Currently free during beta - premium features coming soon. Subscribe now to lock in early access.
CVE

EU Regulatory Changes

648 changes tracked across 24 compliance frameworks including DORA, NIS2, GDPR, EU AI Act, Cyber Resilience Act, and more.

All DORA NIS2 GDPR CSRD MaRisk ISO27001 EU_AI_ACT CRA DSA DMA eIDAS2 SOC2 PCI_DSS HIPAA ISO42001 AMLD6 PSD3 DATA_ACT GPSR CER EUDR CVE BREACH AI_SAFETY
CVE-2026-14958 (CVSS 9.1) — IBM Aspera Faspex 5 5.0.0 through 5.0.15.4 could allow a remote authenticated attacker to...
CVE-2026-14959 (CVSS 9.1) — IBM Aspera Faspex 5 5.0.0 through 5.0.15.4 could allow a remote authenticated attacker to...
CVE-2026-14973 (CVSS 9.3) — IBM Aspera Desktop App 1.0.5 through 1.0.19 IBM Aspera for desktop can allow files to be ...
CVE-2026-48144 (CVSS 9.1) — Improper Validation of Certificate with Host Mismatch vulnerability in Apache Thrift c_gl...
CVE-2026-55971 (CVSS 9.8) — Heap-based Buffer Overflow vulnerability in Apache Thrift C++ bindings. This issue affec...
CVE-2026-58023 (CVSS 9.1) — Out-of-bounds Read vulnerability in Apache Thrift c_glib bindings. This issue affects Ap...
CVE-2026-58662 (CVSS 9.1) — Improper Validation of Specified Quantity in Input, Out-of-bounds Read vulnerability in A...
KEV: CVE-2025-68686 — Fortinet FortiOS (Fortinet FortiOS Exposure of Sensitive Information to an Unauthorized Actor V...
KEV: CVE-2026-16812 — Arista VeloCloud Orchestrator (Arista VeloCloud Orchestrator On-Prem OS Command Injection Vulne...
CVE-2026-66012 (CVSS 10.0) — SiYuan before v3.7.2 contains a missing authorization vulnerability in the POST /mcp ker...
CVE-2026-65689 (CVSS 9.8) — Bold Reports Standalone Report Designer before 14.1.12 contains a missing filepath valida...
CVE-2026-65700 (CVSS 9.8) — h2oGPT through 0.2.1 contains a path traversal vulnerability in the OpenAI-compatible fil...
CVE-2026-15981 (CVSS 9.8) — The SAML Single Sign On – SSO Login plugin for WordPress is vulnerable to Authentication ...
CVE-2024-58354 (CVSS 9.9) — cal.com (calcom repository, later renamed cal.diy) is affected by a repository takeover v...
CVE-2025-71389 (CVSS 10.0) — Cal.com (calcom/cal.diy) before 5.9.9 is vulnerable to unauthenticated remote code execu...
CVE-2026-63732 (CVSS 9.9) — 9router 0.4.59 (fixed in 0.4.60) contains a chain of vulnerabilities: a hardcoded default...
CVE-2026-50517 (CVSS 9.9) — Deserialization of untrusted data in M365 Copilot allows an authorized attacker to execut...
CVE-2026-54120 (CVSS 9.9) — Improper input validation in Microsoft Surface allows an authorized attacker to execute c...
CVE-2026-56160 (CVSS 9.1) — Improper authorization in Azure Red Hat OpenShift (ARO) allows an authorized attacker to ...
CVE-2026-56165 (CVSS 9.8) — Heap-based buffer overflow in Microsoft Account allows an unauthorized attacker to execut...