Currently free during beta - premium features coming soon. Subscribe now to lock in early access.
CVE

EU Regulatory Changes

648 changes tracked across 24 compliance frameworks including DORA, NIS2, GDPR, EU AI Act, Cyber Resilience Act, and more.

All DORA NIS2 GDPR CSRD MaRisk ISO27001 EU_AI_ACT CRA DSA DMA eIDAS2 SOC2 PCI_DSS HIPAA ISO42001 AMLD6 PSD3 DATA_ACT GPSR CER EUDR CVE BREACH AI_SAFETY
CVE-2026-44761 (CVSS 9.1) — SAP Commerce Cloud could retain a sample OAuth2 client with publicly documented sample cr...
KEV: CVE-2008-4128 — Cisco IOS (Cisco IOS Cross-Site Request Forgery Vulnerability)
CVE-2026-40468 (CVSS 9.1) — Integer overflow vulnerability has been found in "builtin.c" program file of gawk. This i...
CVE-2026-61498 (CVSS 9.8) — Vitec Flamingo 4.12.2 contains an unauthenticated OS command injection vulnerability in t...
CVE-2026-61500 (CVSS 9.8) — Rejetto HFS 3.0.0 through 3.2.0 derives its session-cookie signing key from the non-crypt...
CVE-2026-59801 (CVSS 9.8) — 9Router through version 0.4.41 contains an unauthenticated access vulnerability that allo...
CVE-2026-62327 (CVSS 9.1) — 9Router through version 0.4.41 contain an unauthenticated information disclosure vulnerab...
CVE-2026-56271 (CVSS 9.8) — Flowise before 3.1.0 (affected versions 3.0.13 and earlier) uses weak hardcoded default J...
CVE-2026-15511 (CVSS 9.8) — A vulnerability was determined in Comfast CF-WR631AX V3 up to 2.7.0.8. Affected by this v...
CVE-2026-60090 (CVSS 9.8) — PraisonAI before 4.6.78 fails to validate the caller-controlled dimension argument in the...
A new critical vulnerability, CVE-2026-60090, has been published with a CVSS score of 9.8, affecting PraisonAI versions prior to 4.6.78. The flaw lies in the failure to validate a caller-controlled...
Read analysis →
CVE-2026-61445 (CVSS 9.9) — PraisonAI before 4.6.78 contains arbitrary file write and command execution vulnerabiliti...
A critical vulnerability has been published under CVE-2026-61445, affecting PraisonAI versions prior to 4.6.78. The flaw, rated CVSS 9.9, resides in the AICoder component and allows arbitrary file ...
Read analysis →
CVE-2026-61447 (CVSS 10.0) — PraisonAI before 1.6.78 contains a remote code execution vulnerability in CodeAgent._exe...
A critical vulnerability has been published under CVE-2026-61447, affecting PraisonAI versions prior to 1.6.78. The flaw carries a CVSS score of 10.0, the highest severity rating, and involves a re...
Read analysis →
CVE-2026-56291 (CVSS 9.8) — The Joomla extension Balbooa Forms is vulnerable to an unauthenticated arbitrary file upl...
CVE-2026-59214 (CVSS 7.3) — Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. Pri...
CVE-2026-15282 (CVSS 9.8) — The Instant Appointment plugin for WordPress is vulnerable to arbitrary file uploads due ...
CVE-2026-59792 (CVSS 9.6) — In JetBrains IntelliJ IDEA before 2026.1.4, 2026.2 code execution via path traversal in ...
CVE-2026-61459 (CVSS 9.8) — MCP Server Kubernetes before 3.9.0 contains an argument injection vulnerability in struct...
CVE-2026-12761 (CVSS 9.8) — The miniOrange Social Login and Register (Discord, Google, Twitter, LinkedIn) plugin for ...
KEV: CVE-2026-56291 — Balbooa Forms (Balbooa Forms Unrestricted Upload of File with Dangerous Type Vulnerability)
KEV: CVE-2026-48939 — iCagenda iCagenda (iCagenda Unrestricted Upload of File with Dangerous Type Vulnerability)