Monitor vulnerabilities that affect your stack. Sign up free to get alerts when software you use is affected.

CVE Vulnerabilities - 19 February 2026

RSS

391 vulnerabilities published on 19 February 2026

Severity:
Comodo Dome Firewall: Malicious Scripts Can Run in Browsers
CVE-2019-25416
Comodo Dome Firewall version 2.7.0 has a security weakness that lets hackers inject malicious code into websites, which can harm users who visit those sites. This can happen if a hacker sends a specia...
5.1
Comodo Dome Firewall: Malicious Scripts Can Be Injected into User Browsers
CVE-2019-25415
Comodo Dome Firewall version 2.7.0 has a security weakness that could allow hackers to inject malicious code into users' web browsers. This could lead to unauthorized access to users' computers or per...
5.1
Comodo Dome Firewall 2.7.0 allows attackers to inject malicious scripts
CVE-2019-25414
Comodo Dome Firewall 2.7.0 has a security flaw that lets attackers inject malicious code into web pages. This could lead to unauthorized access or actions on your network, so update to a fixed version...
5.1
Comodo Dome Firewall 2.7.0: Malicious Script Injection Through Browser
CVE-2019-25413
Comodo Dome Firewall 2.7.0 has a security weakness that lets hackers inject malicious code into your browser. This could allow them to take control of your browser or steal sensitive information. Upda...
5.1
Comodo Dome Firewall: Malicious Scripts Can Be Injected
CVE-2019-25412
Comodo Dome Firewall 2.7.0 has a security flaw that lets hackers insert malicious code into users' browsers by sending them a specially crafted request. This could allow hackers to take control of a u...
5.1
Comodo Dome Firewall 2.7.0 allows hackers to inject malicious scripts
CVE-2019-25411
Comodo Dome Firewall version 2.7.0 has a security weakness that lets hackers send fake requests to administrators' browsers, potentially allowing them to run malicious code. This could be used to stea...
5.1
Comodo Dome Firewall 2.7.0: Malicious Scripts Injected Via Firewall Configuration
CVE-2019-25410
The Comodo Dome Firewall version 2.7.0 has a security weakness that allows hackers to inject malicious code into users' browsers when they visit certain websites. This could potentially lead to unauth...
5.1
Comodo Dome Firewall 2.7.0: Malicious Scripts Can Be Injected Through Firewall
CVE-2019-25409
Comodo Dome Firewall 2.7.0 has a security flaw that allows hackers to inject malicious code into users' browsers. This can happen when a user visits a website that sends a special request to the firew...
5.1
Comodo Dome Firewall 2.7.0: Malicious Script Injection via User Input
CVE-2019-25408
The Comodo Dome Firewall 2.7.0 contains a security flaw that allows hackers to inject malicious code into users' browsers by submitting specially crafted input. This can lead to unauthorized actions o...
5.1
Comodo Dome Firewall allows malicious scripts to be injected via backup schedule
CVE-2019-25407
Comodo Dome Firewall's backup schedule interface is vulnerable to a security threat that can let hackers inject malicious scripts into users' browsers. This could potentially lead to unauthorized acce...
5.1
Comodo Dome Firewall 2.7.0 allows attackers to inject malicious scripts
CVE-2019-25406
Comodo Dome Firewall 2.7.0 is vulnerable to a security weakness that lets attackers inject malicious code into users' browsers. This can happen if a user visits a specially crafted website or clicks o...
5.1
Comodo Dome Firewall 2.7.0 allows attackers to inject malicious scripts in logins
CVE-2019-25402
An attacker can trick users into revealing sensitive information or taking unwanted actions by sending a special kind of link or form request to their browser. This can happen when a user navigates to...
5.1
Adobe ColdFusion: Malicious URLs Can Execute JavaScript in Browser
CVE-2025-15562
Adobe ColdFusion's /report/internet/urls endpoint fails to protect against malicious URLs, allowing attackers to inject JavaScript code that can execute in a user's browser. This could lead to unautho...
6.1
Malicious URLs Can Steal User Info in OpenCms v18.0 Search
CVE-2026-2736
If you use OpenCms v18.0, an attacker can trick you into visiting a fake link that steals your sensitive information or makes it look like you're doing things you didn't. Update to the latest version ...
5.1
WordPress Xmlrpc Attacks Blocker Plugin Exposes Admins to Malware When Viewing Logs
CVE-2026-2502
The Xmlrpc Attacks Blocker plugin for WordPress is vulnerable to a security risk that allows hackers to inject malicious code into the debug logs, which can be executed when an administrator views the...
6.1
Shield Security plugin for WordPress: Malicious Scripts Can Be Injected
CVE-2026-0561
The Shield Security plugin for WordPress has a security flaw that allows attackers to inject malicious scripts into websites. This can happen if a user clicks on a link sent by an attacker. Update the...
6.1
iXML Google XML Sitemap Generator Plugin for WordPress: Email Injection Risk
CVE-2025-14076
An attacker can trick users into clicking on a malicious link to inject malicious scripts into your WordPress site. This could allow an attacker to take control of your site or steal user data. Update...
6.1
Easy SVG Support plugin for WordPress can inject malicious code via SVG file uploads
CVE-2025-12451
The Easy SVG Support plugin for WordPress is not properly protecting against malicious code injected into SVG files uploaded to your site. This means an attacker with the right access can add code to ...
6.1
Aruba HiSpeed Cache plugin for WordPress allows attackers to inject malicious scripts.
CVE-2025-11706
The Aruba HiSpeed Cache plugin for WordPress is insecure, allowing attackers to inject malicious scripts into web pages if a user clicks on a specially crafted link. This could lead to unauthorized ac...
6.1
10Web Photo Gallery: Malicious Scripts Can Run on Your Site
CVE-2026-27360
The 10Web Photo Gallery software has a security flaw that allows hackers to inject malicious code into your website. This could allow them to steal sensitive information or take control of your site. ...
5.9
FooGallery allows hackers to inject malicious code into your website
CVE-2026-25362
The FooGallery plugin for your website has a security flaw that could allow hackers to inject malicious code into your site. This could potentially lead to unauthorized actions being taken on your sit...
5.9
WP SMS Allows Attackers to Inject Harmful Code into WordPress Sites
CVE-2026-25343
WP SMS, a plugin used for sending SMS from WordPress, has a security weakness that could allow attackers to inject malicious code into websites. This could lead to unauthorized actions, such as steali...
5.9
HurryTimer: Hackers can inject malicious code into your website
CVE-2026-24392
The HurryTimer software does not properly check user input, which allows hackers to inject malicious code into your website. This can lead to unauthorized actions being taken on your site. You should ...
5.9
OpenVPN on Windows 2.8.0 Crashes from Large Packets
CVE-2026-2738
If an attacker sends a large packet to a Windows system running OpenVPN version 2.8.0, it may crash the system. This only happens if the packet has a specific format, and it requires the attacker to b...
5.6
Worldquant-miner (up to 1.0.9) allows attackers to fake server requests
CVE-2026-2711
A flaw in the Worldquant-miner software, up to version 1.0.9, lets hackers trick a server into making false requests. This could be done from anywhere, and while it's not easy to exploit, the vulnerab...
6.3