Monitor vulnerabilities that affect your stack.
Sign up free to get alerts when software you use is affected.
CVE Vulnerabilities - 20 February 2026
RSS391 vulnerabilities published on 20 February 2026
Severity:
Survey Maker Plugin on WordPress: Malicious Script Execution
CVE-2026-26370
The Survey Maker plugin for WordPress has a security flaw that could allow an attacker to run malicious code on your website and potentially harm your users. If you're using an affected version, updat...
5.1
RoundCube Webmail: Animate Tag in SVG Can Execute Malicious Code
CVE-2025-68461
The RoundCube Webmail application contains a security weakness that could allow an attacker to inject malicious code into a user's webmail session. This could lead to unauthorized access to sensitive ...
6.1
KEV
Strimzi: Malicious certificates can be accepted by Kafka cluster
CVE-2026-27133
Strimzi's Kafka clusters may accept fake server certificates if a chain of trusted certificates is used. This means an attacker could pretend to be a trusted server and connect to the cluster. Update ...
5.9
Ray Dashboard Allows Unauthenticated Remote Server Shutdown
CVE-2026-27482
GHSA-q5fh-2hc8-f6rq
Ray dashboard's HTTP server has an issue that allows anyone to remotely shut down the server or delete jobs without a password. This is a problem because it means an attacker could make your server un...
5.9
JobBoard Job listing allows exposing sensitive data in job postings
CVE-2025-68855
A security issue in JobBoard Job listing versions up to 1.2.8 could allow attackers to extract sensitive information from job postings. This means that data that was meant to be private could be acces...
5.9
Silencesoft RSS Reader allows hackers to inject malicious scripts into your website
CVE-2025-60183
A security issue exists in Silencesoft's RSS Reader that could allow hackers to inject malicious code into your website. This could potentially allow them to steal information, disrupt your site, or t...
5.9
Master Addons for Elementor: Stored Malicious Code Can Be Injected
CVE-2024-52387
The Master Addons for Elementor plugin has a security flaw that allows an attacker to inject malicious code into a website, potentially leading to unauthorized actions or data exposure. This affects v...
5.9
Router's Admin Password is Visible on Screen
CVE-2026-26049
If you use the web interface to manage your router, sensitive passwords are displayed in plain text, making it easy for others to see them. This could lead to unauthorized access to your network. Upda...
5.7
RustDesk Client for Windows Leaks Sensitive Information on Upload
CVE-2026-2490
The RustDesk Client for Windows may leak sensitive information if an attacker can run low-privileged code on the system. This can happen when a user uploads a special type of file link. To fix this, u...
5.5
pypdf Can Take a Long Time to Process Malformed PDFs
CVE-2026-27026
GHSA-9mvc-8737-8j8h
If you use pypdf, an attacker could create a PDF that would take a long time to process. This could potentially cause delays or slow down your system. Update to version 6.7.1 or later to fix this issu...
7.3
Pypdf Library Can Fail to Process Large PDF Files
CVE-2026-27025
GHSA-wgvp-vg3v-2xq3
The pypdf library may take a long time or use a lot of memory when processing certain large PDF files. This could cause delays or crashes. Update to the latest version, pypdf 6.7.1, to prevent this is...
7.3
pypdf: Infinite Loop in Processing PDF Outlines
CVE-2026-27024
GHSA-996q-pr4m-cvgq
An attacker can create a malicious PDF that causes pypdf to run indefinitely. This could lead to a denial-of-service (DoS) situation. Update to version 6.7.1 or later to fix this issue.
7.3
Owl opds 2.2.0.4: File manipulation via crafted network request
CVE-2026-26100
A bug in Owl opds version 2.2.0.4 allows an attacker to manipulate files on the server. This could allow an attacker to delete or modify important files, potentially disrupting the normal operation of...
6.8
Owl opds 2.2.0.4: Malicious File Access via Network Request
CVE-2026-26099
A software update for Owl opds version 2.2.0.4 contains a security issue that could allow an attacker to access files on your system by sending a specially crafted network request. This means that a h...
8.4
Owl opds 2.2.0.4: Malicious files can be executed
CVE-2026-26098
A security issue in Owl opds 2.2.0.4 allows an attacker to trick the software into loading malicious files, which could lead to unauthorized actions on your system. This could happen if you use a comp...
8.4
Owl opds 2.2.0.4 allows manipulation of configuration files via network request
CVE-2026-26097
An attacker can send a specific network request to the Owl opds server, potentially allowing them to modify the configuration files. This could lead to unauthorized changes to the system's behavior. Y...
8.4
Owl opds 2.2.0.4 allows unauthorized file access
CVE-2026-26096
A security issue in Owl opds 2.2.0.4 could allow an attacker to access and potentially modify files on the server. This could happen if an attacker sends a specially crafted request to the server. To ...
8.5
Owl opds 2.2.0.4: Unauthorized File Access via Network Request
CVE-2026-26095
A vulnerability in Owl opds version 2.2.0.4 allows an attacker to access sensitive files on the server by sending a specially crafted network request. This could potentially lead to unauthorized data ...
8.5
SVXportal versions 2.5 and prior: Malicious code in user profiles can harm admins
CVE-2026-27506
If you use SVXportal, an attacker can trick an admin into viewing a user's profile by embedding malicious code in the user's name, email, or profile picture. This could allow the attacker to take cont...
5.1
Detronetdip E-commerce 1.0.0 Allows Remote Attackers to Inject Malicious Code
CVE-2025-15583
A security flaw in Detronetdip E-commerce 1.0.0 makes it possible for hackers to inject malicious code into your website. This could allow them to steal sensitive information, display unwanted message...
5.1
Unauthorized Access to Pet Shop and Veterinary WordPress Theme
CVE-2026-22383
An attacker can access restricted areas of the Pet Shop and Veterinary WordPress Theme if the administrator incorrectly configures access levels. This could allow an attacker to view or modify sensiti...
5.4
Booked allows attackers to bypass login security
CVE-2026-22341
A security issue in Booked allows attackers to potentially access the system without a valid login. This affects Booked versions up to 3.0.0. It's essential to update to the latest version to prevent ...
5.4
Flare: Malicious files can steal user data through stored XSS
CVE-2026-26993
Flare versions 1.7.0 and below allow attackers to embed malicious code in uploaded files, which can steal user data when viewed in a special mode. This issue has been fixed in version 1.7.1. To protec...
5.4
Photobooth before 1.0.1 allows hackers to inject malicious code
CVE-2026-27020
Photobooth versions before 1.0.1 are vulnerable to a security risk where hackers can inject malicious code into user input fields. This could allow them to take control of your website or steal user d...
5.3
Yeqifu Warehouse Has a Security Risk in Data Handling
CVE-2026-2851
A vulnerability in Yeqifu Warehouse's data handling system could allow unauthorized access to sensitive information. This means someone with the right tools could potentially view or alter data they s...
5.3