Monitor vulnerabilities that affect your stack.
Sign up free to get alerts when software you use is affected.
CVE Vulnerabilities - 20 February 2026
RSS391 vulnerabilities published on 20 February 2026
Severity:
OpenClaw Cron Webhook May Expose Internal Server Data
CVE-2026-27488
GHSA-w45g-5746-x9fp
The OpenClaw npm package's cron webhook feature allows unauthorized access to internal server data. This could happen if an attacker sends a malicious request to the webhook. Update OpenClaw to versio...
6.9
Product Filter for WooCommerce: Unsecured Access to Sensitive Data
CVE-2025-69378
A security flaw in Product Filter for WooCommerce allows a hacker to access sensitive data they shouldn't be able to see. This affects all versions of the plugin up to 9.1.2. To stay secure, update to...
7.3
LottieFiles: Users Can Access Files Without Permission
CVE-2025-68043
A security issue in LottieFiles allows unauthorized users to access certain files. This is a concern because it could lead to sensitive information being accessed by people who shouldn't have access t...
7.3
Fujian Smart Integrated Management Platform System: SQL Injection Risk in XCamera Function
CVE-2026-2821
A security weakness in the Fujian Smart Integrated Management Platform System version 7.5 allows hackers to inject malicious SQL code, potentially giving them access to sensitive data. This could happ...
6.9
Fujian Smart Integrated Management Platform System SQL Injection Flaw Exposes Data
CVE-2026-2820
The Fujian Smart Integrated Management Platform System versions up to 7.5 have a security flaw that allows hackers to inject malicious code into the system. This could potentially allow attackers to a...
6.9
UTT HiPER 520: Remote Code Execution via Web Management Interface
CVE-2026-2847
A security flaw in the Web Management Interface of UTT HiPER 520 allows a hacker to execute unauthorized commands on the device from anywhere. This could allow an attacker to access sensitive data or ...
7.3
UTT HiPER 520 Web Interface Allows Unauthorized Code Execution
CVE-2026-2846
A security issue in UTT HiPER 520's web interface allows an attacker to execute unauthorized code on the device remotely. This can occur when a specially crafted input is sent to the device. To stay s...
7.3
Oxygen Server Allows Hackers to Access Unauthorized Data
CVE-2025-69299
The Oxygen server software has a security weakness that allows hackers to trick it into visiting unauthorized websites. This can happen if an attacker sends the server a specially crafted request. To ...
7.2
Wren Compiler Allows Malicious Code to Read Sensitive Data
CVE-2026-2858
A vulnerability in the Wren compiler can allow an attacker with local access to read sensitive data from the system. This affects versions of Wren up to 0.4.0. To protect your system, update to the la...
4.8
ADB Explorer Deletes Arbitrary Windows Directories
CVE-2026-27115
ADB Explorer on Windows versions 0.9.26020 and below can be tricked into deleting any directory on the user's computer, including important files and folders. This can happen if a user clicks on a mal...
7.1
Key Systems Inc Global Facilities Management Software exposes sensitive information via query parameter
CVE-2026-26721
The Key Systems Inc Global Facilities Management Software may leak sensitive information to attackers if they know the format of the query parameter 'sid'. This could compromise the security of your d...
7.1
PixelYourSite: Malicious Code Can Be Injected into Websites
CVE-2026-27072
The PixelYourSite website manager has a security flaw that allows hackers to inject malicious code into websites using the service, potentially allowing them to steal sensitive information or take con...
7.1
Whizz Plugins: Malicious Scripts Can Execute in Web Pages
CVE-2026-24955
A security issue in Whizz Plugins allows hackers to inject malicious code into web pages. This could lead to unauthorized access to user data or fake login prompts. Update to the latest version of Whi...
7.1
PhotoMe ThemeGoods theme: Hackers can inject malicious code into your website.
CVE-2026-24949
A vulnerability in PhotoMe's theme allows hackers to inject malicious code into your website, potentially allowing them to steal sensitive information or take control of your site. This issue affects ...
7.1
Reflected Cross-Site Scripting in Reflector Plugin Affects User Data
CVE-2026-24948
The Reflector plugin for Fox-Themes has a security issue that could allow hackers to inject malicious code into a website, potentially stealing user data or spreading malware. If you're using the Refl...
7.1
Grand Conference website can inject malicious code
CVE-2026-24943
The Grand Conference website has a security weakness that allows hackers to inject malicious code into the website. This could be used to steal user information or take control of users' accounts. Upd...
7.1
Malicious Links Can Hijack Link Whisper Free Pages
CVE-2026-22357
A security flaw in Link Whisper Free allows hackers to inject malicious code into web pages, potentially stealing user data or taking control of the page. This affects users of Link Whisper Free versi...
7.1
Persian Woocommerce SMS allows attackers to inject malicious code into web pages
CVE-2026-22352
A security issue exists in Persian Woocommerce SMS, a plugin used by online stores. If not addressed, attackers could inject malicious code into web pages, potentially stealing user data or taking con...
7.1
iMoney: Malicious Links Can Steal User Data
CVE-2025-69392
A security issue in iMoney allows attackers to steal sensitive information from users by tricking them into clicking on malicious links. This affects iMoney versions 0.37 and earlier. Update to the la...
7.1
GT3themes Diamond Cross-Site Scripting Risk: Data Theft or Fake Sites
CVE-2025-69391
The GT3themes Diamond software does not properly filter user input, allowing hackers to inject malicious code into your website. This could let them steal sensitive data or display fake websites that ...
7.1
Themebon Business Template Blocks for WPBakery (Visual Composer) fails to prevent malicious code injection
CVE-2025-69390
A security flaw in Themebon Business Template Blocks for WPBakery (Visual Composer) allows hackers to inject malicious code into pages. This could lead to unauthorized access to sensitive data or even...
7.1
Hugh Mungus Visitor Maps: Reflected Cross-Site Scripting in Visitor Maps
CVE-2025-69389
A security issue in the Visitor Maps plugin can allow an attacker to inject malicious code into your website, potentially stealing user data or taking control of your site. This affects versions 1.2.6...
7.1
RVCFDI Para Woocommerce allows malicious scripts to run on your website.
CVE-2025-69386
An attacker can inject malicious code into your website, potentially stealing sensitive information or taking control of your site. This affects RVCFDI Para Woocommerce plugins installed on your WordP...
7.1
WordPress wpdiscover Timeline Event History Allows Malicious Code Execution
CVE-2025-69384
A security issue in WordPress's wpdiscover Timeline Event History plugin allows an attacker to inject malicious code into a website, potentially stealing user data or taking control of the site. This ...
7.1
WooCommerce Bulk Product Editor allows unauthorized access to products
CVE-2025-69381
A security issue in WooCommerce Bulk Product Editor could allow unauthorized users to access and edit products, even if they shouldn't have permission. This affects versions up to 3.0 of the plugin. T...
7.1