Vulnerability index

Browse CVEs

47 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Intelligent Power Protector CRITICAL 9.9
CVE-2026-22619

Eaton Intelligent Power Protector (IPP) is affected by insecure library loading in its executable, which could lead to arbitrary code execution by an…

Fix: 2.00+
Fix from $2,300 2026-04-16
Intelligent Power Protector HIGH 7.1
CVE-2026-22618

A security misconfiguration was identified in Eaton Intelligent Power Protector (IPP), where an HTTP response header was set with an insecure attribu…

Fix: 2.00+
Fix from $1,950 2026-04-16
Intelligent Power Protector HIGH 7.4
CVE-2026-22617

Eaton Intelligent Power Protector (IPP) uses an insecure cookie configuration, which could allow a network‑based attacker to intercept the cookie and…

Fix: 2.00+
Fix from $1,950 2026-04-16
Intelligent Power Protector HIGH 7.5
CVE-2026-22616

Eaton Intelligent Power Protector (IPP) software allows repeated authentication attempts against the web interface login page due to insufficient rat…

Fix: 2.00+
Fix from $1,950 2026-04-16
Intelligent Power Protector HIGH 7.2
CVE-2026-22615

Due to improper input validation in one of the Eaton Intelligent Power Protector (IPP) XML, it is possible for an attacker with admin privileges and …

Fix: 2.00+
Fix from $1,950 2026-04-16
Easysoft MEDIUM 6.1
CVE-2026-22614

The encryption mechanism used in Eaton's EasySoft project file was insecure and susceptible to brute force attacks, an attacker with access to this f…

Fix: 8.41+
Fix from $1,600 2026-03-10
Ups Companion HIGH 8.6
CVE-2025-59887

Improper authentication of library files in the Eaton UPS Companion software installer could lead to arbitrary code execution of an attacker with the…

Fix: 3.0+
Fix from $1,950 2025-12-26
Ups Companion HIGH 7.8
CVE-2025-67450

Due to insecure library loading in the Eaton UPS Companion software executable, an attacker with access to the software package could perform arbit…

Fix: 3.0+
Fix from $1,950 2025-12-26
Ups Companion MEDIUM 6.7
CVE-2025-59888

Improper quotation in search paths in the Eaton UPS Companion software installer could lead to arbitrary code execution of an attacker with the acces…

Fix: 3.0+
Fix from $1,600 2025-12-26
Xcomfort Ethernet Communication Interface HIGH 8.8
CVE-2025-59886

Improper input validation at one of the endpoints of Eaton xComfort ECI's web interface, could lead into an attacker with network access to the dev…

Mitigation only
Fix from $1,950 2025-12-23
Foreseer Electrical Power Monitoring System MEDIUM 6.5
CVE-2024-31416

The Eaton Foreseer software provides multiple customizable input fields for the users to configure parameters in the tool like alarms, reports, etc. …

Fix: 7.8.600+
Fix from $1,600 2024-09-13
Foreseer Electrical Power Monitoring System HIGH 8.1
CVE-2024-31415

The Eaton Foreseer software provides the feasibility for the user to configure external servers for multiple purposes such as network management, use…

Fix: 7.8.600+
Fix from $1,950 2024-09-13
Foreseer Electrical Power Monitoring System MEDIUM 6.1
CVE-2024-31414

The Eaton Foreseer software provides users the capability to customize the dashboard in WebView pages. However, the input fields for this feature in …

Fix: 7.8.600+
Fix from $1,600 2024-09-13
Easy Box E4 Ac1 Firmware MEDIUM 6.6
CVE-2023-43776

Eaton easyE4 PLC offers a device password protection functionality to facilitate a secure connection and prevent unauthorized access. It was observed…

Fix: 2.02+
Fix from $1,600 2023-10-17
Easysoft MEDIUM 6.5
CVE-2023-43777

Eaton easySoft software is used to program easy controllers and displays for configuring, programming and defining parameters for all the intelligent…

Fix: 8.01+
Fix from $1,600 2023-10-17
Smp Sg 4260 Firmware MEDIUM 5.3
CVE-2023-43775

Denial-of-service vulnerability in the web server of the Eaton SMP Gateway allows attacker to potentially force an unexpected restart of the automa…

