INITIALIZING
📧 info@ciso.sa | 📱 +966550939344 | Riyadh, Kingdom of Saudi Arabia
🔧 Scheduled Maintenance — Saturday 2:00-4:00 AM AST. Some features may be temporarily unavailable.    ●   
💎
Pro Plan 50% Off Unlock all AI features, unlimited reports, and priority support. Upgrade
Search Center
ESC to close
Global vulnerability Mobile Devices / Consumer Electronics HIGH 2h Global ransomware Multiple sectors CRITICAL 2h Global malware Networking / Infrastructure CRITICAL 3h Global ransomware Information Technology, Virtualization Infrastructure CRITICAL 4h Global supply_chain Software Development and DevOps CRITICAL 5h Global supply_chain Software Development and Technology CRITICAL 6h Global apt Multiple sectors HIGH 8h Global general Digital Content & Intellectual Property MEDIUM 8h Global malware Technology and Software Development CRITICAL 8h Global ddos Technology and Social Media HIGH 9h Global vulnerability Mobile Devices / Consumer Electronics HIGH 2h Global ransomware Multiple sectors CRITICAL 2h Global malware Networking / Infrastructure CRITICAL 3h Global ransomware Information Technology, Virtualization Infrastructure CRITICAL 4h Global supply_chain Software Development and DevOps CRITICAL 5h Global supply_chain Software Development and Technology CRITICAL 6h Global apt Multiple sectors HIGH 8h Global general Digital Content & Intellectual Property MEDIUM 8h Global malware Technology and Software Development CRITICAL 8h Global ddos Technology and Social Media HIGH 9h Global vulnerability Mobile Devices / Consumer Electronics HIGH 2h Global ransomware Multiple sectors CRITICAL 2h Global malware Networking / Infrastructure CRITICAL 3h Global ransomware Information Technology, Virtualization Infrastructure CRITICAL 4h Global supply_chain Software Development and DevOps CRITICAL 5h Global supply_chain Software Development and Technology CRITICAL 6h Global apt Multiple sectors HIGH 8h Global general Digital Content & Intellectual Property MEDIUM 8h Global malware Technology and Software Development CRITICAL 8h Global ddos Technology and Social Media HIGH 9h

