INITIALIZING
📧 info@ciso.sa | 📱 +966550939344 | Riyadh, Kingdom of Saudi Arabia
🔧 Scheduled Maintenance — Saturday 2:00-4:00 AM AST. Some features may be temporarily unavailable.    ●   
💎
Pro Plan 50% Off Unlock all AI features, unlimited reports, and priority support. Upgrade
Search Center
ESC to close
Global malware Energy and Utilities CRITICAL 1h Global vulnerability Industrial Control Systems / IoT / Infrastructure CRITICAL 3h Global supply_chain Information Technology and Critical Infrastructure CRITICAL 4h Global phishing Multiple sectors HIGH 4h Global insider Cybersecurity Services CRITICAL 4h Global ransomware Multiple sectors (U.S. companies) CRITICAL 5h Global malware Financial Services, Cryptocurrency CRITICAL 5h Global malware Technology and Cloud Services HIGH 5h Global general Financial Services and E-commerce MEDIUM 5h Global data_breach Social Media and Communications CRITICAL 5h Global malware Energy and Utilities CRITICAL 1h Global vulnerability Industrial Control Systems / IoT / Infrastructure CRITICAL 3h Global supply_chain Information Technology and Critical Infrastructure CRITICAL 4h Global phishing Multiple sectors HIGH 4h Global insider Cybersecurity Services CRITICAL 4h Global ransomware Multiple sectors (U.S. companies) CRITICAL 5h Global malware Financial Services, Cryptocurrency CRITICAL 5h Global malware Technology and Cloud Services HIGH 5h Global general Financial Services and E-commerce MEDIUM 5h Global data_breach Social Media and Communications CRITICAL 5h Global malware Energy and Utilities CRITICAL 1h Global vulnerability Industrial Control Systems / IoT / Infrastructure CRITICAL 3h Global supply_chain Information Technology and Critical Infrastructure CRITICAL 4h Global phishing Multiple sectors HIGH 4h Global insider Cybersecurity Services CRITICAL 4h Global ransomware Multiple sectors (U.S. companies) CRITICAL 5h Global malware Financial Services, Cryptocurrency CRITICAL 5h Global malware Technology and Cloud Services HIGH 5h Global general Financial Services and E-commerce MEDIUM 5h Global data_breach Social Media and Communications CRITICAL 5h

