Vulnerabilities
Summary — last 7 days
New vulnerabilities3,019▲ 545 vs. last week
Critical / high1,439▲ 265 vs. last week
New active exploitation (KEV)5▼ 5 vs. last week
Unscored (no CVSS)382▲ 175 vs. last week
17 results, sorted by published date (most recent first)
| CVE | Status | Severity | EPSS | Active exploitation | Affected technologies | Published ▼ | Modified | Description |
|---|---|---|---|---|---|---|---|---|
| Deferred | Medium (5.3) | 0.24% | — | Seres Software SywebAI | 8/27/2026 | 8/28/2026 | Observable discrepancy vulnerability in Seres Software syWEB allows Account Footprinting. This issue affects syWEB: through 27082026. NOTE: The vendor was contacted and it was learned that the product is not supported. | |
| Deferred | Medium (6.1) | 0.18% | — | Seres Software SywebAI | 8/27/2026 | 8/28/2026 | Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Seres Software syWEB allows Reflected XSS. This issue affects syWEB: through 27082026. NOTE: The vendor was contacted and it was learned that the product is not supported. | |
| Analyzed | High (7.5) | 0.22% | — | Weintek EasywebWeintek Cmt-3072xh2 Firmware | 3/3/2026 | 6/17/2026 | Weintek cMT-3072XH2 easyweb v2.1.53, OS v20231011 was discovered to stroe credentials in plaintext in the component uac_temp.db. | |
| Analyzed | Critical (9.8) | 0.36% | — | Weintek EasywebWeintek Cmt-3072xh2 Firmware | 3/3/2026 | 6/17/2026 | An issue in the reset_pj.cgi endpoint of Weintek cMT-3072XH2 easyweb v2.1.53, OS v20231011 allows unauthorized attackers to execute arbitrary commands via supplying a crafted GET request. | |
| Analyzed | Medium (6.5) | 0.31% | — | Weintek EasywebWeintek Cmt-3072xh2 Firmware | 3/3/2026 | 6/17/2026 | Incorrect access control in the VNC component of Weintek cMT-3072XH2 easyweb v2.1.53, OS v20231011 allows unauthorized attackers to access the HMI system. | |
| Analyzed | Critical (9.8) | 0.37% | — | Weintek EasywebWeintek Cmt-3072xh2 Firmware | 3/3/2026 | 6/17/2026 | An authentication bypass vulnerability in the authorization mechanism of Weintek cMT-3072XH2 easyweb v2.1.53, OS v20231011 allows unauthorized attackers to perform Administrative actions using service accounts. | |
| Analyzed | Medium (5.3) | 0.18% | — | Weintek EasywebWeintek Cmt-3072xh2 Firmware | 3/3/2026 | 6/17/2026 | Weintek cMT-3072XH2 easyweb v2.1.53, OS v20231011 was discovered to contain a hardcoded encryption key which could allow attackers to access sensitive information. | |
| Analyzed | High (8.8) | 1.3% | — | Weintek EasywebWeintek Cmt-3072xh2 Firmware | 3/3/2026 | 6/17/2026 | Weintek cMT-3072XH2 easyweb v2.1.53, OS v20231011 was discovered to contain an authenticated command injection vulnerability via the HMI Name parameter. | |
| Analyzed | High (7.5) | 0.35% | — | Weintek EasywebWeintek Cmt-3072xh2 Firmware | 3/3/2026 | 6/17/2026 | Weintek cMT-3072XH2 easyweb v2.1.53, OS v20231011 was discovered to contain a hardcoded password in the FTP protocol. | |
| Analyzed | Critical (9.8) | 1.7% | — | Weintek EasywebWeintek Cmt-3072xh2 Firmware | 3/3/2026 | 6/17/2026 | A command injection vulnerability in the DHCP activation feature of Weintek cMT-3072XH2 easyweb Web Version v2.1.53, OS v20231011 allows attackers to execute arbitrary commands with root privileges. | |
| Analyzed | High (7.5) | 0.30% | — | Weintek EasywebWeintek Cmt-3072xh2 Firmware | 3/3/2026 | 6/17/2026 | Incorrect access control in the component download_wb.cgi of Weintek cMT-3072XH2 easyweb Web Version v2.1.53, OS v20231011 allows unauthenticated attack to download arbitrary files. | |
| Deferred | High (7.6) | 0.18% | — | Seres Software SywebAI | 2/3/2026 | 6/17/2026 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Seres Software syWEB allows Reflected XSS. This issue affects syWEB: through 03022026. NOTE: The vendor was contacted early about this disclosure but did not respond in any way. | |
| Modified | Medium (5.3) | 1.0% | — | Easyjs Easywebpack-cli | 12/15/2022 | 6/17/2026 | Directory Traversal vulnerability in easywebpack-cli before 4.5.2 allows attackers to obtain sensitive information via crafted GET request. | |
| Modified | Critical (9.8) | 2.8% | — | Nexusfi Opac Easyweb Five | 10/3/2018 | 6/17/2026 | An issue was discovered in OPAC EasyWeb Five 5.7. There is SQL injection via the w2001/index.php?scelta=campi biblio parameter. | |
| Modified | High (7.5) | 1.2% | — | Wcs4web Easywebrealestate | 10/4/2012 | 6/16/2026 | Multiple SQL injection vulnerabilities in EasyWebRealEstate allow remote attackers to execute arbitrary SQL commands via the (1) lstid parameter to listings.php or (2) infoid parameter to index.php. | |
| Modified | High (7.5) | 1.3% | — | Easyweb Factory Subjects Module | 9/10/2004 | 6/16/2026 | Multiple SQL injection vulnerabilities in index.php in Subjects 2.0 Postnuke module allow remote attackers to execute arbitrary SQL commands via the (1) pageid, (2) subid, or (3) catid parameters. | |
| Modified | Medium (5) | 8.2% | — | Easyweb Filemanager | 7/23/2004 | 6/16/2026 | Directory traversal vulnerability in EasyWeb FileManager 1.0 RC-1 for PostNuke allows remote attackers to retrieve arbitrary files via a .. (dot dot) in the pathext parameter. |