Currently free during beta - premium features coming soon. Subscribe now to lock in early access.
CVE

EU Regulatory Changes

777 changes tracked across 24 compliance frameworks including DORA, NIS2, GDPR, EU AI Act, Cyber Resilience Act, and more.

All DORA NIS2 GDPR CSRD MaRisk ISO27001 EU_AI_ACT CRA DSA DMA eIDAS2 SOC2 PCI_DSS HIPAA ISO42001 AMLD6 PSD3 DATA_ACT GPSR CER EUDR CVE BREACH AI_SAFETY
CVE-2026-78211 (CVSS 9.8) — 4MOSAn GCB Doctor developed by 4MOSAn Security Technology has a OS Command Injection vuln...
CVE-2026-5388 (CVSS 9.8) — justhtml before 1.15.0 contains multiple security issues in URL sanitization helpers (clea...
CVE-2026-7808 (CVSS 9.8) — justhtml before 1.16.0 contains multiple HTML sanitization bypass issues that can allow ac...
CVE-2026-8445 (CVSS 9.8) — justhtml versions <= 1.11.0 (fixed in 1.12.0) do not sufficiently escape HTML-significant ...
CVE-2026-78207 (CVSS 9.4) — exceljs-hardened before 5.0.0 contains a prototype pollution vulnerability in the deepMer...
CVE-2026-78167 (CVSS 10.0) — A weakness has been identified in EFM ipTIME T16000M 14.20.2. The impacted element is th...
CVE-2026-78168 (CVSS 9.8) — A security vulnerability has been detected in EFM ipTIME T24000M up to 14.20.0. This affe...
CVE-2026-78169 (CVSS 9.9) — A vulnerability was detected in UTT HiPER 1250GW up to 3.2.7-210907-180535. This impacts ...
CVE-2026-78050 (CVSS 9.9) — A vulnerability was found in Comfast CF-N1-S 2.6.0.1. The affected element is the functio...
CVE-2026-78003 (CVSS 9.8) — The Mailgun for WordPress plugin for WordPress is vulnerable to Server-Side Request Forge...
CVE-2026-77946 (CVSS 10.0) — A vulnerability was determined in TRENDnet TEW-821DAP 2.2.01b05. Affected by this vulner...
CVE-2026-4703 (CVSS 9.8) — The WS Form LITE – Drag & Drop Contact Form Builder plugin for WordPress is vulnerable to ...
KEV: CVE-2026-73570 — Synacor Zimbra Collaboration Suite (ZCS) (Zimbra Collaboration Suite (ZCS) OS Command Injection...
CVE-2026-68789 (CVSS 9.9) — Improper neutralization of special elements used in an sql command ('sql injection') in A...
CVE-2026-69400 (CVSS 9.6) — Improper limitation of a pathname to a restricted directory ('path traversal') in Azure L...
CVE-2026-69555 (CVSS 10.0) — Incorrect authorization in Azure Arc allows an unauthorized attacker to elevate privileg...
CVE-2026-69836 (CVSS 10.0) — Deserialization of untrusted data in Microsoft Entra ID allows an unauthorized attacker ...
CVE-2026-69851 (CVSS 9.9) — Server-side request forgery (ssrf) in Azure Active Directory allows an authorized attacke...
CVE-2026-72843 (CVSS 9.8) — The customer update route in EverShop is declared with "access": "public" in packages/eve...
KEV: CVE-2026-72530 — TrueConf Server (TrueConf Server Code Injection Vulnerability)