🛡️ CVE Intelligence Center

Common Vulnerabilities & Exposures — Security Intelligence Database

CVE ID Severity CVSS Description Status Published
CVE-2026-20764 High 8.0
An OS command injection vulnerability exists in XWEB Pro version 1.12.1 and prior, enabling an authenticated attacker …
✅ Patch Feb 27, 2026
CVE-2026-3037 High 8.0
An OS command injection vulnerability exists in XWEB Pro version 1.12.1 and prior, enabling an authenticated attacker t…
✅ Patch Feb 27, 2026
CVE-2026-23702 High 8.0
An OS command injection vulnerability exists in XWEB Pro version 1.12.1 and prior, enabling an authenticated attacker …
✅ Patch Feb 27, 2026
CVE-2026-24452 High 8.0
An OS command injection vulnerability exists in XWEB Pro version 1.12.1 and prior, enabling an authenticated attacker…
✅ Patch Feb 27, 2026
CVE-2026-25105 High 8.0
An OS command injection vulnerability exists in XWEB Pro version 1.12.1 and prior, enabling an authenticated atta…
✅ Patch Feb 27, 2026
CVE-2026-25037 High 8.0
An OS command injection vulnerability exists in XWEB Pro version 1.12.1 and prior, enabling an authenticated attacker…
✅ Patch Feb 27, 2026
CVE-2026-25721 High 8.0
An OS command injection vulnerability exists in XWEB Pro version 1.12.1 and prior, enabling an authenticated attacker …
✅ Patch Feb 27, 2026
CVE-2026-25196 High 8.0
An OS command injection vulnerability exists in XWEB Pro version 1.12.1 and prior, enabling an authenticated attacker …
✅ Patch Feb 27, 2026
CVE-2026-28364 High 7.9
In OCaml before 4.14.3 and 5.x before 5.4.1, a buffer over-read in Marshal deserialization (runtime/intern.c) enables re…
✅ Patch Feb 27, 2026
CVE-2026-1442 High 7.8
Since the encryption algorithm used to protect firmware updates is itself encrypted using key material available to an a…
✅ Patch Feb 27, 2026
CVE-2026-2252 High 7.5
An XML External Entity (XXE) vulnerability allows malicious user to perform Server-Side Request Forgery (SSRF) via craft…
✅ Patch Feb 27, 2026
CVE-2026-27836 High 7.5
phpMyFAQ is an open source FAQ web application. Prior to version 4.0.18, the WebAuthn prepare endpoint (`/api/webauthn/p…
✅ Patch Feb 27, 2026
CVE-2026-2428 High 7.5
The Fluent Forms Pro Add On Pack plugin for WordPress is vulnerable to Insufficient Verification of Data Authenticity in…
✅ Patch Feb 27, 2026
CVE-2025-10990 High 7.5
A flaw was found in REXML. A remote attacker could exploit inefficient regular expression (regex) parsing when processin…
✅ Patch Feb 27, 2026
CVE-2026-28372 High 7.4
telnetd in GNU inetutils through 2.7 allows privilege escalation that can be exploited by abusing systemd service creden…
✅ Patch Feb 27, 2026
CVE-2026-27707 High 7.3
Seerr is an open-source media request and discovery manager for Jellyfin, Plex, and Emby. Starting in version 2.0.0 and …
✅ Patch Feb 27, 2026
CVE-2026-27776 High 7.2
IM-LogicDesigner module of intra-mart Accel Platform contains insecure deserialization issue. This can be exploited only…
✅ Patch Feb 27, 2026
CVE-2026-25147 High 7.1
OpenEMR is a free and open source electronic health records and medical practice management application. Prior to versio…
✅ Patch Feb 27, 2026
CVE-2026-27757 High 7.1
SODOLA SL902-SWTGW124AS firmware versions through 200.1.20 contain an authentication vulnerability that allows authentic…
✅ Patch Feb 27, 2026
CVE-2026-28338 Medium 6.8
PMD is an extensible multilanguage static code analyzer. Prior to version 7.22.0, PMD's `vbhtml` and `yahtml` report for…
⚡ Exploit Feb 27, 2026
📣 Found this valuable?
Share it with your cybersecurity network
in LinkedIn 𝕏 X / Twitter 💬 WhatsApp ✈ Telegram
🍪 Privacy Preferences
CISO Consulting — Compliant with Saudi Personal Data Protection Law (PDPL)
We use cookies and similar technologies to provide the best experience on our platform. You can choose which types you accept.
🔒
Essential Always On
Required for the website to function properly. Cannot be disabled.
📋 Sessions, CSRF tokens, authentication, language preferences
📊
Analytics
Help us understand how visitors use the site and improve performance.
📋 Page views, session duration, traffic sources, performance metrics
⚙️
Functional
Enable enhanced features like content personalization and preferences.
📋 Dark/light theme, font size, custom dashboards, saved filters
📣
Marketing
Used to deliver content and ads relevant to your interests.
📋 Campaign tracking, retargeting, social media analytics
Privacy Policy →
CISO AI Assistant
Ask anything · Documents · Support
🔐

Introduce Yourself

Enter your details to access the full assistant

Your info is private and never shared
💬
CyberAssist
Online · responds in seconds
5 / 5
🔐 Verify Your Identity

Enter your email to receive a verification code before submitting a support request.

Enter to send · / for commands 0 / 2000
CISO AI · Powered by Anthropic Claude
✦ Quick Survey Help Us Improve CISO Consulting Your feedback shapes the future of our platform — takes less than 2 minutes.
⚠ Please answer this question to continue

How would you rate your overall experience with our platform?

Rate from 1 (poor) to 5 (excellent)

🎉
Thank you!
Your response has been recorded.