VulnSea

Daily digest

Wednesday 18 February 2026

A heavy day: 26 new CVEs, well above the recent average of about 15. Severity skewed high: 5 critical and 13 high, 69% of the total. 9 arrived with exploitation evidence or public exploit code already attached. codeastro was the most-affected vendor with 3.

26
New CVEs
5
Critical
0
KEV additions
0
Records changed

New this day, ranked by depth score

The 12 that matter most of the 26 published.

CVE-2025-70152Critical· 9.8PoC
7mo ago

code-projects Community Project Scholars Tracking System 1.0 is vulnerable to SQL Injection in the admin user management endpoints /admin/save_user.php and /admin/update_user.php

code-projects Community Project Scholars Tracking System 1.0 is vulnerable to SQL Injection in the admin user management endpoints /admin/save_user.php and /admin/update_user.php. These endpoints lack authentication checks and directly c…

▾ Abyssalfabian · scholars_tracking_systemEPSS 0.45%via NVD
CVE-2025-70150Critical· 9.8PoC
7mo ago

CodeAstro Membership Management System 1.0 contains a missing authentication vulnerability in delete_members.php that allows unauthenticated attackers to delete arbitrary member records via the id parameter.

CodeAstro Membership Management System 1.0 contains a missing authentication vulnerability in delete_members.php that allows unauthenticated attackers to delete arbitrary member records via the id parameter.

▾ Abyssalcodeastro · membership_management_systemEPSS 0.66%via NVD
CVE-2025-70149Critical· 9.8PoC
7mo ago

CodeAstro Membership Management System 1.0 is vulnerable to SQL Injection in print_membership_card.php via the ID parameter.

CodeAstro Membership Management System 1.0 is vulnerable to SQL Injection in print_membership_card.php via the ID parameter.

▾ Abyssalcodeastro · membership_management_systemEPSS 0.39%via NVD
CVE-2025-70141Critical· 9.4PoC
7mo ago

SourceCodester Customer Support System 1.0 contains an incorrect access control vulnerability in ajax.php

SourceCodester Customer Support System 1.0 contains an incorrect access control vulnerability in ajax.php. The AJAX dispatcher does not enforce authentication or authorization before invoking administrative methods in admin_class.php bas…

▾ Abyssaloretnom23 · customer_support_systemEPSS 0.69%via NVD
CVE-2025-70146Critical· 9.1PoC
7mo ago

Missing authentication in multiple administrative action scripts under /admin/ in ProjectWorlds Online Time Table Generator 1.0 allows remote attackers to perform unauthorized administrative operations (e.g.,adding records, deleting reco…

Missing authentication in multiple administrative action scripts under /admin/ in ProjectWorlds Online Time Table Generator 1.0 allows remote attackers to perform unauthorized administrative operations (e.g.,adding records, deleting reco…

▾ Abyssalprojectworlds · online_time_table_generatorEPSS 0.57%via NVD
CVE-2025-70151High· 8.8PoC
7mo ago

code-projects Scholars Tracking System 1.0 allows an authenticated attacker to achieve remote code execution via unrestricted file upload

code-projects Scholars Tracking System 1.0 allows an authenticated attacker to achieve remote code execution via unrestricted file upload. The endpoints update_profile_picture.php and upload_picture.php store uploaded files in a web-acce…

▾ Midnightfabian · scholars_tracking_systemEPSS 0.70%via NVD
CVE-2025-70148High· 7.5PoC
7mo ago

Missing authentication and authorization in print_membership_card.php in CodeAstro Membership Management System 1.0 allows unauthenticated attackers to access membership card data of arbitrary users via direct requests with a manipulated…

Missing authentication and authorization in print_membership_card.php in CodeAstro Membership Management System 1.0 allows unauthenticated attackers to access membership card data of arbitrary users via direct requests with a manipulated…

▾ Midnightcodeastro · membership_management_systemEPSS 0.43%via NVD
CVE-2025-70147High· 7.5PoC
7mo ago

Missing authentication in /admin/student.php and /admin/teacher.php in ProjectWorlds Online Time Table Generator 1.0 allows remote attackers to obtain sensitive information (including plaintext password field values) via direct HTTP GET …

Missing authentication in /admin/student.php and /admin/teacher.php in ProjectWorlds Online Time Table Generator 1.0 allows remote attackers to obtain sensitive information (including plaintext password field values) via direct HTTP GET …

▾ Midnightprojectworlds · online_time_table_generatorEPSS 0.52%via NVD
CVE-2026-2670High· 7.2PoC
7mo ago

A vulnerability was identified in Advantech WISE-6610-NB, WISE-6610-EB, WISE-6610-TB, WISE-6610-JB, WISE-6610-CB, WISE-6610-EL-NB, WISE-6610-EL-EB, WISE-6610-EL-TB, WISE-6610-EL-JB, WISE-6610-EL-CB, WISE-6610P-DEA, WISE-6610P-DNA and WIS…

A vulnerability was identified in Advantech WISE-6610-NB, WISE-6610-EB, WISE-6610-TB, WISE-6610-JB, WISE-6610-CB, WISE-6610-EL-NB, WISE-6610-EL-EB, WISE-6610-EL-TB, WISE-6610-EL-JB, WISE-6610-EL-CB, WISE-6610P-DEA, WISE-6610P-DNA and WIS…

▾ MidnightEPSS 3.6%via NVD
CVE-2026-26318High· 8.8
7mo ago

Command Injection via Unsanitized `locate` Output in `versions()` — systeminformation

Command Injection via Unsanitized `locate` Output in `versions()` — systeminformation

▾ Twilightsysteminformation · systeminformationEPSS 1.3%via GHSA
CVE-2025-14009High· 8.8
7mo ago

A critical vulnerability exists in the NLTK downloader component of nltk/nltk, affecting all versions

A critical vulnerability exists in the NLTK downloader component of nltk/nltk, affecting all versions. The _unzip_iter function in nltk/downloader.py uses zipfile.extractall() without performing path validation or security checks. This a…

▾ Twilightnltk · nltkEPSS 0.95%via NVD
CVE-2026-24708High· 8.2
7mo ago

An issue was discovered in OpenStack Nova before 30.2.2, 31 before 31.2.1, and 32 before 32.1.1

An issue was discovered in OpenStack Nova before 30.2.2, 31 before 31.2.1, and 32 before 32.1.1. By writing a malicious QCOW header to a root or ephemeral disk and then triggering a resize, a user may convince Nova's Flat image backend t…

▾ TwilightOpenStack · NovaEPSS 0.38%via NVD

Most-affected vendors

By CVEs published in the period.