Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2751▲ 29 respecto a la semana anterior
Críticas / altas1468▲ 334 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)85▼ 441 respecto a la semana anterior
6 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (5.2) | 0.13% | — | Zkteco Wl20AI | 13/8/2025 | 17/6/2026 | This vulnerability exists in ZKTeco WL20 due to storage of Wi-Fi credentials, configuration data and system data in plaintext within the device firmware. An attacker with physical access could exploit this vulnerability by extracting the firmware and reverse engineer the binary data to access the plaintext sensitive… | |
| Aplazada | Media (6.9) | 0.17% | — | Zkteco Wl20AI | 13/8/2025 | 17/6/2026 | This vulnerability exists in ZKTeco WL20 due to hard-coded private key stored in plaintext within the device firmware. An attacker with physical access could exploit this vulnerability by extracting the firmware and analyzing the binary data to retrieve private key stored in the firmware of the targeted device.… | |
| Aplazada | Media (6.8) | 0.19% | — | Zkteco Wl20AI | 13/8/2025 | 17/6/2026 | This vulnerability exists in ZKTeco WL20 due to hard-coded MQTT credentials and endpoints stored in plaintext within the device firmware. An attacker with physical access could exploit this vulnerability by extracting the firmware and analyzing the binary data to retrieve the hard-coded MQTT credentials and endpoints… | |
| Aplazada | Alta (7) | 0.09% | — | Zkteco Wl20AI | 13/8/2025 | 17/6/2026 | This vulnerability exists in ZKTeco WL20 due to storage of admin and user credentials without encryption in the device firmware. An attacker with physical access could exploit this vulnerability by extracting the firmware and reverse engineer the binary data to access the unencrypted credentials stored in the firmware… | |
| Modificada | Media (6.1) | 0.47% | — | Weidmueller 19 IOT Md01 LAN H4 S0011 FirmwareWeidmueller FP IOT Md01 4EU S2 00000 FirmwareWeidmueller FP IOT Md01 LAN S2 00000 FirmwareWeidmueller FP IOT Md01 LAN S2 00011 Firmware+5 | 14/12/2022 | 17/6/2026 | Quanos "SCHEMA ST4" example web templates in version Bootstrap 2019 v2/2021 v1/2022 v1/2022 SP1 v1 or below are prone to JavaScript injection allowing a remote attacker to hijack existing sessions to e.g. other web services in the same environment or execute scripts in the users browser environment. The affected… | |
| Modificada | Crítica (9.8) | 0.95% | — | Weidmueller Uc20-wl2000-ac FirmwareWeidmueller Uc20-wl2000-iot FirmwareWeidmueller Iot-gw30 FirmwareWeidmueller Iot-gw30-4g-eu Firmware | 13/5/2021 | 17/6/2026 | In Weidmüller u-controls and IoT-Gateways in versions up to 1.12.1 a network port intended only for device-internal usage is accidentally accessible via external network interfaces. By exploiting this vulnerability the device may be manipulated or the operation may be stopped. |