Currently free during beta - premium features coming soon. Subscribe now to lock in early access.
CVE

EU Regulatory Changes

656 changes tracked across 24 compliance frameworks including DORA, NIS2, GDPR, EU AI Act, Cyber Resilience Act, and more.

All DORA NIS2 GDPR CSRD MaRisk ISO27001 EU_AI_ACT CRA DSA DMA eIDAS2 SOC2 PCI_DSS HIPAA ISO42001 AMLD6 PSD3 DATA_ACT GPSR CER EUDR CVE BREACH AI_SAFETY
CVE-2026-10109 (CVSS 9.8) — IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.4 is vulnerable to remote code exe...
CVE-2026-10134 (CVSS 10.0) — IBM Langflow OSS 1.0.0 through 1.9.3 allows an attacker to read every secret available t...
CVE-2026-10140 (CVSS 9.6) — IBM Langflow OSS 1.0.0 through 1.10.0 voice mode contains improper shared-state handling ...
CVE-2026-11708 (CVSS 9.3) — IBM WebSphere Application Server 9.0, and 8.5 is affected by a cross-site scripting vulne...
CVE-2026-11712 (CVSS 9.3) — IBM WebSphere Application Server 9.0, and 8.5 is affected by a cross-site scripting vulne...
CVE-2026-7663 (CVSS 9.1) — IBM Langflow OSS 1.0.0 through 1.9.6 could allow unauthenticated attackers to access prote...
CVE-2026-7803 (CVSS 9.8) — IBM Langflow OSS 1.0.0 through 1.10.0 could allow arbitrary code execution due to improper...
CVE-2026-7871 (CVSS 9.8) — IBM Langflow OSS 1.0.0 through 1.10.0 allows users with Redis access to execute arbitrary ...
CVE-2026-7873 (CVSS 9.9) — IBM Langflow OSS 1.0.0 through 1.10.0 allows authenticated attackers to execute arbitrary ...
CVE-2026-7874 (CVSS 9.1) — IBM Langflow OSS 1.0.0 through 1.10.0 Langflow could allow disclosure of all stored creden...
CVE-2026-58449 (CVSS 9.8) — txtai through 9.10.0, fixed in commit 11b32da, exposes an API /reindex endpoint whose fun...
CVE-2026-56278 (CVSS 9.1) — Flowise before 3.1.0 (affected versions 3.0.13 and earlier) uses a weak hardcoded default...
CVE-2026-56700 (CVSS 9.8) — Grav CMS before 2.0.0-beta.2 contains multiple code-execution vulnerabilities. Three unsa...
KEV: CVE-2026-48558 — SimpleHelp SimpleHelp (SimpleHelp Authentication Bypass Vulnerability)
CVE-2026-2053 (CVSS 8.3) — The WSO2 API Manager's message flow component, when processing WS-Addressing headers, does...
A new vulnerability, CVE-2026-2053, has been published with a CVSS score of 8.3, indicating a high severity risk. The issue affects the WSO2 API Manager, specifically its message flow component, wh...
Read analysis →
CVE-2026-53914 (CVSS 6.7) — In JetBrains Kotlin before 2.4.20 code execution was possible via unsafe deserialization ...
A new vulnerability, CVE-2026-53914, has been published with a CVSS score of 6.7, affecting JetBrains Kotlin versions prior to 2.4.20. The issue allows code execution through unsafe deserialization...
Read analysis →
CVE-2026-57926 (CVSS 2.6) — In JetBrains YouTrack before 2026.2.16593 the websandbox bridge was vulnerable to a proto...
A new vulnerability has been published under CVE-2026-57926, affecting JetBrains YouTrack versions prior to 2026.2.16593. The issue involves a prototype pollution attack in the websandbox bridge, w...
Read analysis →
CVE-2026-12415 (CVSS 9.8) — The Invoice Generator plugin for WordPress is vulnerable to privilege escalation due to a...
A critical vulnerability has been published under CVE-2026-12415, affecting the Invoice Generator plugin for WordPress up to version 1.0. The flaw, rated 9.8 on the CVSS scale, allows privilege esc...
Read analysis →
CVE-2026-58053 (CVSS 9.9) — Gitea act_runner with the Docker backend (through act 0.262.0) passes a workflow's contai...
A critical vulnerability, CVE-2026-58053, has been published with a CVSS score of 9.9, affecting Gitea act_runner when using the Docker backend up to version act 0.262.0. The flaw allows a maliciou...
Read analysis →
CVE-2026-56123 (CVSS 8.1) — socat versions 1.8.0.0 through 1.8.1.1 contain a heap-based buffer overflow vulnerability...