📧 info@ciso.sa | 📱 +966550939344 | Riyadh, Kingdom of Saudi Arabia
🔧 Scheduled Maintenance — Saturday 2:00-4:00 AM AST. Some features may be temporarily unavailable.    ●   
💎
Pro Plan 50% Off Unlock all AI features, unlimited reports, and priority support. Upgrade
Search Center
ESC to close
Global general Enterprise Security HIGH 6m Global general Multiple sectors HIGH 33m Global vulnerability Enterprise Infrastructure CRITICAL 42m Global vulnerability Information Technology / Network Security CRITICAL 1h Global general Enterprise security and incident response HIGH 1h Global supply_chain Software Development CRITICAL 1h Global general Digital Safety and Regulatory Compliance HIGH 1h Global malware Technology and Software Development CRITICAL 2h Global supply_chain Software Development and Technology CRITICAL 2h Global apt Water and Wastewater Utilities CRITICAL 4h Global general Enterprise Security HIGH 6m Global general Multiple sectors HIGH 33m Global vulnerability Enterprise Infrastructure CRITICAL 42m Global vulnerability Information Technology / Network Security CRITICAL 1h Global general Enterprise security and incident response HIGH 1h Global supply_chain Software Development CRITICAL 1h Global general Digital Safety and Regulatory Compliance HIGH 1h Global malware Technology and Software Development CRITICAL 2h Global supply_chain Software Development and Technology CRITICAL 2h Global apt Water and Wastewater Utilities CRITICAL 4h Global general Enterprise Security HIGH 6m Global general Multiple sectors HIGH 33m Global vulnerability Enterprise Infrastructure CRITICAL 42m Global vulnerability Information Technology / Network Security CRITICAL 1h Global general Enterprise security and incident response HIGH 1h Global supply_chain Software Development CRITICAL 1h Global general Digital Safety and Regulatory Compliance HIGH 1h Global malware Technology and Software Development CRITICAL 2h Global supply_chain Software Development and Technology CRITICAL 2h Global apt Water and Wastewater Utilities CRITICAL 4h

