Daily digest
Thursday 19 February 2026
A busier-than-usual day with 14 new CVEs (recent average about 12). Severity skewed high: 2 critical and 8 high, 71% of the total. 4 arrived with exploitation evidence or public exploit code already attached. parall was the most-affected vendor with 3.
New this day, ranked by depth score
The 12 that matter most of the 14 published.
CVE-2026-25940High· 8.1PoCjsPDF is a library to generate PDFs in JavaScript
jsPDF is a library to generate PDFs in JavaScript. Prior to 4.2.0, user control of properties and methods of the Acroform module allows users to inject arbitrary PDF objects, such as JavaScript actions. If given the possibility to pass u…
CVE-2026-25755High· 8.1PoCjsPDF is a library to generate PDFs in JavaScript
jsPDF is a library to generate PDFs in JavaScript. Prior to 4.2.0, user control of the argument of the `addJS` method allows an attacker to inject arbitrary PDF objects into the generated document. By crafting a payload that escapes the …
CVE-2025-9953Critical· 9.8Authorization Bypass Through User-Controlled SQL Primary Key vulnerability in DATABASE Software Training Consulting Ltd
Authorization Bypass Through User-Controlled SQL Primary Key vulnerability in DATABASE Software Training Consulting Ltd. Databank Accreditation Software allows SQL Injection. This issue affects Databank Accreditation Software: before 20…
CVE-2025-13590Critical· 9.1Authenticated arbitrary file upload via a System REST API requiring administrator permission.
A malicious actor with administrative privileges can upload an arbitrary file to a user-controlled location within the deployment via a system REST API. Successful uploads may lead to remote code execution. By leveraging the vulnerabi…
CVE-2026-24834High· 8.8Kata Container to Guest micro VM privilege escalation
Kata Container to Guest micro VM privilege escalation
CVE-2025-12821High· 8.8The NewsBlogger theme for WordPress is vulnerable to Cross-Site Request Forgery in versions 0.2.5.6 to 0.2.5.9
The NewsBlogger theme for WordPress is vulnerable to Cross-Site Request Forgery in versions 0.2.5.6 to 0.2.5.9. This is due to missing or incorrect nonce validation on the newsblogger_install_and_activate_plugin() function. This makes i…
CVE-2025-12107High· 8.4The Velocity template engine, utilized by the affected product, accepts and processes template syntax without sufficient sanitization or validation of user-controlled input
The Velocity template engine, utilized by the affected product, accepts and processes template syntax without sufficient sanitization or validation of user-controlled input. This allows an authenticated administrator to inject arbitrary …
CVE-2026-27194HighD-Tale affected by Remote Code Execution through the /save-column-filter endpoint
D-Tale affected by Remote Code Execution through the /save-column-filter endpoint
CVE-2026-26278High· 7.5fast-xml-parser allows users to validate XML, parse XML to JS object, or build XML from JS object without C/C++ based libraries and no callback
fast-xml-parser allows users to validate XML, parse XML to JS object, or build XML from JS object without C/C++ based libraries and no callback. In versions 4.1.3 through 5.3.5, the XML parser can be forced to do an unlimited amount of e…
CVE-2026-25535High· 7.5jsPDF is a library to generate PDFs in JavaScript
jsPDF is a library to generate PDFs in JavaScript. Prior to 4.2.0, user control of the first argument of the `addImage` method results in denial of service. If given the possibility to pass unsanitized image data or URLs to the `addImage…
CVE-2026-25527Medium· 5.3PoCchangedetection.io is a free open source web page change detection tool. In versions prior to 0.53.2, the `/static/<group>/<filename>` ro…
changedetection.io is a free open source web page change detection tool. In versions prior to 0.53.2, the `/static/<group>/<filename>` route accepts `group=".."`, which causes `send_from_directory("static/..", filename)` to execute. This…
CVE-2026-27199MediumPoCWerkzeug safe_join() allows Windows special device names
Werkzeug safe_join() allows Windows special device names
Most-affected vendors
By CVEs published in the period.