Monitor vulnerabilities that affect your stack. Sign up free to get alerts when software you use is affected.

CVE Vulnerabilities - 20 February 2026

RSS

391 vulnerabilities published on 20 February 2026

Severity:
Samsung MultiXpress Printers Expose Address Book and Settings
CVE-2026-2832
A security issue in Samsung MultiXpress multifunction printers could allow unauthorized access to sensitive information, including your address book and printer settings. This could happen if a hacker...
5.3
Static Web Server Basic Authentication Reveals Valid Usernames
CVE-2026-27480 GHSA-qhp6-635j-x7r2
A security issue in Static Web Server's Basic Authentication could allow attackers to figure out valid usernames by measuring how long it takes the server to respond, making it easier for them to try ...
5.3
OpenSourcePOS 3.4.1: SQL Injection in Currency Configuration
CVE-2026-26745
OpenSourcePOS version 3.4.1 has a security weakness that allows attackers to manipulate data in the system. This could lead to unauthorized access or data tampering. To protect your business, update t...
5.3
Primer MyData for Woocommerce: Malicious File Access Risk
CVE-2025-69325
Primer MyData for Woocommerce has a security issue that allows an attacker to access and potentially manipulate sensitive files on the server. This can lead to unauthorized data exposure or even syste...
5.3
Schedula Appointment Booking System: Unauthorized Access to Sensitive Data
CVE-2025-67970
A security flaw in Schedula's appointment booking system allows hackers to access sensitive data even if they shouldn't have permission. This means that someone with the wrong level of access could se...
5.3
SecuPress Free allows unauthorized access to sensitive settings
CVE-2024-43228
An unauthorized user can access sensitive settings in SecuPress Free, potentially compromising the security of your WordPress site. This issue affects all versions of SecuPress Free up to and includin...
5.3
Anssi Laitila Shared Files allows unauthorized access to files
CVE-2024-34438
A security weakness in Anssi Laitila Shared Files means that some users may be able to access files they shouldn't be able to see. This is a concern because sensitive information could be exposed. Upd...
5.3
bn.js: Infinite Loop Triggers Process Hang
CVE-2026-2739 GHSA-378v-28hj-76wf
Versions of bn.js before 4.12.3 and 5.2.3 are vulnerable to a bug that causes processes to hang indefinitely. This can happen when certain methods are called on a BN instance with a specific input. Up...
5.5
Unpublished Course Details Exposed in Frappe LMS Versions 2.44.0 and Below
CVE-2026-26977
If you're using Frappe LMS versions 2.44.0 or earlier, unauthorized users can view details of unpublished courses. This is a security risk because sensitive information about your courses could be acc...
6.9
PJSIP H.264 Video Processing Can Overwrite Memory
CVE-2026-26967
If an attacker sends malicious video data, it could potentially cause a critical security issue. This affects applications that use PJSIP to play H.264 video. A fix is available, and users should upda...
8.1
Tanium TanOS Leaks Sensitive Information in Log Files
CVE-2026-2605
A vulnerability in Tanium's TanOS operating system allows sensitive information to be accidentally written to log files. This could potentially expose confidential data, such as user credentials or ot...
5.3
HCL Digital Experience: Stored XSS in Admin Interface
CVE-2025-62326
A hacker could inject malicious code into the HCL Digital Experience admin interface, potentially taking control of the system or stealing sensitive information. This requires an attacker to have elev...
4.8
Lettermint SDK Leaks Email Info to Wrong Recipients
CVE-2026-27492 GHSA-49pc-8936-wvfp
If you reuse a Lettermint client instance to send multiple emails, some email details may accidentally be sent to the wrong people. To fix this, upgrade to Lettermint version 1.5.1 or later. If an upg...
4.7
Tanium Cloud Workloads Enforce Client Extension Use-After-Free Flaw
CVE-2026-2408
The Tanium Cloud Workloads Enforce client extension has a flaw that could allow attackers to potentially execute malicious code. This issue is fixed in a recent update, so it's essential for administr...
4.7
OpenClaw: Vulnerability in Skill Packaging Script Allows Unauthorized File Inclusion
CVE-2026-27485 GHSA-r6h2-5gqq-v5v6
A vulnerability in the OpenClaw skill packaging script allows an attacker to include unintended files in a skill archive when a user packages the skill locally. This could potentially expose sensitive...
4.6
Discord Bot Moderation Actions Can Be Faked
CVE-2026-27484 GHSA-wh94-p5m6-mr7j
A security issue in the OpenClaw Discord moderation tool allows a non-admin user to fake moderation actions, such as kicking or banning users, by manipulating the request. This was fixed in a recent u...
2.3
Seraphinite Accelerator allows unauthorized access to sensitive data
CVE-2024-54222
A weakness in Seraphinite Accelerator's security lets unauthorized users access sensitive information stored in the application. This means that attackers could potentially view confidential data that...
4.3
OpenClaw: Very Large Inputs Can Slow Down Local Conversations
CVE-2026-27576 GHSA-cxpw-2g23-2vgw
A bug in OpenClaw's local conversation system can cause it to slow down or become unresponsive when very large inputs are sent. This issue affects local ACP clients, such as IDE integrations, and can ...
4.8
EnOcean SmartServer IoT (versions prior to 4.60.009) - Remote Memory Leak
CVE-2026-22885
A security issue affects older versions of EnOcean SmartServer IoT, allowing hackers to remotely send malicious messages that can cause the system to run out of memory. This could lead to the server c...
3.7
OrientDB Community Edition allows malicious requests to perform unauthorized actions
CVE-2019-25447
Attackers can trick users into performing actions they shouldn't by crafting fake requests to certain endpoints. This could let them create or delete databases, change settings, or even add new functi...
5.3
HCL Connections Leaks Internal Information
CVE-2025-52603
HCL Connections, a collaboration platform, is vulnerable to a situation where a user can accidentally view internal details that shouldn't be publicly visible. This can happen when a specific navigati...
3.5
WeRSS we-mp-rss: Cross-Site Scripting in Article Module
CVE-2026-2825
A security issue in WeRSS we-mp-rss 1.4.8 and earlier allows attackers to inject malicious code into web pages, potentially allowing them to take control of user sessions. This could lead to unauthori...
5.1
Windmill: Non-Admins Can See Slack OAuth Secrets
CVE-2026-26964
Non-admin users on Windmill versions 1.634.6 and below can access Slack OAuth client secrets. This allows unauthorized users to potentially access sensitive information. Update to version 1.635.0 to f...
2.7
Silicon Labs Secure NCP: Malicious Packet Can Crash System
CVE-2025-14055
An integer underflow error in the Silicon Labs Secure NCP host implementation can be exploited by a hacker to crash the system. This could lead to a denial-of-service, making the system unavailable. F...
2.4
Fickling can incorrectly rate safe Python files that use network protocols
GHSA-83pf-v6qq-pwmr
Fickling, a tool used to check Python code for security vulnerabilities, has a bug that can lead to it incorrectly rating some safe code as vulnerable. This happens when the code uses certain standard...
2.3