Currently free during beta - premium features coming soon. Subscribe now to lock in early access.
CVE

EU Regulatory Changes

656 changes tracked across 24 compliance frameworks including DORA, NIS2, GDPR, EU AI Act, Cyber Resilience Act, and more.

All DORA NIS2 GDPR CSRD MaRisk ISO27001 EU_AI_ACT CRA DSA DMA eIDAS2 SOC2 PCI_DSS HIPAA ISO42001 AMLD6 PSD3 DATA_ACT GPSR CER EUDR CVE BREACH AI_SAFETY
CVE-2026-56291 (CVSS 9.8) — The Joomla extension Balbooa Forms is vulnerable to an unauthenticated arbitrary file upl...
CVE-2026-59214 (CVSS 7.3) — Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. Pri...
CVE-2026-15282 (CVSS 9.8) — The Instant Appointment plugin for WordPress is vulnerable to arbitrary file uploads due ...
CVE-2026-59792 (CVSS 9.6) — In JetBrains IntelliJ IDEA before 2026.1.4, 2026.2 code execution via path traversal in ...
CVE-2026-61459 (CVSS 9.8) — MCP Server Kubernetes before 3.9.0 contains an argument injection vulnerability in struct...
CVE-2026-12761 (CVSS 9.8) — The miniOrange Social Login and Register (Discord, Google, Twitter, LinkedIn) plugin for ...
KEV: CVE-2026-56291 — Balbooa Forms (Balbooa Forms Unrestricted Upload of File with Dangerous Type Vulnerability)
KEV: CVE-2026-48939 — iCagenda iCagenda (iCagenda Unrestricted Upload of File with Dangerous Type Vulnerability)
CVE-2026-8801 (CVSS 3.5) — Path equivalence: vulnerability in Progress MOVEit Transfer (File Upload modules). This i...
CVE-2026-58122 (CVSS 9.1) — Hermes WebUI before 0.51.307 contains an authentication bypass vulnerability that allows ...
CVE-2026-58123 (CVSS 9.8) — Hermes WebUI before 0.51.788 contains an unauthenticated remote code execution vulnerabil...
CVE-2026-14894 (CVSS 9.8) — The Super Forms – Drag & Drop Form Builder plugin for WordPress is vulnerable to Arbitrar...
CVE-2026-58480 (CVSS 9.8) — Blocksy Companion Pro plugin for WordPress before 2.1.47 contains an unauthenticated arbi...
CVE-2026-47646 (CVSS 9.3) — Improper neutralization of input during web page generation ('cross-site scripting') in D...
KEV: CVE-2026-48908 — JoomShaper SP Page Builder (JoomShaper SP Page Builder Unrestricted Upload of File with Dangero...
KEV: CVE-2026-55255 — Langflow Langflow (Langflow Authorization Bypass Through User-Controlled Key Vulnerability)
KEV: CVE-2026-56290 — Joomlack Page Builder (Joomlack Page Builder Improper Access Control Vulnerability)
KEV: CVE-2026-48282 — Adobe ColdFusion (Adobe ColdFusion Path Traversal Vulnerability)
CVE-2026-40139 (CVSS 9.8) — A critical pre-authentication vulnerability exists in the authentication subsystem of Bey...
CVE-2026-40141 (CVSS 9.9) — A high-severity vulnerability exists in a web application component of BeyondTrust Remote...