Currently free during beta - premium features coming soon. Subscribe now to lock in early access.
CVE

EU Regulatory Changes

648 changes tracked across 24 compliance frameworks including DORA, NIS2, GDPR, EU AI Act, Cyber Resilience Act, and more.

All DORA NIS2 GDPR CSRD MaRisk ISO27001 EU_AI_ACT CRA DSA DMA eIDAS2 SOC2 PCI_DSS HIPAA ISO42001 AMLD6 PSD3 DATA_ACT GPSR CER EUDR CVE BREACH AI_SAFETY
CVE-2026-9205 (CVSS 7.4) — IBM Langflow OSS contains a weak cryptographic key derivation vulnerability in the ensure_...
CVE-2026-53984 (CVSS 9.1) — Ground Station prior to 0.6.0 contains an unauthenticated database-destruction and arbitr...
CVE-2026-67622 (CVSS 9.9) — Flowise through 3.1.4 contains an insecure direct object reference vulnerability in the O...
CVE-2026-70558 (CVSS 9.8) — Dinky's POST /download/uploadFromRsByLocal handler passes the caller-supplied path parame...
CVE-2026-50515 (CVSS 9.9) — Deserialization of untrusted data in Azure Service Bus allows an authorized attacker to e...
CVE-2026-56162 (CVSS 10.0) — Improper authentication in Azure SQL Database allows an unauthorized attacker to elevate...
CVE-2026-62830 (CVSS 9.9) — Missing authorization in Azure SRE Agent allows an authorized attacker to elevate privile...
CVE-2026-63508 (CVSS 10.0) — Missing authentication for critical function in Microsoft Planetary Computer Pro allows ...
CVE-2026-68823 (CVSS 9.1) — Exposed dangerous method or function in Azure Confidential Ledger allows an authorized at...
CVE-2026-70332 (CVSS 9.6) — Server-side request forgery (ssrf) in Microsoft Office SharePoint allows an unauthorized ...
CVE-2026-70615 (CVSS 9.9) — boringproxy through 0.10.0 contains a newline injection vulnerability that allows authent...
KEV: CVE-2026-63077 — JetBrains TeamCity (JetBrains TeamCity Deserialization of Untrusted Data Vulnerability)
KEV: CVE-2026-18556 — N-able N-central (N-able N-central Authentication Bypass Using an Alternate Path or Channel Vul...
KEV: CVE-2026-34486 — Apache Tomcat (Apache Tomcat Missing Encryption of Sensitive Data Vulnerability)
KEV: CVE-2026-9198 — IBM Langflow (IBM Langflow Code Injection Vulnerability)
CVE-2026-61515 (CVSS 9.8) — Puwell IP Camera firmware versions 2.x through 4.x contains an unauthenticated command in...
CVE-2026-69098 (CVSS 9.8) — kotaemon through 0.12.0 contains an insecure deserialization vulnerability in the check_c...
CVE-2026-70552 (CVSS 9.8) — MaxSite CMS 109.5 and earlier contains an authentication bypass vulnerability in the AJAX...
CVE-2026-70554 (CVSS 9.8) — MaxSite CMS contains a PHP object injection vulnerability that allows unauthenticated att...
KEV: CVE-2026-18577 — N-able N-central (N-able N-central Authentication Bypass Using an Alternate Path or Channel Vul...