🛡️ CVE Intelligence Center

Common Vulnerabilities & Exposures — Security Intelligence Database

CVE ID Severity CVSS Description Status Published
CVE-2026-20764 High 8.0
An OS command injection vulnerability exists in XWEB Pro version 1.12.1 and prior, enabling an authenticated attacker …
✅ Patch Feb 27, 2026
CVE-2026-23702 High 8.0
An OS command injection vulnerability exists in XWEB Pro version 1.12.1 and prior, enabling an authenticated attacker …
✅ Patch Feb 27, 2026
CVE-2026-24452 High 8.0
An OS command injection vulnerability exists in XWEB Pro version 1.12.1 and prior, enabling an authenticated attacker…
✅ Patch Feb 27, 2026
CVE-2026-25037 High 8.0
An OS command injection vulnerability exists in XWEB Pro version 1.12.1 and prior, enabling an authenticated attacker…
✅ Patch Feb 27, 2026
CVE-2026-25105 High 8.0
An OS command injection vulnerability exists in XWEB Pro version 1.12.1 and prior, enabling an authenticated atta…
✅ Patch Feb 27, 2026
CVE-2026-25196 High 8.0
An OS command injection vulnerability exists in XWEB Pro version 1.12.1 and prior, enabling an authenticated attacker …
✅ Patch Feb 27, 2026
CVE-2026-25721 High 8.0
An OS command injection vulnerability exists in XWEB Pro version 1.12.1 and prior, enabling an authenticated attacker …
✅ Patch Feb 27, 2026
CVE-2026-3037 High 8.0
An OS command injection vulnerability exists in XWEB Pro version 1.12.1 and prior, enabling an authenticated attacker t…
✅ Patch Feb 27, 2026
CVE-2026-28364 High 7.9
In OCaml before 4.14.3 and 5.x before 5.4.1, a buffer over-read in Marshal deserialization (runtime/intern.c) enables re…
✅ Patch Feb 27, 2026
CVE-2026-1442 High 7.8
Since the encryption algorithm used to protect firmware updates is itself encrypted using key material available to an a…
✅ Patch Feb 27, 2026
CVE-2026-2252 High 7.5
An XML External Entity (XXE) vulnerability allows malicious user to perform Server-Side Request Forgery (SSRF) via craft…
✅ Patch Feb 27, 2026
CVE-2026-2428 High 7.5
The Fluent Forms Pro Add On Pack plugin for WordPress is vulnerable to Insufficient Verification of Data Authenticity in…
✅ Patch Feb 27, 2026
CVE-2026-27836 High 7.5
phpMyFAQ is an open source FAQ web application. Prior to version 4.0.18, the WebAuthn prepare endpoint (`/api/webauthn/p…
✅ Patch Feb 27, 2026
CVE-2025-10990 High 7.5
A flaw was found in REXML. A remote attacker could exploit inefficient regular expression (regex) parsing when processin…
✅ Patch Feb 27, 2026
CVE-2026-28372 High 7.4
telnetd in GNU inetutils through 2.7 allows privilege escalation that can be exploited by abusing systemd service creden…
✅ Patch Feb 27, 2026
CVE-2026-27707 High 7.3
Seerr is an open-source media request and discovery manager for Jellyfin, Plex, and Emby. Starting in version 2.0.0 and …
✅ Patch Feb 27, 2026
CVE-2026-27776 High 7.2
IM-LogicDesigner module of intra-mart Accel Platform contains insecure deserialization issue. This can be exploited only…
✅ Patch Feb 27, 2026
CVE-2026-25147 High 7.1
OpenEMR is a free and open source electronic health records and medical practice management application. Prior to versio…
✅ Patch Feb 27, 2026
CVE-2026-27757 High 7.1
SODOLA SL902-SWTGW124AS firmware versions through 200.1.20 contain an authentication vulnerability that allows authentic…
✅ Patch Feb 27, 2026
CVE-2026-28338 Medium 6.8
PMD is an extensible multilanguage static code analyzer. Prior to version 7.22.0, PMD's `vbhtml` and `yahtml` report for…
⚡ Exploit Feb 27, 2026
📣 Found this valuable?
Share it with your cybersecurity network
in LinkedIn 𝕏 X / Twitter 💬 WhatsApp ✈ Telegram
🍪 Privacy Preferences
CISO Consulting — Compliant with Saudi Personal Data Protection Law (PDPL)
We use cookies and similar technologies to provide the best experience on our platform. You can choose which types you accept.
🔒
Essential Always On
Required for the website to function properly. Cannot be disabled.
📋 Sessions, CSRF tokens, authentication, language preferences
📊
Analytics
Help us understand how visitors use the site and improve performance.
📋 Page views, session duration, traffic sources, performance metrics
⚙️
Functional
Enable enhanced features like content personalization and preferences.
📋 Dark/light theme, font size, custom dashboards, saved filters
📣
Marketing
Used to deliver content and ads relevant to your interests.
📋 Campaign tracking, retargeting, social media analytics
Privacy Policy →
CISO AI Assistant
Ask anything · Documents · Support
🔐

Introduce Yourself

Enter your details to access the full assistant

Your info is private and never shared
💬
CyberAssist
Online · responds in seconds
5 / 5
🔐 Verify Your Identity

Enter your email to receive a verification code before submitting a support request.

Enter to send · / for commands 0 / 2000
CISO AI · Powered by Anthropic Claude
✦ Quick Survey Help Us Improve CISO Consulting Your feedback shapes the future of our platform — takes less than 2 minutes.
⚠ Please answer this question to continue

How would you rate your overall experience with our platform?

Rate from 1 (poor) to 5 (excellent)

🎉
Thank you!
Your response has been recorded.