Monitor vulnerabilities that affect your stack.
Sign up free to get alerts when software you use is affected.
CVE Vulnerabilities - 21 February 2026
RSS59 vulnerabilities published on 21 February 2026
Severity:
GetSimple CMS: Unsecured File Access through Uploaded Files
CVE-2026-27202
All versions of the GetSimple CMS have a flaw that lets attackers read any file on the server. This is a serious issue because it can allow unauthorized access to sensitive data. Update to the latest ...
8.8
GetSimple CMS Fails to Restrict Access to Sensitive Files in Some Environments
CVE-2026-27161
All versions of GetSimple CMS are affected. If you use a shared hosting environment or have Apache AllowOverride disabled, sensitive files like authorization data and API keys can be accessed without ...
8.7
CollabPlatform: Malicious Sites Can Access User Account Info
CVE-2026-27579
CollabPlatform's collaboration platform allows a malicious website to access user account information, including email address, account identifiers, and MFA status. This is due to a misconfiguration i...
7.4
Moodle Backup Files Can Execute Malicious Code on Server
CVE-2026-26045
GHSA-ggxq-2mg9-8966
Moodle's backup and restore feature has a security flaw that could allow an attacker to execute malicious code on the server. This requires a malicious user to have access to restore capabilities, whi...
7.2
Moodle TeX Filter with ImageMagick: Command Injection Risk
CVE-2026-26046
The TeX filter in Moodle, when used with ImageMagick, can be manipulated by an administrator to execute unintended system commands. This requires administrative access, but could allow an attacker to ...
7.2
OpenSift allows accessing private networks via malicious URLs
CVE-2026-27170
A bug in OpenSift versions 1.1.2-alpha and earlier lets attackers access private networks from the OpenSift server. This can happen if the server is configured to ingest URLs from untrusted sources. T...
7.1
Unauthorized form deletion in weMail plugin for WordPress
CVE-2025-14339
The weMail plugin for WordPress allows an attacker to delete all email forms without permission. This is a serious issue because it lets anyone with some technical knowledge delete sensitive marketing...
6.5
Metabase allows authenticated users to access sensitive database credentials
CVE-2026-27464
Some Metabase users can access database login information, which could be misused. This is fixed in version 0.57.13 and 0.58.7. To protect your database, update to one of these versions or disable ema...
6.5
Moodle TeX Formula Editor Can Overload Servers
CVE-2026-26047
GHSA-cg8j-5cr2-568q
Moodle's TeX formula editor is at risk of being overwhelmed by malicious input, potentially causing the server to become slow or unresponsive. This could happen when a user enters a specially crafted ...
6.5
Apache Airflow error reporting may leak sensitive data
CVE-2025-65995
GHSA-gfw7-2v73-69wg
A bug in Apache Airflow's error reporting could expose sensitive information in the UI. If you use Airflow, consider upgrading to 3.1.5rc1 or 2.11.1 to prevent any potential data breaches. If you're n...
6.5
EmployeeController in SSM-ERP allows unauthorized remote access
CVE-2026-2860
A security issue in the EmployeeController of SSM-ERP allows unauthorized users to access the system remotely. This vulnerability has been publicly disclosed, so it's possible that attackers may use i...
5.3
OpenSift: Data Loss or Corruption on Older Versions
CVE-2026-27189
Using OpenSift versions 1.1.2-alpha or earlier can lead to data loss or corruption, especially when multiple people access and update the same data at the same time. This is because the tool doesn't p...
5.8
Aardappel Lobster 2025.4 Has Uncontrolled Recursion Flaw
CVE-2026-2887
A bug in Aardappel Lobster version 2025.4 can cause a software loop that uses up too much computer resources. This only happens when an attacker has direct access to the affected computer. To fix this...
4.8
janet-lang janet: Local data leak through handleattr function
CVE-2026-2869
A security issue exists in janet up to version 1.40.1 that could allow an attacker on the same computer to access sensitive data they shouldn't. This issue can be fixed by updating to version 1.41.0. ...
4.8
SSM-ERP Picture Deletion Vulnerability Allows Remote Attackers to Access Files
CVE-2026-2864
The SSM-ERP system has a security flaw in its picture deletion function, which allows attackers to access files on the server. This means that a hacker could potentially access sensitive files on your...
5.3
LinkAce self-hosted link archive has a security risk through its Atom feed
CVE-2026-27458
LinkAce versions 2.4.2 and below have a security issue that allows an attacker to inject malicious code into the web page when a user visits a specially crafted link. This could potentially allow an a...
8.7
SSM-ERP allows attackers to delete arbitrary files
CVE-2026-2863
The SSM-ERP system has a flaw that allows attackers to delete any file on the server. This could lead to data loss and disruption of the system. Users should check with the vendor for an update and ap...
5.3
GetSimple CMS Allows Attackers to Inject Malicious Code via SVG Files
CVE-2026-27147
GetSimple CMS versions all have a security issue with uploaded SVG files. This means an authenticated user can upload a malicious file that can harm your website. Update to a fixed version of the soft...
6.9
ASN.1 TypeScript Library Leaks Sensitive Data from INTEGER Decodes
CVE-2026-27452
The ASN.1 TypeScript library, used for encoding and decoding data, has a bug in versions 11.0.5 and below. If certain INTEGER data is decoded, sensitive data could be accidentally exposed. Update to v...
9.2
Foswiki: Unpatched version may leak sensitive information
CVE-2026-2861
A weakness in older versions of Foswiki may allow unauthorized access to sensitive information. This vulnerability is now being exploited, so upgrading to the latest version (2.1.11) is recommended to...
5.5
LearnPress Export Import Plugin: Unauthorized Data Deletion in LearnPress
CVE-2026-1787
A security flaw in the LearnPress Export Import plugin for WordPress allows unauthorized users to delete courses that have been migrated from Tutor LMS. This could lead to loss of important course dat...
4.8
GetSimple CMS: Unprotected File Upload Allows Unauthorized File Upload
CVE-2026-27146
GetSimple CMS, a content management system, does not protect against unauthorized file uploads. This means an attacker can trick a logged-in user into uploading malicious files without their knowledge...
7.1
Flask Web Framework Fails to Protect User Info in Caches
CVE-2026-27205
GHSA-68rp-wp8r-4726
Flask versions 3.1.2 and earlier may leak sensitive user information to caches, potentially compromising user data. This issue occurs when a caching proxy doesn't ignore responses with cookies and doe...
7.8
CCExtractor: Local Attack Possible with Outdated Version
CVE-2026-2889
A security issue in CCExtractor versions up to 0.96.5 allows an attacker with local access to potentially cause system instability. To fix this, update CCExtractor to version 0.96.6 as soon as possibl...
4.8
BigBlueButton: Muted Audio Sent to Server When Joining
CVE-2026-27467
BigBlueButton versions 3.0.19 and below send audio to the server when joining a muted session. This could potentially allow malicious server operators to access audio data. Update to version 3.0.20 or...
2.4