INITIALIZING
📧 info@ciso.sa | 📱 +966550939344 | Riyadh, Kingdom of Saudi Arabia
🔧 Scheduled Maintenance — Saturday 2:00-4:00 AM AST. Some features may be temporarily unavailable.    ●   
💎
Pro Plan 50% Off Unlock all AI features, unlimited reports, and priority support. Upgrade
Search Center
ESC to close
Global vulnerability Mobile Devices / Consumer Electronics HIGH 4h Global ransomware Multiple sectors CRITICAL 4h Global malware Networking / Infrastructure CRITICAL 5h Global ransomware Information Technology, Virtualization Infrastructure CRITICAL 6h Global supply_chain Software Development and DevOps CRITICAL 7h Global supply_chain Software Development and Technology CRITICAL 8h Global apt Multiple sectors HIGH 10h Global general Digital Content & Intellectual Property MEDIUM 10h Global malware Technology and Software Development CRITICAL 10h Global ddos Technology and Social Media HIGH 11h Global vulnerability Mobile Devices / Consumer Electronics HIGH 4h Global ransomware Multiple sectors CRITICAL 4h Global malware Networking / Infrastructure CRITICAL 5h Global ransomware Information Technology, Virtualization Infrastructure CRITICAL 6h Global supply_chain Software Development and DevOps CRITICAL 7h Global supply_chain Software Development and Technology CRITICAL 8h Global apt Multiple sectors HIGH 10h Global general Digital Content & Intellectual Property MEDIUM 10h Global malware Technology and Software Development CRITICAL 10h Global ddos Technology and Social Media HIGH 11h Global vulnerability Mobile Devices / Consumer Electronics HIGH 4h Global ransomware Multiple sectors CRITICAL 4h Global malware Networking / Infrastructure CRITICAL 5h Global ransomware Information Technology, Virtualization Infrastructure CRITICAL 6h Global supply_chain Software Development and DevOps CRITICAL 7h Global supply_chain Software Development and Technology CRITICAL 8h Global apt Multiple sectors HIGH 10h Global general Digital Content & Intellectual Property MEDIUM 10h Global malware Technology and Software Development CRITICAL 10h Global ddos Technology and Social Media HIGH 11h

