risk through Untrusted Input
CVE-2026-23542
The Grand Restaurant software is vulnerable to a data injection risk. This means that an attacker could potentially inject malicious data into the system, which could lead to unauthorized actions or d...
9.8
itsourcecode Event Management System 1.0: SQL Injection Risk
CVE-2026-2691
A security flaw in itsourcecode Event Management System 1.0 allows an attacker to manipulate data in the system by exploiting a weakness in a file called /admin/manage_register.php. This could lead to...
6.9
itsourcecode Event Management System allows attackers to inject malicious SQL code
CVE-2026-2690
A security flaw in itsourcecode Event Management System's Admin Login feature allows hackers to inject malicious code, potentially giving them access to sensitive information. This could happen if an ...
6.9
itsourcecode Event Management System 1.0: Malicious Data Injection Risk
CVE-2026-2689
The itsourcecode Event Management System 1.0 has a security flaw in its admin manage_booking.php feature. This means a hacker could potentially inject malicious data, which could lead to unauthorized ...
6.9
s2Member plugin for WordPress: Passwords can be changed by attackers
CVE-2026-1994
The s2Member plugin for WordPress has a security flaw that allows attackers to change any user's password, including administrators, without knowing their current password. This could lead to unauthor...
9.8
Slider Future plugin allows attackers to upload any file
CVE-2026-1405
The Slider Future plugin for WordPress fails to check the type of files that can be uploaded, making it possible for attackers to upload any file to your server. This could allow an attacker to take c...
9.8
Prodigy Commerce plugin allows attackers to read or execute arbitrary files
CVE-2026-0926
The Prodigy Commerce plugin for WordPress, in versions up to 3.2.9, has a security flaw that allows attackers to access and potentially execute any file on the server. This can lead to unauthorized ac...
9.8
Buyent Classified plugin for WordPress allows attackers to create administrator accounts
CVE-2025-13851
The Buyent Classified plugin for WordPress, included with the Buyent theme, has a security flaw that lets hackers create administrator accounts without a password. This means an attacker can take cont...
9.8
Lizza LMS Pro plugin for WordPress allows unauthorized admin access
CVE-2025-13563
The Lizza LMS Pro plugin for WordPress, used in some websites, has a security flaw that lets attackers gain administrator access to the site without a password. This can happen when a user registers f...
9.8