INITIALIZING
📧 info@ciso.sa | 📱 +966550939344 | Riyadh, Kingdom of Saudi Arabia
🔧 Scheduled Maintenance — Saturday 2:00-4:00 AM AST. Some features may be temporarily unavailable.    ●   
💎
Pro Plan 50% Off Unlock all AI features, unlimited reports, and priority support. Upgrade
Search Center
ESC to close
Global ransomware Financial Services / Cybersecurity CRITICAL 31m Global vulnerability Information Technology / Cybersecurity CRITICAL 2h Global malware Energy and Utilities CRITICAL 3h Global ransomware Multiple sectors CRITICAL 3h Global vulnerability Industrial Control Systems / IoT / Infrastructure CRITICAL 5h Global supply_chain Information Technology and Critical Infrastructure CRITICAL 6h Global phishing Multiple sectors HIGH 6h Global insider Cybersecurity Services CRITICAL 6h Global ransomware Multiple sectors (U.S. companies) CRITICAL 7h Global malware Financial Services, Cryptocurrency CRITICAL 7h Global ransomware Financial Services / Cybersecurity CRITICAL 31m Global vulnerability Information Technology / Cybersecurity CRITICAL 2h Global malware Energy and Utilities CRITICAL 3h Global ransomware Multiple sectors CRITICAL 3h Global vulnerability Industrial Control Systems / IoT / Infrastructure CRITICAL 5h Global supply_chain Information Technology and Critical Infrastructure CRITICAL 6h Global phishing Multiple sectors HIGH 6h Global insider Cybersecurity Services CRITICAL 6h Global ransomware Multiple sectors (U.S. companies) CRITICAL 7h Global malware Financial Services, Cryptocurrency CRITICAL 7h Global ransomware Financial Services / Cybersecurity CRITICAL 31m Global vulnerability Information Technology / Cybersecurity CRITICAL 2h Global malware Energy and Utilities CRITICAL 3h Global ransomware Multiple sectors CRITICAL 3h Global vulnerability Industrial Control Systems / IoT / Infrastructure CRITICAL 5h Global supply_chain Information Technology and Critical Infrastructure CRITICAL 6h Global phishing Multiple sectors HIGH 6h Global insider Cybersecurity Services CRITICAL 6h Global ransomware Multiple sectors (U.S. companies) CRITICAL 7h Global malware Financial Services, Cryptocurrency CRITICAL 7h

