Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6673
Adobe 6383
Ibm 6286
Cisco 5751
Debian 3919
Mozilla 2886
Apache 2864
Redhat 2586
HIGH 7.8
CVE-2024-1155
Incorrect permissions in the installation directories for shared SystemLink Elixir based services may allow an authenticated user to potentially enab…
Data Record Ad
2024_q1+
HIGH 7.8
CVE-2024-1156
Incorrect directory permissions for the shared NI RabbitMQ service may allow a local authenticated user to read RabbitMQ configuration information an…
Data Record Ad
2024_q1+
CRITICAL 9.8
CVE-2023-49716
In Emerson Rosemount GC370XA, GC700XA, and GC1500XA products, an authenticated user with network access could run arbitrary commands from a remote co…
Gc370xa Firmware
Mitigation only
HIGH 8.1
CVE-2023-51761
In Emerson Rosemount GC370XA, GC700XA, and GC1500XA products, an unauthenticated user with network access could bypass authentication and acquire adm…
Gc370xa Firmware
Mitigation only
CRITICAL 9.8
CVE-2023-46687
In Emerson Rosemount GC370XA, GC700XA, and GC1500XA products, an unauthenticated user with network access could execute arbitrary commands in root co…
Gc370xa Firmware
Mitigation only
CRITICAL 9.1
CVE-2023-43609
In Emerson Rosemount GC370XA, GC700XA, and GC1500XA products, an unauthenticated user with network access could obtain access to sensitive informatio…
Gc370xa Firmware
Mitigation only
CRITICAL 9.4
CVE-2023-1935
ROC800-Series RTU devices are vulnerable to an authentication bypass, which could allow an attacker to gain unauthorized access to data or control of…
Roc809 Firmware
Mitigation only
HIGH 7.8
CVE-2022-30260
Emerson DeltaV Distributed Control System (DCS) has insufficient verification of firmware integrity (an inadequate checksum approach, and no signatur…
Deltav Distributed Control System Sq Controller Firmware
14.3+
HIGH 7.8
CVE-2022-2791
Emerson Electric's Proficy Machine Edition Version 9.00 and prior is vulnerable to CWE-434 Unrestricted Upload of File with Dangerous Type, and will …
Proficy
after 9.00
HIGH 7.8
CVE-2022-2793
Emerson Electric's Proficy Machine Edition Version 9.00 and prior is vulenrable to CWE-353 Missing Support for Integrity Check, and has no authentica…
Electric\'s Proficy
after 9.0.0
HIGH 7.5
CVE-2022-2792
Emerson Electric's Proficy Machine Edition Version 9.00 and prior is vulenrable to CWE-284 Improper Access Control, and stores project data in a dire…
Electric\'s Proficy
after 9.0.0
MEDIUM 5.9
CVE-2022-2790
Emerson Electric's Proficy Machine Edition Version 9.00 and prior is vulenrable to CWE-347 Improper Verification of Cryptographic Signature, and does…
Electric\'s Proficy
after 9.0.0
MEDIUM 5.5
CVE-2022-2789
Emerson Electric's Proficy Machine Edition Version 9.00 and prior is vulnerable to CWE-345 Insufficient Verification of Data Authenticity, and can di…
Electric\'s Proficy
after 9.0.0
HIGH 7.3
CVE-2022-2788
Emerson Electric's Proficy Machine Edition Version 9.80 and prior is vulnerable to CWE-29 Path Traversal: '\..\Filename', also known as a ZipSlip att…
Electric\'s Proficy
after 9.80
HIGH 7.8
CVE-2022-30262
The Emerson ControlWave 'Next Generation' RTUs through 2022-05-02 mishandle firmware integrity. They utilize the BSAP-IP protocol to transmit firmwar…
Controlwave Pac Firmware
after 2022-05-02
CRITICAL 9.8
CVE-2022-30264
The Emerson ROC and FloBoss RTU product lines through 2022-05-02 perform insecure filesystem operations. They utilize the ROC protocol (4000/TCP, 500…
Dl8000 Firmware
2022-05-02+
MEDIUM 5.5
CVE-2022-29959
Emerson OpenBSI through 2022-04-29 mishandles credential storage. It is an engineering environment for the ControlWave and Bristol Babcock line of RT…
Openbsi
5.9+
MEDIUM 5.5
CVE-2022-29960
Emerson OpenBSI through 2022-04-29 uses weak cryptography. It is an engineering environment for the ControlWave and Bristol Babcock line of RTUs. DES…
Openbsi
5.9+
MEDIUM 5.5
CVE-2022-29962
The Emerson DeltaV Distributed Control System (DCS) controllers and IO cards through 2022-04-29 misuse passwords. FTP has hardcoded credentials (but …
Deltav Distributed Control System Sq Controller Firmware
after 2022-04-29
MEDIUM 5.5
CVE-2022-29963
The Emerson DeltaV Distributed Control System (DCS) controllers and IO cards through 2022-04-29 misuse passwords. TELNET on port 18550 provides acces…
Deltav Distributed Control System Sq Controller Firmware
after 2022-04-29
MEDIUM 5.5
CVE-2022-29964
The Emerson DeltaV Distributed Control System (DCS) controllers and IO cards through 2022-04-29 misuse passwords. WIOC SSH provides access to a shell…
Deltav Distributed Control System Sq Controller Firmware
after 2022-04-29
MEDIUM 5.5
CVE-2022-29965
The Emerson DeltaV Distributed Control System (DCS) controllers and IO cards through 2022-04-29 misuse passwords. Access to privileged operations on …
Deltav Distributed Control System
after 2022-04-29
HIGH 7.8
CVE-2022-29957
The Emerson DeltaV Distributed Control System (DCS) through 2022-04-29 mishandles authentication. It utilizes several proprietary protocols for a wid…
Deltav Distributed Control System
after 2022-04-29
MEDIUM 6.5
CVE-2020-16235
Inadequate encryption may allow the credentials used by Emerson OpenEnterprise, up through version 3.3.5, to access field devices and external system…
Openenterprise Scada Server
after 3.3.5
CRITICAL 9.8
CVE-2020-10640
Emerson OpenEnterprise versions through 3.3.4 may allow an attacker to run an arbitrary commands with system privileges or perform remote code execut…
Openenterprise Scada Server
after 3.3.4
HIGH 7.5
CVE-2020-10636
Inadequate encryption may allow the passwords for Emerson OpenEnterprise versions through 3.3.4 user accounts to be obtained.
Openenterprise Scada Server
after 3.3.4
MEDIUM 5.3
CVE-2020-10632
Inadequate folder security permissions in Emerson OpenEnterprise versions through 3.3.4 may allow modification of important configuration files, whic…
Openenterprise Scada Server
after 3.3.4
CRITICAL 9.8
CVE-2021-45420EPSS 18%
Emerson Dixell XWEB-500 products are affected by arbitrary file write vulnerability in /cgi-bin/logo_extra_upload.cgi, /cgi-bin/cal_save.cgi, and /cg…
Dixell Xweb 500 Firmware
Mitigation only
HIGH 7.5
CVE-2021-45421
Emerson Dixell XWEB-500 products are affected by information disclosure via directory listing. A potential attacker can use this misconfiguration to …
Dixell Xweb 500 Firmware
No fix yet
HIGH 7.3
CVE-2021-44463
Missing DLLs, if replaced by an insider, could allow an attacker to achieve local privilege escalation on the DeltaV Distributed Control System Contr…
Deltav
Mitigation only