Currently free during beta - premium features coming soon. Subscribe now to lock in early access.
CVE

EU Regulatory Changes

251 changes tracked across 24 compliance frameworks including DORA, NIS2, GDPR, EU AI Act, Cyber Resilience Act, and more.

All DORA NIS2 GDPR CSRD MaRisk ISO27001 EU_AI_ACT CRA DSA DMA eIDAS2 SOC2 PCI_DSS HIPAA ISO42001 AMLD6 PSD3 DATA_ACT GPSR CER EUDR CVE BREACH AI_SAFETY
CVE-2026-56073 (CVSS 9.4) — Cap-go before 12.128.2 contains an authentication bypass vulnerability in OTP verificatio...
KEV: CVE-2026-20253 — Splunk Enterprise (Splunk Enterprise Missing Authentication for Critical Function Vulnerability)
CVE-2026-53776 (CVSS 9.1) — Perry before 0.5.1166 contains a JWT validation vulnerability that allows remote attacker...
KEV: CVE-2026-48907 — Widget Factory Joomla Content Editor (Widget Factory Joomla Content Editor Improper Access Con...
CVE-2018-25436 (CVSS 9.8) — WordPress Plugin Baggage Freight Shipping Australia 0.1.0 contains an unrestricted file u...
CVE-2026-49952 (CVSS 9.1) — Discuz! X5.0 releases 20260320 through 20260501 contains an authentication bypass vulnera...
KEV: CVE-2026-54420 — LiteSpeed cPanel Plugin (LiteSpeed cPanel Plugin UNIX Symbolic Link (Symlink) Following Vulnera...
KEV: CVE-2026-20262 — Cisco Catalyst SD-WAN Manager (Cisco Catalyst SD-WAN Manager Directory or Path Traversal Vulner...
KEV: CVE-2026-35273 — Oracle PeopleSoft Enterprise PeopleTools (Oracle PeopleSoft Enterprise PeopleTools Missing Aut...
CVE-2026-11561 (CVSS 9.8) — Improper neutralization of special elements used in an expression language statement ('ex...
CVE-2026-11849 (CVSS 9.8) — The  iRM-IEI Remote Management developed by IEI Integration Corp has a Hardcoded Credenti...
CVE-2026-53787 (CVSS 9.8) — Amasty Order Attributes for Magento 2 before version 4.0.0 contains an unauthenticated ar...
CVE-2026-6853 (CVSS 9.8) — Improper restriction of excessive authentication attempts vulnerability in Başbelen Group ...
CVE-2026-48558 (CVSS 10.0) — SimpleHelp versions 5.5.15 and prior and 6.0 pre-release versions contain an authenticat...
CVE-2026-53838 (CVSS 9.8) — OpenClaw before 2026.5.27 contains a state mutation vulnerability in node pairing reconne...
CVE-2026-7852 (CVSS 9.8) — Unrestricted upload of file with dangerous type vulnerability in Limatek System Inc. LimRA...
CVE-2026-11839 (CVSS 9.9) — Unrestricted upload of file with dangerous type vulnerability in Başarsoft Information Te...
CVE-2026-49973 (CVSS 9.4) — Hermes WebUI before version 0.51.358 contains an improper access control vulnerability th...
KEV: CVE-2026-10520 — Ivanti Sentry (Ivanti Sentry OS Command Injection Vulnerability)
CVE-2025-6254 (CVSS 9.8) — The Doctreat Core plugin for WordPress is vulnerable to Privilege Escalation in all versio...