🛡️ CVE Vulnerability Database

CVE vulnerabilities with bilingual AI analysis tailored for Saudi Arabia

CVE ID Title / Description Severity CVSS Status Published
CVE-2026-21913
An Incorrect Initialization of Resource vulnerability in the Inte…
An Incorrect Initialization of Resource vulnerability in the Internal Device Manager (IDM) of Junipe…
HIGH
7.5
Jan 15, 2026
CVE-2026-21914
An Improper Locking vulnerability in the GTP plugin of Juniper Ne…
An Improper Locking vulnerability in the GTP plugin of Juniper Networks Junos OS on SRX Series allow…
HIGH
7.5
Jan 15, 2026
CVE-2026-21917
An Improper Validation of Syntactic Correctness of Input vulnerab…
An Improper Validation of Syntactic Correctness of Input vulnerability in the Web-Filtering module o…
HIGH
7.5
Jan 15, 2026
CVE-2026-21918
A Double Free vulnerability in the flow processing daemon (flowd)…
A Double Free vulnerability in the flow processing daemon (flowd) of Juniper Networks Junos OS on SR…
HIGH
7.5
Jan 15, 2026
CVE-2026-21920
An Unchecked Return Value vulnerability in the DNS module of Juni…
An Unchecked Return Value vulnerability in the DNS module of Juniper Networks Junos OS on SRX Series…
HIGH
7.5
Jan 15, 2026
CVE-2026-22803
SvelteKit is a framework for rapidly developing robust, performan…
SvelteKit is a framework for rapidly developing robust, performant web applications using Svelte. Fr…
HIGH
7.5
Jan 15, 2026
CVE-2026-22863
Deno is a JavaScript, TypeScript, and WebAssembly runtime. Before…
Deno is a JavaScript, TypeScript, and WebAssembly runtime. Before 2.6.0, node:crypto doesn't finaliz…
HIGH
7.5
Jan 15, 2026
CVE-2026-23622
Easy!Appointments is a self hosted appointment scheduler. In 1.5.…
Easy!Appointments is a self hosted appointment scheduler. In 1.5.2 and earlier, application/core/EA_…
HIGH
8.8
Jan 15, 2026
CVE-2026-21889
Weblate is a web based localization tool. Prior to 5.15.2, the sc…
Weblate is a web based localization tool. Prior to 5.15.2, the screenshot images were served directl…
HIGH
7.5
Jan 14, 2026
CVE-2026-22240
The vulnerability exists in BLUVOYIX due to an improper password …
The vulnerability exists in BLUVOYIX due to an improper password storage implementation and subseque…
HIGH
7.5
Jan 14, 2026
CVE-2026-22856
FreeRDP is a free implementation of the Remote Desktop Protocol. …
FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.20.1, a race in the seri…
HIGH
8.1
Jan 14, 2026
CVE-2026-23498
Shopware is an open commerce platform. From 6.7.0.0 to before 6.7…
Shopware is an open commerce platform. From 6.7.0.0 to before 6.7.6.1, a regression of CVE-2023-2017…
HIGH
7.2
Jan 14, 2026
CVE-2026-23512
SumatraPDF is a multi-format reader for Windows. In 3.5.2 and ear…
SumatraPDF is a multi-format reader for Windows. In 3.5.2 and earlier, there is a Untrusted Search P…
HIGH
8.6
Jan 14, 2026
CVE-2025-12166
The Appointment Booking Calendar — Simply Schedule Appointments B…
The Appointment Booking Calendar — Simply Schedule Appointments Booking Plugin plugin for WordPress …
HIGH
7.5
Jan 14, 2026
CVE-2025-13455
A vulnerability was reported in ThinkPlus configuration software …
A vulnerability was reported in ThinkPlus configuration software that could allow a local authentica…
HIGH
7.8
Jan 14, 2026
CVE-2025-14613
The GetContentFromURL plugin for WordPress is vulnerable to Serve…
The GetContentFromURL plugin for WordPress is vulnerable to Server-Side Request Forgery in all versi…
HIGH
7.2
Jan 14, 2026
CVE-2025-14615
The DASHBOARD BUILDER – WordPress plugin for Charts and Graphs pl…
The DASHBOARD BUILDER – WordPress plugin for Charts and Graphs plugin for WordPress is vulnerable to…
HIGH
7.1
Jan 14, 2026
CVE-2025-14770
The Shipping Rate By Cities plugin for WordPress is vulnerable to…
The Shipping Rate By Cities plugin for WordPress is vulnerable to SQL Injection via the 'city' param…
HIGH
7.5
Jan 14, 2026
CVE-2025-15266
The GeekyBot — Generate AI Content Without Prompt, Chatbot and Le…
The GeekyBot — Generate AI Content Without Prompt, Chatbot and Lead Generation plugin for WordPress …
HIGH
7.2
Jan 14, 2026
CVE-2025-15283
The Name Directory plugin for WordPress is vulnerable to Stored C…
The Name Directory plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'name_d…
HIGH
7.2
Jan 14, 2026
CVE-2025-15378
The AJS Footnotes plugin for WordPress is vulnerable to Stored Cr…
The AJS Footnotes plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'note_li…
HIGH
7.2
Jan 14, 2026
CVE-2025-40942
A vulnerability has been identified in TeleControl Server Basic (…
A vulnerability has been identified in TeleControl Server Basic (All versions < V3.1.2.4). Affected …
HIGH
8.8
Jan 13, 2026
CVE-2025-40944
A vulnerability has been identified in SIMATIC ET 200AL IM 157-1 …
A vulnerability has been identified in SIMATIC ET 200AL IM 157-1 PN (6ES7157-1AB00-0AB0) (All versio…
HIGH
7.5
Jan 13, 2026
CVE-2025-46685
Dell SupportAssist OS Recovery, versions prior to 5.5.15.1, conta…
Dell SupportAssist OS Recovery, versions prior to 5.5.15.1, contain a Creation of Temporary File Wit…
HIGH
7.5
Jan 13, 2026
CVE-2025-59022
Backend users who had access to the recycler module could delete …
Backend users who had access to the recycler module could delete arbitrary data from any database ta…
HIGH
8.1
Jan 13, 2026
🤖 AI Analysis Active
AI analysis includes: Arabic description, Saudi impact assessment, remediation steps, compliance mapping (NCA ECC, SAMA CSF, ISO 27001) and MITRE ATT&CK techniques.
💡 Search Tips
CVE-2024-12345 Search by exact ID
apache Search by product name
remote code execution Search by vulnerability type
log4j Search by common name
📡 Data Sources
NVD (NIST) · CIRCL
CISA KEV · ThreatFox
Feodo Tracker · AlienVault OTX
Auto-updated daily via cron
📣 Found this valuable?
Share it with your cybersecurity network
in LinkedIn 𝕏 X / Twitter 💬 WhatsApp ✈ Telegram
🍪 Privacy Preferences
CISO Consulting — Compliant with Saudi Personal Data Protection Law (PDPL)
We use cookies and similar technologies to provide the best experience on our platform. You can choose which types you accept.
🔒
Essential Always On
Required for the website to function properly. Cannot be disabled.
📋 Sessions, CSRF tokens, authentication, language preferences
📊
Analytics
Help us understand how visitors use the site and improve performance.
📋 Page views, session duration, traffic sources, performance metrics
⚙️
Functional
Enable enhanced features like content personalization and preferences.
📋 Dark/light theme, font size, custom dashboards, saved filters
📣
Marketing
Used to deliver content and ads relevant to your interests.
📋 Campaign tracking, retargeting, social media analytics
Privacy Policy →
CISO AI Assistant
Ask anything · Documents · Support
🔐

Introduce Yourself

Enter your details to access the full assistant

Your info is private and never shared
💬
CyberAssist
Online · responds in seconds
5 / 5
🔐 Verify Your Identity

Enter your email to receive a verification code before submitting a support request.

Enter to send · / for commands 0 / 2000
CISO AI · Powered by Anthropic Claude
✦ Quick Survey Help Us Improve CISO Consulting Your feedback shapes the future of our platform — takes less than 2 minutes.
⚠ Please answer this question to continue

How would you rate your overall experience with our platform?

Rate from 1 (poor) to 5 (excellent)

🎉
Thank you!
Your response has been recorded.