Monitor vulnerabilities that affect your stack. Sign up free to get alerts when software you use is affected.

CVE Vulnerabilities - 20 February 2026

RSS

391 vulnerabilities published on 20 February 2026

Severity:
LabCollector 5.423: Unauthenticated SQL Code Injection Exposes Database Data
CVE-2019-25438
LabCollector 5.423 has a security weakness that allows hackers to access sensitive information without a login. This is a serious issue because it lets attackers extract confidential data. To protect ...
8.8
SpotAuditor 5.3.1.0 can be crashed by excessive registration name entries
CVE-2019-25434
An attacker can cause SpotAuditor to crash by entering a very long name during registration. This can happen without needing a password or login. To protect your system, update to a fixed version of S...
6.7
Part-DB 0.4 allows unauthorized login with malicious input
CVE-2019-25432
An attacker can submit a specific character to the login form to gain unauthorized access to Part-DB 0.4. This is a serious issue because it allows anyone to access the application without a legitimat...
8.8
openITCOCKPIT Monitoring Tool Exposes Data to Malicious Payloads
CVE-2026-24891
Versions 5.3.1 and below of openITCOCKPIT contain a security flaw that allows an attacker to inject malicious data into the tool's monitoring system. This could lead to unauthorized access or disrupti...
7.5
Your Wi-Fi Router Can Be Hacked with a Fake Disconnect
CVE-2026-26048
Your Wi-Fi router doesn't protect against fake disconnect messages, which means a bad actor can send fake signals to disconnect you from the internet, causing outages and disruptions. This is a seriou...
7.5
Device Web Interface Sends Passwords in Plain Text Over Network
CVE-2026-24455
The device's web interface sends user passwords in plain text over the network, making them easily accessible to anyone on the same network. This means that hackers can intercept and steal user creden...
7.5
Authorsy allows unauthorized access with incorrect security settings
CVE-2026-24950
An error in Authorsy's security settings can allow unauthorized users to access certain features. This issue affects Authorsy versions up to 1.0.6. To fix the issue, update to a newer version of Autho...
7.5
WP Job Portal: Unauthorized Access to Job Posts
CVE-2026-24941
An issue with WP Job Portal allows unauthorized access to job posts if access control settings are not properly configured. This can lead to sensitive information being viewed or modified by unapprove...
7.5
Jetpack CRM allows hackers to access sensitive files
CVE-2026-22356
A vulnerability in Jetpack CRM allows unauthorized access to sensitive files on the server, which could lead to data exposure or other security issues. This affects Jetpack CRM versions up to 6.7.0. U...
7.5
WooODT Lite allows attackers to pretend to be any user
CVE-2025-69401
WooODT Lite, a plugin for WooCommerce, has a security weakness that lets attackers pretend to be any user, which can lead to unauthorized changes to orders or other sensitive information. This issue a...
7.5
Cnvrse: Exploiting Access Control Settings Can Bypass Security
CVE-2025-69394
A mistake in the way Cnvrse controls user access can allow an attacker to access sensitive information or features they shouldn't have permission to. This issue affects all versions of Cnvrse up to 2....
7.5
Exzo Configuration Error Exposes Sensitive Data
CVE-2025-69393
Exzo, a website builder, has a security issue that could allow unauthorized access to sensitive information if access control settings are not properly configured. This affects Exzo versions up to 1.2...
7.5
Simple Retail Menus PHP Files Can Be Accidentally Run
CVE-2025-69387
A security issue in Simple Retail Menus allows an attacker to make the system run unauthorized PHP files, potentially allowing them to access sensitive data or take control of the system. This affects...
7.5
Agence web Eoxia WP shop allows attackers to access local files
CVE-2025-69383
The Agence web Eoxia WP shop has a security flaw that lets attackers access sensitive files on the server where it's installed. This means they could potentially steal or modify important data. To fix...
7.5
Upload Files Anywhere fails to prevent malicious file uploads
CVE-2025-69380
A security issue in Upload Files Anywhere plugin allows hackers to upload files to unintended locations on your website. This could lead to unauthorized access or data exposure. Update to version 2.9 ...
7.5
VidoRev allows hackers to access local files
CVE-2025-69373
A security weakness in VidoRev, a PHP-based video review software, allows hackers to access and potentially read sensitive local files on the server. This creates a risk of data exposure and unauthori...
7.5
ModelTheme Framework: Insecure Access Control Allows Unauthorized Access
CVE-2025-69303
An outdated version of the ModelTheme Framework has a security weakness that lets users access areas they shouldn't. This is a concern because it could allow unauthorized changes or data exposure. Upd...
7.5
GhostPool Gauge allows unauthorized access due to incorrect access control settings
CVE-2025-69298
A security issue in GhostPool Gauge makes it possible for unauthorized users to access data or perform actions they shouldn't be able to. This affects versions of GhostPool Gauge from its initial rele...
7.5
Aardvark Plugin: Unauthorized Access to Sensitive Data
CVE-2025-69297
An outdated version of the Aardvark Plugin for GhostPool may allow unauthorized access to sensitive data. This is because the plugin doesn't properly control who can access certain features. Upgrade t...
7.5
Themepul TopperPack Allows Attackers to Access Local Files
CVE-2025-68841
Themepul TopperPack, a plugin for Elementor, has a security flaw that allows hackers to access sensitive files on your website. This could lead to data theft or disruption of your site's functionality...
7.5
NextMove Lite: Unauthorized Access to Configuration Settings
CVE-2025-68048
NextMove Lite plugins may allow unauthorized access to sensitive settings. This could potentially allow an attacker to make changes to the plugin's settings, which could compromise the security of the...
7.5
YayCurrency Incorrect Access Control Allows Unauthorized Access
CVE-2025-67994
A security issue exists in YayCurrency versions 3.3 and earlier. This allows unauthorized users to access sensitive areas of the application, potentially leading to data theft or tampering. Update to ...
7.5
WPLegalPages: Unrestricted Access to Sensitive Pages
CVE-2025-67974
If not configured correctly, WPLegalPages may allow unauthorized access to sensitive pages and information. This could lead to unauthorized users viewing confidential data. Update to version 3.5.5 or ...
7.5
Shiprocket Access Control Configuration Error Exposes Sensitive Data
CVE-2025-68051
Incorrect access control settings in Shiprocket allow unauthorized access to sensitive information. This can happen when an attacker configures access controls incorrectly, potentially putting user da...
7.4
PDF-XChange Editor allows local attackers to gain administrator access
CVE-2026-2040
PDF-XChange Editor has a security flaw that could allow a malicious local user to gain administrator access on a computer. This means a hacker with some basic access could potentially take control of ...
7.3