Vulnerabilities

Summary — last 7 days

New vulnerabilities3,019▲ 545 vs. last week
Critical / high1,439▲ 265 vs. last week
New active exploitation (KEV)5▼ 5 vs. last week
Unscored (no CVSS)382▲ 175 vs. last week
–

17 results, sorted by published date (most recent first)

CVEStatusSeverityEPSS Active exploitationAffected technologiesPublished ▼Modified Description
DeferredMedium (5.3)0.24%—Seres Software SywebAI8/27/20268/28/2026
Observable discrepancy vulnerability in Seres Software syWEB allows Account Footprinting. This issue affects syWEB: through 27082026. NOTE: The vendor was contacted and it was learned that the product is not supported.
DeferredMedium (6.1)0.18%—Seres Software SywebAI8/27/20268/28/2026
Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Seres Software syWEB allows Reflected XSS. This issue affects syWEB: through 27082026. NOTE: The vendor was contacted and it was learned that the product is not supported.
AnalyzedHigh (7.5)0.22%—Weintek EasywebWeintek Cmt-3072xh2 Firmware3/3/20266/17/2026
Weintek cMT-3072XH2 easyweb v2.1.53, OS v20231011 was discovered to stroe credentials in plaintext in the component uac_temp.db.
AnalyzedCritical (9.8)0.36%—Weintek EasywebWeintek Cmt-3072xh2 Firmware3/3/20266/17/2026
An issue in the reset_pj.cgi endpoint of Weintek cMT-3072XH2 easyweb v2.1.53, OS v20231011 allows unauthorized attackers to execute arbitrary commands via supplying a crafted GET request.
AnalyzedMedium (6.5)0.31%—Weintek EasywebWeintek Cmt-3072xh2 Firmware3/3/20266/17/2026
Incorrect access control in the VNC component of Weintek cMT-3072XH2 easyweb v2.1.53, OS v20231011 allows unauthorized attackers to access the HMI system.
AnalyzedCritical (9.8)0.37%—Weintek EasywebWeintek Cmt-3072xh2 Firmware3/3/20266/17/2026
An authentication bypass vulnerability in the authorization mechanism of Weintek cMT-3072XH2 easyweb v2.1.53, OS v20231011 allows unauthorized attackers to perform Administrative actions using service accounts.
AnalyzedMedium (5.3)0.18%—Weintek EasywebWeintek Cmt-3072xh2 Firmware3/3/20266/17/2026
Weintek cMT-3072XH2 easyweb v2.1.53, OS v20231011 was discovered to contain a hardcoded encryption key which could allow attackers to access sensitive information.
AnalyzedHigh (8.8)1.3%—Weintek EasywebWeintek Cmt-3072xh2 Firmware3/3/20266/17/2026
Weintek cMT-3072XH2 easyweb v2.1.53, OS v20231011 was discovered to contain an authenticated command injection vulnerability via the HMI Name parameter.
AnalyzedHigh (7.5)0.35%—Weintek EasywebWeintek Cmt-3072xh2 Firmware3/3/20266/17/2026
Weintek cMT-3072XH2 easyweb v2.1.53, OS v20231011 was discovered to contain a hardcoded password in the FTP protocol.
AnalyzedCritical (9.8)1.7%—Weintek EasywebWeintek Cmt-3072xh2 Firmware3/3/20266/17/2026
A command injection vulnerability in the DHCP activation feature of Weintek cMT-3072XH2 easyweb Web Version v2.1.53, OS v20231011 allows attackers to execute arbitrary commands with root privileges.
AnalyzedHigh (7.5)0.30%—Weintek EasywebWeintek Cmt-3072xh2 Firmware3/3/20266/17/2026
Incorrect access control in the component download_wb.cgi of Weintek cMT-3072XH2 easyweb Web Version v2.1.53, OS v20231011 allows unauthenticated attack to download arbitrary files.
DeferredHigh (7.6)0.18%—Seres Software SywebAI2/3/20266/17/2026
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Seres Software syWEB allows Reflected XSS. This issue affects syWEB: through 03022026. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.
ModifiedMedium (5.3)1.0%—Easyjs Easywebpack-cli12/15/20226/17/2026
Directory Traversal vulnerability in easywebpack-cli before 4.5.2 allows attackers to obtain sensitive information via crafted GET request.
ModifiedCritical (9.8)2.8%—Nexusfi Opac Easyweb Five10/3/20186/17/2026
An issue was discovered in OPAC EasyWeb Five 5.7. There is SQL injection via the w2001/index.php?scelta=campi biblio parameter.
ModifiedHigh (7.5)1.2%—Wcs4web Easywebrealestate10/4/20126/16/2026
Multiple SQL injection vulnerabilities in EasyWebRealEstate allow remote attackers to execute arbitrary SQL commands via the (1) lstid parameter to listings.php or (2) infoid parameter to index.php.
ModifiedHigh (7.5)1.3%—Easyweb Factory Subjects Module9/10/20046/16/2026
Multiple SQL injection vulnerabilities in index.php in Subjects 2.0 Postnuke module allow remote attackers to execute arbitrary SQL commands via the (1) pageid, (2) subid, or (3) catid parameters.
ModifiedMedium (5)8.2%—Easyweb Filemanager7/23/20046/16/2026
Directory traversal vulnerability in EasyWeb FileManager 1.0 RC-1 for PostNuke allows remote attackers to retrieve arbitrary files via a .. (dot dot) in the pathext parameter.