VulnSea

Daily digest

Thursday 19 February 2026

A busier-than-usual day with 14 new CVEs (recent average about 12). Severity skewed high: 2 critical and 8 high, 71% of the total. 4 arrived with exploitation evidence or public exploit code already attached. parall was the most-affected vendor with 3.

14
New CVEs
2
Critical
0
KEV additions
0
Records changed

New this day, ranked by depth score

The 12 that matter most of the 14 published.

CVE-2026-25940High· 8.1PoC
7mo ago

jsPDF is a library to generate PDFs in JavaScript

jsPDF is a library to generate PDFs in JavaScript. Prior to 4.2.0, user control of properties and methods of the Acroform module allows users to inject arbitrary PDF objects, such as JavaScript actions. If given the possibility to pass u…

▾ Midnightparall · jspdfEPSS 0.63%via NVD
CVE-2026-25755High· 8.1PoC
7mo ago

jsPDF is a library to generate PDFs in JavaScript

jsPDF is a library to generate PDFs in JavaScript. Prior to 4.2.0, user control of the argument of the `addJS` method allows an attacker to inject arbitrary PDF objects into the generated document. By crafting a payload that escapes the …

▾ Midnightparall · jspdfEPSS 0.80%via NVD
CVE-2025-9953Critical· 9.8
7mo ago

Authorization Bypass Through User-Controlled SQL Primary Key vulnerability in DATABASE Software Training Consulting Ltd

Authorization Bypass Through User-Controlled SQL Primary Key vulnerability in DATABASE Software Training Consulting Ltd. Databank Accreditation Software allows SQL Injection. This issue affects Databank Accreditation Software: before 20…

▾ MidnightEPSS 0.36%via NVD
CVE-2025-13590Critical· 9.1
7mo ago

Authenticated arbitrary file upload via a System REST API requiring administrator permission.

A malicious actor with administrative privileges can upload an arbitrary file to a user-controlled location within the deployment via a system REST API. Successful uploads may lead to remote code execution. By leveraging the vulnerabi…

▾ MidnightWSO2 · WSO2 API ManagerEPSS 0.70%via CVEORG
CVE-2026-24834High· 8.8
7mo ago

Kata Container to Guest micro VM privilege escalation

Kata Container to Guest micro VM privilege escalation

▾ Twilightkata-containers · github.com/kata-containers/kata-containers/src/runtimeEPSS 0.22%via OSV
CVE-2025-12821High· 8.8
7mo ago

The NewsBlogger theme for WordPress is vulnerable to Cross-Site Request Forgery in versions 0.2.5.6 to 0.2.5.9

The NewsBlogger theme for WordPress is vulnerable to Cross-Site Request Forgery in versions 0.2.5.6 to 0.2.5.9. This is due to missing or incorrect nonce validation on the newsblogger_install_and_activate_plugin() function. This makes i…

▾ Twilightspicethemes · NewsBloggerEPSS 0.35%via NVD
CVE-2025-12107High· 8.4
7mo ago

The Velocity template engine, utilized by the affected product, accepts and processes template syntax without sufficient sanitization or validation of user-controlled input

The Velocity template engine, utilized by the affected product, accepts and processes template syntax without sufficient sanitization or validation of user-controlled input. This allows an authenticated administrator to inject arbitrary …

▾ Twilightwso2 · identity_serverEPSS 0.65%via NVD
CVE-2026-27194High
7mo ago

D-Tale affected by Remote Code Execution through the /save-column-filter endpoint

D-Tale affected by Remote Code Execution through the /save-column-filter endpoint

▾ Twilightdtale · dtaleEPSS 0.96%via OSV
CVE-2026-26278High· 7.5
7mo ago

fast-xml-parser allows users to validate XML, parse XML to JS object, or build XML from JS object without C/C++ based libraries and no callback

fast-xml-parser allows users to validate XML, parse XML to JS object, or build XML from JS object without C/C++ based libraries and no callback. In versions 4.1.3 through 5.3.5, the XML parser can be forced to do an unlimited amount of e…

▾ Twilightnaturalintelligence · fast-xml-parserEPSS 0.97%via NVD
CVE-2026-25535High· 7.5
7mo ago

jsPDF is a library to generate PDFs in JavaScript

jsPDF is a library to generate PDFs in JavaScript. Prior to 4.2.0, user control of the first argument of the `addImage` method results in denial of service. If given the possibility to pass unsanitized image data or URLs to the `addImage…

▾ Twilightparall · jspdfEPSS 0.92%via NVD
CVE-2026-25527Medium· 5.3PoC
7mo ago

changedetection.io is a free open source web page change detection tool. In versions prior to 0.53.2, the `/static/<group>/<filename>` ro…

changedetection.io is a free open source web page change detection tool. In versions prior to 0.53.2, the `/static/<group>/<filename>` route accepts `group=".."`, which causes `send_from_directory("static/..", filename)` to execute. This…

▾ Twilightchangedetection-io · changedetection-ioEPSS 0.89%via OSV
CVE-2026-27199MediumPoC
7mo ago

Werkzeug safe_join() allows Windows special device names

Werkzeug safe_join() allows Windows special device names

▾ Twilightwerkzeug · werkzeugEPSS 0.54%via OSV

Most-affected vendors

By CVEs published in the period.