Monitor vulnerabilities that affect your stack.
Sign up free to get alerts when software you use is affected.
CVE Vulnerabilities - 19 February 2026
RSS391 vulnerabilities published on 19 February 2026
Severity:
NanaZip: Infinite Loop and Crash Risk in File Archive Parsing
CVE-2026-27014
NanaZip, an open source file archive tool, has a bug in versions 5.0.1252.0 to 6.0.1630.0 that can cause it to loop endlessly or crash if it encounters a specific type of file structure. This can happ...
5.1
URL Shortify allows attackers to make unauthorized requests to internal servers
CVE-2026-25385
A security bug in URL Shortify allows hackers to send fake requests to internal servers, potentially exposing sensitive data. This affects all versions of URL Shortify up to version 1.12.3. To stay se...
5.5
xlnt-community: Malicious Data Can Cause Data Corruption
CVE-2026-2703
A bug in xlnt-community's xlnt library allows an attacker with local access to manipulate data in a way that can cause data corruption. This could potentially be exploited by attackers who have obtain...
4.8
Pi-hole Admin Interface: Malicious HTML Injected into Admin Sessions
CVE-2026-26953
Pi-hole versions 6.0 and above have a security flaw that allows an attacker to inject malicious code into the web interface. This can happen when an attacker sends a special request to the Pi-hole adm...
5.4
Pi-hole Admin Interface: Stored HTML Injection in DNS Records Configuration
CVE-2026-26952
Versions of Pi-hole below 6.4 are vulnerable to a security flaw that allows an attacker to inject malicious code into the DNS records table. This could potentially allow an attacker to perform actions...
5.4
OpenText Web Site Management Server allows hackers to inject malicious scripts
CVE-2025-9208
OpenText's Web Site Management Server has a security issue that lets hackers inject malicious code into websites, which could steal user information or take control of user sessions. If you use this s...
7.5
OpenText Web Site Management Server allows Malicious Code to Run in Browsers
CVE-2025-13672
A security issue in OpenText's Web Site Management Server could allow attackers to inject malicious code into web pages, which could be executed by users' browsers. This could lead to unauthorized acc...
7.0
DirectoryPress: Unauthorized Access to Sensitive Data
CVE-2026-27387
A security issue in DirectoryPress could allow an attacker to access sensitive data or features they shouldn't be able to access. This affects DirectoryPress versions up to 3.6.26, so update to a newe...
5.4
Open WebUI: Unsecured Chat History Allows Malicious Link Sharing
CVE-2026-26193
A security issue in Open WebUI's chat history feature allows hackers to create a malicious link that can be shared with other users, potentially leading to cross-site scripting (XSS) attacks. This aff...
5.4
Open WebUI Cross-Site Scripting (XSS) Through Chat History
CVE-2026-26192
Open WebUI, a self-hosted AI platform, had a security issue where malicious code could be injected into chat history. This allowed attackers to execute code on users' devices when viewing shared chats...
5.4
OpenClaw: Insecure Hashing Used for Docker Sandbox Configuration
CVE-2026-28479
GHSA-fh3f-q9qw-93j9
Versions of OpenClaw <= 2026.2.14 use a deprecated and insecure hash algorithm, potentially allowing unauthorized access to sandboxed containers. This has been fixed in version 2026.2.15. Update to th...
8.7
ChurchCRM Group View JavaScript Injection
CVE-2026-26059
An authenticated user with group editing permissions can inject malicious JavaScript code into ChurchCRM, which executes when they view a group. This could potentially allow the attacker to steal sens...
2.1
GFI MailEssentials: Stored Code Injection in Settings Page
CVE-2026-23619
A malicious user with an account can inject malicious code into the settings page of GFI MailEssentials, potentially allowing them to take control of the system or view sensitive information. This aff...
5.1
GFI MailEssentials AI: Stored Scripting Vulnerability in Spam Filter
CVE-2026-23618
An attacker can execute malicious scripts in GFI MailEssentials AI's Spam Keyword Checking interface if they have an account. This could allow them to access sensitive information or take control of t...
5.1
GFI MailEssentials AI: Stored Cross-Site Scripting Risk
CVE-2026-23617
GFI MailEssentials AI versions before 22.4 have a security weakness that allows an attacker to inject malicious code into the management interface. This could let an attacker take control of a logged-...
5.1
GFI MailEssentials AI: Untrusted Code Execution via Config Page
CVE-2026-23616
If you use GFI MailEssentials AI version 22.4 or earlier, an attacker who logs in to your system can inject malicious code into the Anti-Spoofing configuration page. This allows them to execute unauth...
5.1
GFI MailEssentials Stored XSS Vulnerability in Email Exceptions Interface
CVE-2026-23615
GFI MailEssentials versions prior to 22.4 have a security issue that allows an authenticated user to execute malicious scripts when accessing the Email Exceptions interface. This could potentially lea...
5.1
GFI MailEssentials AI: Stored JavaScript Injection Risk in Management Interface
CVE-2026-23614
An attacker with a GFI MailEssentials AI account can inject malicious JavaScript code into the management interface, potentially allowing them to steal sensitive information or take control of the sys...
5.1
GFI MailEssentials AI 22.4 and Earlier: Malicious Code Injection via URI DNS Blocklist
CVE-2026-23613
GFI MailEssentials AI versions before 22.4 have a security flaw that allows an attacker to inject malicious code into the system's configuration page. An authenticated user can enter and store malicio...
5.1
GFI MailEssentials: Untrusted Content Can Run on Management Interface
CVE-2026-23612
GFI MailEssentials versions before 22.4 have a security flaw that lets an authorized user inject malicious code onto the management interface. This could be used to steal sensitive information or take...
5.1
GFI MailEssentials AI versions 22.4 and earlier allow unauthorized code execution
CVE-2026-23611
GFI MailEssentials AI versions prior to 22.4 contain a security flaw that allows an authenticated user to inject malicious code that can execute in the context of a logged-in user. This could potentia...
5.1
GFI MailEssentials: Malicious Code Injection in POP2Exchange Configuration
CVE-2026-23610
GFI MailEssentials versions before 22.4 have a security flaw that allows an attacker to inject malicious code into the email security settings. An attacker with a user account can exploit this vulnera...
5.1
GFI MailEssentials Stored Code Injection in Management Interface
CVE-2026-23609
Authenticated users can inject malicious code into the GFI MailEssentials management interface, potentially allowing them to access sensitive information or take control of the system. This issue affe...
5.1
GFI MailEssentials: Malicious Code Injection Through Mail Monitoring Rule Creation
CVE-2026-23608
Authenticated users can inject malicious code into the GFI MailEssentials interface, potentially allowing them to take control of user sessions or steal sensitive information. This issue affects all v...
5.1
GFI MailEssentials AI: Unauthenticated Code Injection in Whitelist Interface
CVE-2026-23607
A security flaw in older versions of GFI MailEssentials AI allows a malicious user to inject code into the admin interface, potentially allowing them to take control of the system. This issue affects ...
5.1