Monitor vulnerabilities that affect your stack.
Sign up free to get alerts when software you use is affected.
CVE Vulnerabilities - 21 February 2026
RSS59 vulnerabilities published on 21 February 2026
Severity:
Cloud Hypervisor allows sensitive host files to be accessed by VM guests
CVE-2026-27211
Old versions of Cloud Hypervisor (34.0 to 50.0) can be tricked into sharing sensitive host files with virtual machines. This can happen if the virtual machine is given permission to write to its disk ...
9.1
itsourcecode Vehicle Management System SQL Injection Risk
CVE-2026-2867
A security flaw in itsourcecode Vehicle Management System 1.0 makes it possible for hackers to inject malicious code into the system. This could allow them to access sensitive data or take control of ...
6.9
SQL Injection in itsourcecode Agri-Trading Online Shopping System 1.0
CVE-2026-2865
A security flaw in itsourcecode Agri-Trading Online Shopping System 1.0 allows hackers to inject malicious SQL code, potentially stealing or altering sensitive data. This puts customer information and...
6.9
SAIL Library: Arbitrary Code Execution through Malicious Image Files
CVE-2026-27168
The SAIL library is susceptible to a serious security flaw when handling certain types of image files. An attacker can exploit this weakness by creating a specially crafted image file, potentially all...
9.8
ERP Enterprise Resource Planning lacks access controls for some endpoints
CVE-2026-27471
Versions of the free ERP software up to 15.98.0 and 16.0.0-rc.1 through 16.6.0 have a security weakness that allows unauthorized users to view sensitive documents. This issue has been fixed in later v...
9.3
Sentry SAML SSO allows attackers to take over any user account
CVE-2026-27197
Versions 21.12.0 through 26.1.0 of Sentry's error tracking and performance monitoring tool have a critical security weakness in its SAML single sign-on feature. This could allow an attacker to gain co...
9.1
OpenSift: Untrusted Content Executes in Browser on Earlier Versions
CVE-2026-27169
OpenSift versions 1.1.2-alpha and below allow attackers to inject malicious code into the chat tool, which can execute in a user's browser when they view a compromised study or quiz. This could lead t...
8.9
Tenda A21 Router Allows Remote Attackers to Crash Device
CVE-2026-2886
A vulnerability in the Tenda A21 router's set_device_name function allows a remote attacker to crash the device. This could happen if a malicious user sends a specially crafted input to the device. To...
7.4
D-Link DWR-M960 IPv6 Setup Function Allows Remote Code Execution
CVE-2026-2885
A security flaw in the D-Link DWR-M960's IPv6 setup function can allow an attacker to execute malicious code on the device remotely. This means an attacker could potentially take control of the device...
7.4
D-Link DWR-M960 Router WAN Interface Setting Handler Code Execution
CVE-2026-2884
A security flaw in the D-Link DWR-M960 router's WAN interface setting handler allows a remote attacker to execute code on the device. This could potentially allow an attacker to take control of the ro...
7.4
D-Link DWR-M960: Unsecured Input Can Cause System Crash
CVE-2026-2883
A flaw in the D-Link DWR-M960's software allows an attacker to potentially crash the system by manipulating certain input. This could be done remotely and has already been publicly disclosed, making i...
7.4
D-Link DWR-M960 Router Can Be Hacked Remotely
CVE-2026-2882
A bug in the D-Link DWR-M960 router can allow an attacker to take control of the device remotely. This can happen if a hacker sends a specific type of data to the router. To protect your network, upda...
7.4
D-Link DWR-M960: Remote code execution through firewall config
CVE-2026-2881
A security flaw in the D-Link DWR-M960's advanced firewall settings can be exploited by an attacker to run malicious code on the device. This can happen if a hacker sends a specially crafted message t...
7.4
Tenda A18 15.13.07.13: Unsecured Data Transfer Exposes System to Remote Attack
CVE-2026-2877
A security weakness in Tenda A18's software allows hackers to send malicious data to the system, potentially leading to unauthorized access. This weakness can be exploited remotely, and an exploit is ...
7.4
Tenda A18 15.13.07.13: Remote Code Execution Possible
CVE-2026-2876
A security flaw in the Tenda A18 router's settings page allows an attacker to potentially take control of the device. This can happen if a hacker sends a specially crafted request to the router's sett...
7.4
Tenda A21 1.0.0.0 WiFi Setting Function Allows Remote Attack
CVE-2026-2874
The Tenda A21 WiFi router's WiFi setting function has a security flaw that could allow an attacker to take control of the device remotely if they send a specially crafted message. This means that a ha...
7.4
Tenda A21 Router Allows Remote Code Execution
CVE-2026-2873
A security flaw in the Tenda A21 router's scheduling feature can be exploited by an attacker to execute malicious code remotely. This could potentially allow an attacker to take control of the router....
7.4
Tenda Router Allows Remote Attack via Malicious Device Name
CVE-2026-2872
A vulnerability in the Tenda A21 router's MAC Filtering Configuration allows an attacker to potentially cause the router to crash or behave unexpectedly by sending a specially crafted device name. Thi...
7.4
Tenda A21 Router: Uncontrolled Data Can Crash the Device
CVE-2026-2871
An attacker can send a specially crafted request to a Tenda A21 router, potentially causing it to crash. This could lead to loss of control over the device and make it unavailable for use. Users shoul...
7.4
Tenda A21 Router: Unsecured Remote Code Execution Risk
CVE-2026-2870
A security flaw in the Tenda A21 router's Quality of Service settings can allow an attacker to remotely execute malicious code, potentially taking control of the device. This could lead to unauthorize...
7.4
ZoneMinder: Unauthorized Access to Database Records
CVE-2026-27470
ZoneMinder, a software for monitoring CCTV cameras, has a security flaw. If an authorized user edits a camera event, they can access unauthorized data. To fix this, update to a safe version of ZoneMin...
8.8
BigBlueButton: Unsecured Ports Make Server Prone to Denial of Service
CVE-2026-27466
The BigBlueButton virtual classroom software has a security issue in versions 3.0.21 and earlier that could allow an attacker to overload the server with large or complex documents, causing it to slow...
8.2
Strimzi: Incorrect mTLS Configuration with Multistage CA Chain
CVE-2026-27134
Strimzi incorrectly configures mTLS authentication when using a custom certificate chain. This allows some users to authenticate even if their certificate isn't valid. To fix this, update to version 0...
8.1
Wallos 4.6.0 and below: Malicious Redirects Expose Internal Resources
CVE-2026-27479
A security issue in Wallos' logo upload feature allows attackers to access sensitive internal resources. This could potentially lead to unauthorized access and data exposure. Update to version 4.6.1 t...
7.7
Metabase: Server-Side Template Injection via Notifications Endpoint Leads to RCE
CVE-2026-27464
GHSA-vcj8-rcm8-gfj9
Metabase is an open-source data analytics platform. In versions prior to 0.57.13 and versions 0.58.x through 0.58.6, authenticated users are able to retrieve sensitive information from a Metabase inst...
7.7