NVD disclosure day

Published threat advisories for February 18, 2026

CVE advisoryCRITICAL

CVE-2025-70152

Scholars Tracking System 1.0 SQL Injection in Admin User Management.

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

The Scholars Tracking System is vulnerable to SQL injection through its unauthenticated administrative endpoints. This could allow an attacker to manipulate user data, leading to unauthorized access or modification. Confirm if this system is in use and exposed to assess risk.

CVE advisoryCRITICAL

CVE-2025-70150

CodeAstro Membership Management Missing Auth Arbitrary Delete.

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A critical vulnerability exists in the CodeAstro Membership Management System, allowing unauthenticated attackers to delete arbitrary member records. This missing authentication flaw in `delete_members.php` could lead to data loss or service disruption if the system is reachable.

CVE advisoryCRITICAL

CVE-2025-70149

CodeAstro Membership Management System SQL Injection Vulnerability

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A critical SQL injection vulnerability exists in the CodeAstro Membership Management System's `print_membership_card.php` script, allowing network-accessible exploitation without authentication. This could lead to unauthorized access or modification of sensitive membership data. It is uncertain if this system is in use

CVE advisoryCRITICAL

CVE-2025-70146

ProjectWorlds Time Table Generator Missing Authentication Allows Unauthorized Administrative Access

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

Remote attackers can add or delete records in the ProjectWorlds Online Time Table Generator by sending direct HTTP requests to administrative scripts without a valid session. This missing authentication vulnerability could lead to unauthorized data manipulation, impacting system data integrity and availability. It is i

CVE advisoryCRITICAL

CVE-2025-70141

SourceCodester Customer Support System Incorrect Access Control Vulnerability

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

An access control vulnerability exists in SourceCodester Customer Support System 1.0, allowing unauthenticated remote attackers to perform sensitive administrative operations. This could result in unauthorized creation, modification, or deletion of customer data, user accounts, and other application records. Organizati