Fix: 8.0r9 / 8.1r5+
Fix from $1,600 2023-09-27
Foreseer Electrical Power Monitoring System CRITICAL 9.8
CVE-2022-33859

A security vulnerability was discovered in the Eaton Foreseer EPMS software. Foreseer EPMS connects an operation’s vast array of devices to assist in…

Fix: 7.6+
Fix from $2,300 2022-10-28
Intelligent Power Protector MEDIUM 5.4
CVE-2021-23283

Eaton Intelligent Power Protector (IPP) prior to version 1.69 is vulnerable to stored Cross Site Scripting. The vulnerability exists due to insuffici…

Fix: 1.69+
Fix from $1,600 2022-04-19
Intelligent Power Manager HIGH 8.0
CVE-2021-23286

Eaton Intelligent Power Manager Infrastructure (IPM Infrastructure) version 1.5.0plus205 and all prior versions are vulnerable to CSV Formula Injecti…

Fix: after 1.5.0plus205
Fix from $1,950 2022-04-18
Intelligent Power Manager MEDIUM 5.4
CVE-2021-23287

The vulnerability exists due to insufficient validation of input of certain resources within the IPM software. This issue affects: Intelligent Power …

Fix: 1.70+
Fix from $1,600 2022-04-01
Intelligent Power Manager CRITICAL 10.0
CVE-2021-23281

Eaton Intelligent Power Manager (IPM) prior to 1.69 is vulnerable to unauthenticated remote code execution vulnerability. IPM software does not sanit…

Fix: 1.69+
Fix from $2,300 2021-04-13
Intelligent Power Manager CRITICAL 10.0
CVE-2021-23277

Eaton Intelligent Power Manager (IPM) prior to 1.69 is vulnerable to unauthenticated eval injection vulnerability. The software does not neutralize c…

Fix: 1.68 / 1.69+
Fix from $2,300 2021-04-13
Intelligent Power Manager CRITICAL 10.0
CVE-2021-23279EPSS 27%

Eaton Intelligent Power Manager (IPM) prior to 1.69 is vulnerable to unauthenticated arbitrary file delete vulnerability induced due to improper inpu…

Fix: 1.68 / 1.69+
Fix from $2,300 2021-04-13
Intelligent Power Manager CRITICAL 9.9
CVE-2021-23280

Eaton Intelligent Power Manager (IPM) prior to 1.69 is vulnerable to authenticated arbitrary file upload vulnerability. IPM’s maps_srv.js allows an a…

Fix: 1.68 / 1.69+
Fix from $2,300 2021-04-13
Intelligent Power Manager CRITICAL 9.6
CVE-2021-23278

Eaton Intelligent Power Manager (IPM) prior to 1.69 is vulnerable to authenticated arbitrary file delete vulnerability induced due to improper input …

Fix: 1.68 / 1.69+
Fix from $2,300 2021-04-13
Intelligent Power Manager HIGH 8.8
CVE-2021-23276

Eaton Intelligent Power Manager (IPM) prior to 1.69 is vulnerable to authenticated SQL injection. A malicious user can send a specially crafted packe…

Fix: 1.68 / 1.69+
Fix from $1,950 2021-04-13
Easysoft HIGH 7.8
CVE-2020-6656

Eaton's easySoft software v7.xx prior to v7.22 are susceptible to file parsing type confusion remote code execution vulnerability. A malicious entity…

Fix: 7.20+
Fix from $1,950 2021-01-07
Easysoft HIGH 7.8
CVE-2020-6655

The Eaton's easySoft software v7.xx prior to v7.22 are susceptible to Out-of-bounds remote code execution vulnerability. A malicious entity can execu…

Fix: 7.22+
Fix from $1,950 2021-01-07
9000x Programming And Configuration Software HIGH 7.8
CVE-2020-6654

A DLL Hijacking vulnerability in Eaton's 9000x Programming and Configuration Software v 2.0.38 and prior allows an attacker to execute arbitrary code…

Fix: after 2.0.38
Fix from $1,950 2020-09-30
Intelligent Power Manager HIGH 7.8
CVE-2020-6652

Incorrect Privilege Assignment vulnerability in Eaton's Intelligent Power Manager (IPM) v1.67 & prior allow non-admin users to upload the system conf…

Fix: after 1.67
Fix from $1,950 2020-05-07