🛡️ CVE Vulnerability Database

CVE vulnerabilities with bilingual AI analysis tailored for Saudi Arabia

CVE ID Title / Description Severity CVSS Status Published
CVE-2026-27280
DNG SDK versions 1.7.1 2471 and earlier are affected by an out-of…
DNG SDK versions 1.7.1 2471 and earlier are affected by an out-of-bounds write vulnerability that co…
HIGH
7.8
Mar 10, 2026
CVE-2026-27689
Due to an uncontrolled resource consumption (Denial of Service) v…
Due to an uncontrolled resource consumption (Denial of Service) vulnerability, an authenticated atta…
HIGH
7.7
Mar 10, 2026
CVE-2026-28431
Misskey is an open source, federated social media platform. All M…
Misskey is an open source, federated social media platform. All Misskey servers running versions 8.4…
HIGH
7.5
Mar 10, 2026
CVE-2026-28432
Misskey is an open source, federated social media platform. All M…
Misskey is an open source, federated social media platform. All Misskey servers prior to 2026.3.1 co…
HIGH
7.5
Mar 10, 2026
CVE-2026-28513
Pocket ID is an OIDC provider that allows users to authenticate w…
Pocket ID is an OIDC provider that allows users to authenticate with their passkeys to your services…
HIGH
8.5
Mar 10, 2026
CVE-2026-30925
Parse Server is an open source backend that can be deployed to an…
Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.…
HIGH
7.5
Mar 10, 2026
CVE-2026-30929
ImageMagick is free and open-source software used for editing and…
ImageMagick is free and open-source software used for editing and manipulating digital images. Prior…
HIGH
7.7
Mar 10, 2026
CVE-2026-30939
Parse Server is an open source backend that can be deployed to an…
Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.…
HIGH
7.5
Mar 10, 2026
CVE-2026-30941
Parse Server is an open source backend that can be deployed to an…
Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.…
HIGH
7.5
Mar 10, 2026
CVE-2026-30958
OneUptime is a solution for monitoring and managing online servic…
OneUptime is a solution for monitoring and managing online services. Prior to 10.0.21, an unauthenti…
HIGH
7.2
Mar 10, 2026
CVE-2026-20967
Improper input validation in System Center Operations Manager all…
Improper input validation in System Center Operations Manager allows an authorized attacker to eleva…
HIGH
8.8
AI Mar 10, 2026
CVE-2026-2339
Missing Authentication for Critical Function vulnerability in TUB…
Missing Authentication for Critical Function vulnerability in TUBITAK BILGEM Software Technologies R…
HIGH
7.5
Mar 10, 2026
CVE-2026-2364
If a legitimate user confirms a self-update prompt or initiate an…
If a legitimate user confirms a self-update prompt or initiate an installation of a CODESYS Developm…
HIGH
7.3
Mar 10, 2026
CVE-2026-23654
Dependency on vulnerable third-party component in GitHub Repo: ze…
Dependency on vulnerable third-party component in GitHub Repo: zero-shot-scfoundation allows an unau…
HIGH
8.8
AI Mar 10, 2026
CVE-2026-23660
Improper access control in Azure Portal Windows Admin Center allo…
Improper access control in Azure Portal Windows Admin Center allows an authorized attacker to elevat…
HIGH
7.8
Mar 10, 2026
CVE-2026-23661
Cleartext transmission of sensitive information in Azure IoT Expl…
Cleartext transmission of sensitive information in Azure IoT Explorer allows an unauthorized attacke…
HIGH
7.5
Mar 10, 2026
CVE-2026-23662
Missing authentication for critical function in Azure IoT Explore…
Missing authentication for critical function in Azure IoT Explorer allows an unauthorized attacker t…
HIGH
7.5
Mar 10, 2026
CVE-2026-23664
Improper restriction of communication channel to intended endpoin…
Improper restriction of communication channel to intended endpoints in Azure IoT Explorer allows an …
HIGH
7.5
Mar 10, 2026
CVE-2026-23665
Heap-based buffer overflow in Azure Linux Virtual Machines allows…
Heap-based buffer overflow in Azure Linux Virtual Machines allows an authorized attacker to elevate …
HIGH
7.8
Mar 10, 2026
CVE-2026-23667
Use after free in Broadcast DVR allows an authorized attacker to …
Use after free in Broadcast DVR allows an authorized attacker to elevate privileges locally.
HIGH
7.0
Mar 10, 2026
CVE-2026-23668
Concurrent execution using shared resource with improper synchron…
Concurrent execution using shared resource with improper synchronization ('race condition') in Micro…
HIGH
7.0
Mar 10, 2026
CVE-2026-23669
Use after free in Windows Print Spooler Components allows an auth…
Use after free in Windows Print Spooler Components allows an authorized attacker to execute code ove…
HIGH
8.8
AI Mar 10, 2026
CVE-2026-23671
Concurrent execution using shared resource with improper synchron…
Concurrent execution using shared resource with improper synchronization ('race condition') in Windo…
HIGH
7.0
Mar 10, 2026
CVE-2026-23672
Windows Universal Disk Format File System Driver (UDFS) Elevation…
Windows Universal Disk Format File System Driver (UDFS) Elevation of Privilege Vulnerability
HIGH
7.8
Mar 10, 2026
CVE-2026-23673
Out-of-bounds read in Windows Resilient File System (ReFS) allows…
Out-of-bounds read in Windows Resilient File System (ReFS) allows an authorized attacker to elevate …
HIGH
7.8
Mar 10, 2026
🤖 AI Analysis Active
AI analysis includes: Arabic description, Saudi impact assessment, remediation steps, compliance mapping (NCA ECC, SAMA CSF, ISO 27001) and MITRE ATT&CK techniques.
💡 Search Tips
CVE-2024-12345 Search by exact ID
apache Search by product name
remote code execution Search by vulnerability type
log4j Search by common name
📡 Data Sources
NVD (NIST) · CIRCL
CISA KEV · ThreatFox
Feodo Tracker · AlienVault OTX
Auto-updated daily via cron
📣 Found this valuable?
Share it with your cybersecurity network
in LinkedIn 𝕏 X / Twitter 💬 WhatsApp ✈ Telegram
🍪 Privacy Preferences
CISO Consulting — Compliant with Saudi Personal Data Protection Law (PDPL)
We use cookies and similar technologies to provide the best experience on our platform. You can choose which types you accept.
🔒
Essential Always On
Required for the website to function properly. Cannot be disabled.
📋 Sessions, CSRF tokens, authentication, language preferences
📊
Analytics
Help us understand how visitors use the site and improve performance.
📋 Page views, session duration, traffic sources, performance metrics
⚙️
Functional
Enable enhanced features like content personalization and preferences.
📋 Dark/light theme, font size, custom dashboards, saved filters
📣
Marketing
Used to deliver content and ads relevant to your interests.
📋 Campaign tracking, retargeting, social media analytics
Privacy Policy →
CISO AI Assistant
Ask anything · Documents · Support
🔐

Introduce Yourself

Enter your details to access the full assistant

Your info is private and never shared
💬
CyberAssist
Online · responds in seconds
5 / 5
🔐 Verify Your Identity

Enter your email to receive a verification code before submitting a support request.

Enter to send · / for commands 0 / 2000
CISO AI · Powered by Anthropic Claude
✦ Quick Survey Help Us Improve CISO Consulting Your feedback shapes the future of our platform — takes less than 2 minutes.
⚠ Please answer this question to continue

How would you rate your overall experience with our platform?

Rate from 1 (poor) to 5 (excellent)

🎉
Thank you!
Your response has been recorded.