📧 info@ciso.sa | 📱 +966550939344 | Riyadh, Kingdom of Saudi Arabia
🔧 Scheduled Maintenance — Saturday 2:00-4:00 AM AST. Some features may be temporarily unavailable.    ●   
💎
Pro Plan 50% Off Unlock all AI features, unlimited reports, and priority support. Upgrade
Search Center
ESC to close
Global vulnerability Technology/Software CRITICAL 1h Global vulnerability Information Technology, Remote Access Services CRITICAL 1h Global vulnerability Information Technology and Communications HIGH 1h Global vulnerability Software Development and Technology CRITICAL 4h Global vulnerability Software Development / Technology CRITICAL 4h Global apt Financial Services, Cryptocurrency CRITICAL 12h Global ransomware General/Cross-sector HIGH 13h Global vulnerability Technology/Software Development CRITICAL 13h Global insider Government, Intelligence, Cybersecurity HIGH 13h Global ransomware Multiple sectors HIGH 14h Global vulnerability Technology/Software CRITICAL 1h Global vulnerability Information Technology, Remote Access Services CRITICAL 1h Global vulnerability Information Technology and Communications HIGH 1h Global vulnerability Software Development and Technology CRITICAL 4h Global vulnerability Software Development / Technology CRITICAL 4h Global apt Financial Services, Cryptocurrency CRITICAL 12h Global ransomware General/Cross-sector HIGH 13h Global vulnerability Technology/Software Development CRITICAL 13h Global insider Government, Intelligence, Cybersecurity HIGH 13h Global ransomware Multiple sectors HIGH 14h Global vulnerability Technology/Software CRITICAL 1h Global vulnerability Information Technology, Remote Access Services CRITICAL 1h Global vulnerability Information Technology and Communications HIGH 1h Global vulnerability Software Development and Technology CRITICAL 4h Global vulnerability Software Development / Technology CRITICAL 4h Global apt Financial Services, Cryptocurrency CRITICAL 12h Global ransomware General/Cross-sector HIGH 13h Global vulnerability Technology/Software Development CRITICAL 13h Global insider Government, Intelligence, Cybersecurity HIGH 13h Global ransomware Multiple sectors HIGH 14h

🛡️ CVE Intelligence Center

Common Vulnerabilities & Exposures — Security Intelligence Database

CVE ID Severity CVSS Description Status Published
CVE-2026-22856 High 8.1
FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.20.1, a race in the serial channel IRP threa…
⚡ Exploit ✅ Patch Jan 14, 2026
CVE-2025-13455 High 7.8
A vulnerability was reported in ThinkPlus configuration software that could allow a local authenticated user to bypass T…
✅ Patch Jan 14, 2026
CVE-2025-12166 High 7.5
The Appointment Booking Calendar — Simply Schedule Appointments Booking Plugin plugin for WordPress is vulnerable to bli…
✅ Patch Jan 14, 2026
CVE-2025-14770 High 7.5
The Shipping Rate By Cities plugin for WordPress is vulnerable to SQL Injection via the 'city' parameter in all versions…
✅ Patch Jan 14, 2026
CVE-2026-21889 High 7.5
Weblate is a web based localization tool. Prior to 5.15.2, the screenshot images were served directly by the HTTP server…
✅ Patch Jan 14, 2026
CVE-2026-22240 High 7.5
The vulnerability exists in BLUVOYIX due to an improper password storage implementation and subsequent exposure via unau…
✅ Patch Jan 14, 2026
CVE-2026-23498 High 7.2
Shopware is an open commerce platform. From 6.7.0.0 to before 6.7.6.1, a regression of CVE-2023-2017 leads to an array a…
✅ Patch Jan 14, 2026
CVE-2025-14613 High 7.2
The GetContentFromURL plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and inclu…
✅ Patch Jan 14, 2026
CVE-2025-15266 High 7.2
The GeekyBot — Generate AI Content Without Prompt, Chatbot and Lead Generation plugin for WordPress is vulnerable to Sto…
✅ Patch Jan 14, 2026
CVE-2025-15283 High 7.2
The Name Directory plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'name_directory_name' and …
✅ Patch Jan 14, 2026
CVE-2025-15378 High 7.2
The AJS Footnotes plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'note_list_class' and 'popup…
✅ Patch Jan 14, 2026
CVE-2025-14615 High 7.1
The DASHBOARD BUILDER – WordPress plugin for Charts and Graphs plugin for WordPress is vulnerable to Cross-Site Request …
✅ Patch Jan 14, 2026
CVE-2026-0500 Critical 9.6
Due to the usage of vulnerable third party component in SAP Wily Introscope Enterprise Manager (WorkStation), an unauthe…
✅ Patch Jan 13, 2026
CVE-2026-0498 Critical 9.1
SAP S/4HANA (Private Cloud and On-Premise) allows an attacker with admin privileges to exploit a vulnerability in the fu…
✅ Patch Jan 13, 2026
CVE-2026-20805 Critical 9.0
Microsoft Windows Information Disclosure Vulnerability — Microsoft Windows Desktop Windows Manager contains an informati…
⚡ Exploit ✅ Patch Jan 13, 2026
CVE-2026-20947 High 8.8
Improper neutralization of special elements used in an sql command ('sql injection') in Microsoft Office SharePoint allo…
✅ Patch Jan 13, 2026
CVE-2026-20963 High 8.8
Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a ne…
✅ Patch Jan 13, 2026
CVE-2022-50909 High 8.8
Algo 8028 Control Panel version 3.3.3 contains a command injection vulnerability in the fm-data.lua endpoint that allows…
✅ Patch Jan 13, 2026
CVE-2022-50936 High 8.8
WBCE CMS version 1.5.2 contains an authenticated remote code execution vulnerability that allows attackers to upload mal…
⚡ Exploit ✅ Patch Jan 13, 2026
CVE-2025-40942 High 8.8
A vulnerability has been identified in TeleControl Server Basic (All versions < V3.1.2.4). Affected application contains…
✅ Patch Jan 13, 2026
📣 Found this valuable?
Share it with your cybersecurity network
in LinkedIn 𝕏 X / Twitter 💬 WhatsApp ✈ Telegram
🍪 Privacy Preferences
CISO Consulting — Compliant with Saudi Personal Data Protection Law (PDPL)
We use cookies and similar technologies to provide the best experience on our platform. You can choose which types you accept.
🔒
Essential Always On
Required for the website to function properly. Cannot be disabled.
📋 Sessions, CSRF tokens, authentication, language preferences
📊
Analytics
Help us understand how visitors use the site and improve performance.
📋 Page views, session duration, traffic sources, performance metrics
⚙️
Functional
Enable enhanced features like content personalization and preferences.
📋 Dark/light theme, font size, custom dashboards, saved filters
📣
Marketing
Used to deliver content and ads relevant to your interests.
📋 Campaign tracking, retargeting, social media analytics
Privacy Policy →
CISO AI Assistant
Ask anything · Documents · Support
🔐

Introduce Yourself

Enter your details to access the full assistant

Your info is private and never shared
💬
CyberAssist
Online · responds in seconds
5 / 5
🔐 Verify Your Identity

Enter your email to receive a verification code before submitting a support request.

Enter to send · / for commands 0 / 2000
CISO AI · Powered by Anthropic Claude
✦ Quick Survey Help Us Improve CISO Consulting Your feedback shapes the future of our platform — takes less than 2 minutes.
⚠ Please answer this question to continue

How would you rate your overall experience with our platform?

Rate from 1 (poor) to 5 (excellent)

🎉
Thank you!
Your response has been recorded.