🛡️ CVE Vulnerability Database

CVE vulnerabilities with bilingual AI analysis tailored for Saudi Arabia

CVE ID Title / Description Severity CVSS Status Published
CVE-2025-68704
Jervis is a library for Job DSL plugin scripts and shared Jenkins…
Jervis is a library for Job DSL plugin scripts and shared Jenkins pipeline libraries. Prior to 2.2, …
HIGH
7.5
Jan 13, 2026
CVE-2025-68817
In the Linux kernel, the following vulnerability has been resolve…
In the Linux kernel, the following vulnerability has been resolved: ksmbd: fix use-after-free in ks…
HIGH
7.8
Jan 13, 2026
CVE-2025-68931
Jervis is a library for Job DSL plugin scripts and shared Jenkins…
Jervis is a library for Job DSL plugin scripts and shared Jenkins pipeline libraries. Prior to 2.2, …
HIGH
7.5
Jan 13, 2026
CVE-2025-70753
Tenda AX-1806 v1.0.0.1 was discovered to contain a stack overflow…
Tenda AX-1806 v1.0.0.1 was discovered to contain a stack overflow in the security_5g parameter of th…
HIGH
7.5
Jan 13, 2026
CVE-2025-71024
Tenda AX-3 v16.03.12.10_CN was discovered to contain a stack over…
Tenda AX-3 v16.03.12.10_CN was discovered to contain a stack overflow in the serviceName2 parameter …
HIGH
7.5
Jan 13, 2026
CVE-2025-71025
Tenda AX-3 v16.03.12.10_CN was discovered to contain a stack over…
Tenda AX-3 v16.03.12.10_CN was discovered to contain a stack overflow in the cloneType2 parameter of…
HIGH
7.5
Jan 13, 2026
CVE-2025-71026
Tenda AX-3 v16.03.12.10_CN was discovered to contain a stack over…
Tenda AX-3 v16.03.12.10_CN was discovered to contain a stack overflow in the wanSpeed2 parameter of …
HIGH
7.5
Jan 13, 2026
CVE-2025-71027
Tenda AX-3 v16.03.12.10_CN was discovered to contain a stack over…
Tenda AX-3 v16.03.12.10_CN was discovered to contain a stack overflow in the wanMTU2 parameter of th…
HIGH
7.5
Jan 13, 2026
CVE-2025-71089
In the Linux kernel, the following vulnerability has been resolve…
In the Linux kernel, the following vulnerability has been resolved: iommu: disable SVA when CONFIG_…
HIGH
7.8
Jan 13, 2026
CVE-2026-0403
An insufficient input validation vulnerability in NETGEAR Orbi ro…
An insufficient input validation vulnerability in NETGEAR Orbi routers allows attackers connected t…
HIGH
8.0
Jan 13, 2026
CVE-2026-0404
An insufficient input validation vulnerability in NETGEAR Orbi de…
An insufficient input validation vulnerability in NETGEAR Orbi devices' DHCPv6 functionality allows…
HIGH
8.0
Jan 13, 2026
CVE-2026-0405
An authentication bypass vulnerability in NETGEAR Orbi devices al…
An authentication bypass vulnerability in NETGEAR Orbi devices allows users connected to the local …
HIGH
7.8
Jan 13, 2026
CVE-2026-0406
An insufficient input validation vulnerability in the NETGEAR XR1…
An insufficient input validation vulnerability in the NETGEAR XR1000v2 allows attackers connected t…
HIGH
8.0
Jan 13, 2026
CVE-2026-0407
An insufficient authentication vulnerability in NETGEAR WiFi rang…
An insufficient authentication vulnerability in NETGEAR WiFi range extenders allows a network adjac…
HIGH
8.0
Jan 13, 2026
CVE-2026-0408
A path traversal vulnerability in NETGEAR WiFi range extenders al…
A path traversal vulnerability in NETGEAR WiFi range extenders allows an attacker with LAN authenti…
HIGH
8.0
Jan 13, 2026
CVE-2026-0492
SAP HANA database is vulnerable to privilege escalation allowing …
SAP HANA database is vulnerable to privilege escalation allowing an attacker with valid credentials …
HIGH
8.8
Jan 13, 2026
CVE-2026-0506
Due to a Missing Authorization Check vulnerability in Application…
Due to a Missing Authorization Check vulnerability in Application Server ABAP and ABAP Platform, an …
HIGH
8.1
Jan 13, 2026
CVE-2026-0507
Due to an OS Command Injection vulnerability in SAP Application S…
Due to an OS Command Injection vulnerability in SAP Application Server for ABAP and SAP NetWeaver RF…
HIGH
8.4
Jan 13, 2026
CVE-2026-0511
SAP Fiori App Intercompany Balance Reconciliation does not perfor…
SAP Fiori App Intercompany Balance Reconciliation does not perform necessary authorization checks fo…
HIGH
8.1
Jan 13, 2026
CVE-2026-0859
TYPO3's mail‑file spool deserialization flaw lets local users wit…
TYPO3's mail‑file spool deserialization flaw lets local users with write access to the spool directo…
HIGH
7.8
Jan 13, 2026
CVE-2021-47751
CuteEditor for PHP (now referred to as Rich Text Editor) 6.6 cont…
CuteEditor for PHP (now referred to as Rich Text Editor) 6.6 contains a directory traversal vulnerab…
HIGH
7.5
Jan 13, 2026
CVE-2022-50693
Splashtop 8.71.12001.0 contains an unquoted service path vulnerab…
Splashtop 8.71.12001.0 contains an unquoted service path vulnerability in the Splashtop Software Upd…
HIGH
8.4
Jan 13, 2026
CVE-2022-50805
Senayan Library Management System 9.0.0 contains a SQL injection …
Senayan Library Management System 9.0.0 contains a SQL injection vulnerability in the 'class' parame…
HIGH
8.2
Jan 13, 2026
CVE-2022-50806
4images 1.9 contains a remote command execution vulnerability tha…
4images 1.9 contains a remote command execution vulnerability that allows authenticated administrato…
HIGH
7.2
Jan 13, 2026
CVE-2022-50808
CoolerMaster MasterPlus 1.8.5 contains an unquoted service path v…
CoolerMaster MasterPlus 1.8.5 contains an unquoted service path vulnerability in the MPService that …
HIGH
8.4
Jan 13, 2026
🤖 AI Analysis Active
AI analysis includes: Arabic description, Saudi impact assessment, remediation steps, compliance mapping (NCA ECC, SAMA CSF, ISO 27001) and MITRE ATT&CK techniques.
💡 Search Tips
CVE-2024-12345 Search by exact ID
apache Search by product name
remote code execution Search by vulnerability type
log4j Search by common name
📡 Data Sources
NVD (NIST) · CIRCL
CISA KEV · ThreatFox
Feodo Tracker · AlienVault OTX
Auto-updated daily via cron
📣 Found this valuable?
Share it with your cybersecurity network
in LinkedIn 𝕏 X / Twitter 💬 WhatsApp ✈ Telegram
🍪 Privacy Preferences
CISO Consulting — Compliant with Saudi Personal Data Protection Law (PDPL)
We use cookies and similar technologies to provide the best experience on our platform. You can choose which types you accept.
🔒
Essential Always On
Required for the website to function properly. Cannot be disabled.
📋 Sessions, CSRF tokens, authentication, language preferences
📊
Analytics
Help us understand how visitors use the site and improve performance.
📋 Page views, session duration, traffic sources, performance metrics
⚙️
Functional
Enable enhanced features like content personalization and preferences.
📋 Dark/light theme, font size, custom dashboards, saved filters
📣
Marketing
Used to deliver content and ads relevant to your interests.
📋 Campaign tracking, retargeting, social media analytics
Privacy Policy →
CISO AI Assistant
Ask anything · Documents · Support
🔐

Introduce Yourself

Enter your details to access the full assistant

Your info is private and never shared
💬
CyberAssist
Online · responds in seconds
5 / 5
🔐 Verify Your Identity

Enter your email to receive a verification code before submitting a support request.

Enter to send · / for commands 0 / 2000
CISO AI · Powered by Anthropic Claude
✦ Quick Survey Help Us Improve CISO Consulting Your feedback shapes the future of our platform — takes less than 2 minutes.
⚠ Please answer this question to continue

How would you rate your overall experience with our platform?

Rate from 1 (poor) to 5 (excellent)

🎉
Thank you!
Your response has been recorded.