Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2623▼ 224 respecto a la semana anterior
Críticas / altas1384▲ 157 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)56▼ 472 respecto a la semana anterior
6 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (7.6) | 0.68% | — | Westermo WeosAI | 2/9/2026 | 8/9/2026 | Westermo WeOS 5.x starting from 5.24 allows OS command injection via a media definition. | |
| Aplazada | Media (6.3) | 0.31% | — | Westermo WeosAI | 20/7/2025 | 17/6/2026 | An issue was discovered in Westermo WeOS 5 (5.24 through 5.24.4). A threat actor potentially can gain unauthorized access to sensitive information via system logging information (syslog verbose logging that includes credentials). | |
| Aplazada | Media (5.9) | 0.27% | — | Aweos Gmbh Aweos WP LockAI | 7/5/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in AWEOS GmbH AWEOS WP Lock aweos-wp-lock allows Stored XSS.This issue affects AWEOS WP Lock: from n/a through <= 1.4.8. | |
| Aplazada | Media (5.9) | 0.37% | — | Westermo WeosAI | 24/4/2025 | 17/6/2026 | Westermo WeOS 5 through 5.23.0 allows a reboot via a malformed ESP packet. | |
| Aplazada | Alta (8.8) | 0.37% | — | Aweos Gmbh Email Notifications FOR UpdatesAI | 15/4/2025 | 17/6/2026 | Missing Authorization vulnerability in AWEOS GmbH Email Notifications for Updates wp-update-mail-notification allows Privilege Escalation.This issue affects Email Notifications for Updates: from n/a through <= 1.1.6. | |
| Modificada | Crítica (9) | 1.2% | — | Westermo Weos | 30/1/2016 | 17/6/2026 | Westermo WeOS before 4.19.0 uses the same SSL private key across different customers' installations, which makes it easier for man-in-the-middle attackers to defeat cryptographic protection mechanisms by leveraging knowledge of a key. |