Currently free during beta - premium features coming soon. Subscribe now to lock in early access.
CVE

EU Regulatory Changes

648 changes tracked across 24 compliance frameworks including DORA, NIS2, GDPR, EU AI Act, Cyber Resilience Act, and more.

All DORA NIS2 GDPR CSRD MaRisk ISO27001 EU_AI_ACT CRA DSA DMA eIDAS2 SOC2 PCI_DSS HIPAA ISO42001 AMLD6 PSD3 DATA_ACT GPSR CER EUDR CVE BREACH AI_SAFETY
CVE-2026-9135 (CVSS 9.9) — IBM Langflow OSS 1.0.0 through 1.10.0 Langflow versions up to 1.9.2 (commit 94981c443d4918...
CVE-2026-15091 (CVSS 9.3) — IBM Engineering AI Hub 1.0.0, 1.1.0, and 1.2.0 could allow a remote attacker to execute a...
CVE-2026-8476 (CVSS 9.9) — IBM Langflow OSS 1.0.0 through 1.10.0 contain a critical remote code execution vulnerabili...
CVE-2026-8481 (CVSS 9.9) — IBM Langflow OSS 1.0.0 through 1.10.0 contain a critical remote code execution vulnerabili...
CVE-2026-8635 (CVSS 9.9) — IBM Langflow OSS 1.0.0 through 1.10.0 allows authenticated users to escalate privileges to...
CVE-2026-8859 (CVSS 9.9) — IBM Langflow OSS 1.0.0 through 1.10.0 Langflow could allow an attacker to write arbitrary ...
CVE-2026-13446 (CVSS 9.8) — IBM Langflow OSS 1.0.0 through 1.10.1 contains hard-coded credentials, such as a password...
CVE-2026-56398 (CVSS 7.3) — Open WebUI before 0.9.5 contains a stored cross-site scripting vulnerability in the OAuth...
CVE-2026-56400 (CVSS 8.3) — open-webui before 0.3.14 contains a cross-origin resource sharing misconfiguration allowi...
CVE-2023-49899 (CVSS 9.8) — An unauthenticated remote attacker can execute any command on the affected device due to ...
CVE-2026-63087 (CVSS 9.8) — Grafana OnCall through 1.16.11 contains an unauthenticated access vulnerability that allo...
CVE-2026-63089 (CVSS 9.3) — WireGuard Easy through 15.3.0, fixed in commit 66b292b, contains a cryptographically weak...
CVE-2026-14956 (CVSS 9.8) — The Bricksforge plugin for WordPress is vulnerable to Privilege Escalation in all version...
CVE-2026-62241 (CVSS 9.1) — clawvet self-hosted API server (apps/api) before 0.7.5 hard-codes a fallback JWT secret (...
KEV: CVE-2026-58644 — Microsoft SharePoint (Microsoft SharePoint Deserialization of Untrusted Data Vulnerability)
KEV: CVE-2026-25089 — Fortinet FortiSandbox (Fortinet FortiSandbox OS Command Injection Vulnerability)
KEV: CVE-2026-39808 — Fortinet FortiSandbox (Fortinet FortiSandbox OS Command Injection Vulnerability)
CVE-2026-59836 (CVSS 7.5) — A improper certificate validation vulnerability in Fortinet FortiClientEMS 7.4.3 through ...
CVE-2026-45063 (CVSS 9.1) — Symfony is a PHP framework for web and console applications and a set of reusable PHP com...
CVE-2026-45069 (CVSS 9.1) — Symfony is a PHP framework for web and console applications and a set of reusable PHP com...