Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6673
Adobe 6383
Ibm 6286
Cisco 5751
Debian 3919
Mozilla 2886
Apache 2864
Redhat 2586
HIGH 7.5
CVE-2023-5909
KEPServerEX does not properly validate certificates from clients which may allow unauthenticated users to connect.
Industrial Gateway Server
after 7.614
CRITICAL 9.1
CVE-2023-5908
KEPServerEX is vulnerable to a buffer overflow which may allow an attacker to crash the product being accessed or leak information.
Industrial Gateway Server
after 7.614
HIGH 7.3
CVE-2023-0898
General Electric MiCOM S1 Agile is vulnerable to an attacker achieving code execution by placing malicious DLL files in the directory of the applicat…
Micom S1 Agile
Mitigation only
HIGH 7.8
CVE-2023-4487
GE CIMPLICITY 2023 is by a process control vulnerability, which could allow a local attacker to insert malicious configuration files in the expected …
Cimplicity
Mitigation only
CRITICAL 9.8
CVE-2023-3463
All versions of GE Digital CIMPLICITY that are not adhering to SDG guidance and accepting documents from untrusted sources are vulnerable to memory c…
Cimplicity
Mitigation only
HIGH 7.8
CVE-2023-1552
ToolboxST prior to version 7.10 is affected by a deserialization vulnerability. An attacker with local access to an HMI or who has conducted a social…
Toolboxst
7.10+
CRITICAL 9.8
CVE-2022-2825
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Kepware KEPServerEX 6.11.718.0. Authentication is n…
Industrial Gateway Server
1.4 / 6.12+
CRITICAL 9.1
CVE-2022-2848
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Kepware KEPServerEX 6.11.718.0. Authentication is n…
Industrial Gateway Server
1.4 / 6.12+
CRITICAL 9.8
CVE-2023-0598
GE Digital Proficy iFIX 2022, GE Digital Proficy iFIX v6.1, and GE Digital Proficy iFIX v6.5 are vulnerable to code injection, which may allow an att…
Ifix
Mitigation only
CRITICAL 9.8
CVE-2023-0754
The affected products are vulnerable to an integer
overflow or wraparound, which could allow an attacker to crash the server and remotely
execute ar…
Digital Industrial Gateway Server
after 7.612
CRITICAL 9.8
CVE-2023-0755EPSS 12%
The affected products are vulnerable to an improper validation of array index, which could allow an attacker to crash the server and remotely execute…
Digital Industrial Gateway Server
after 7.612
CRITICAL 9.8
CVE-2022-46732
Even if the authentication fails for local service authentication, the requested command could still execute regardless of authentication status.
Proficy Historian
2023+
HIGH 8.1
CVE-2022-46331
An unauthorized user could possibly delete any file on the system.
Proficy Historian
2023+
MEDIUM 6.5
CVE-2022-43494
An unauthorized user could be able to read any file on the system, potentially exposing sensitive information.
Proficy Historian
2023+
MEDIUM 6.5
CVE-2022-46660
An unauthorized user could alter or write files with full control over the path and content of the file.
Proficy Historian
2023+
HIGH 7.5
CVE-2022-38469
An unauthorized user with network access and the decryption key could decrypt sensitive data, such as usernames and passwords.
Proficy Historian
2023+
CRITICAL 9.8
CVE-2022-43977
An issue was discovered on GE Grid Solutions MS3000 devices before 3.7.6.25p0_3.2.2.17p0_4.7p0. The debug port accessible via TCP (a qconn service) l…
Ms 3000 Firmware
3.7.6.25p0_3.2.2.17p0_4.7p0+
CRITICAL 9.8
CVE-2022-43976
An issue was discovered in FC46-WebBridge on GE Grid Solutions MS3000 devices before 3.7.6.25p0_3.2.2.17p0_4.7p0. Direct access to the API is possibl…
Ms 3000 Firmware
3.7.6.25p0_3.2.2.17p0_4.7p0+
HIGH 7.5
CVE-2022-43975
An issue was discovered in FC46-WebBridge on GE Grid Solutions MS3000 devices before 3.7.6.25p0_3.2.2.17p0_4.7p0. A vulnerability in the web server a…
Ms 3000 Firmware
3.7.6.25p0_3.2.2.17p0_4.7p0+
CRITICAL 9.8
CVE-2022-24119
Certain General Electric Renewable Energy products have a hidden feature for unauthenticated remote access to the device configuration shell. This af…
Inet 900 Firmware
1.2.6 / 2.0.16+
CRITICAL 9.1
CVE-2022-24118
Certain General Electric Renewable Energy products allow attackers to use a code to trigger a reboot into the factory default configuration. This aff…
Inet 900 Firmware
1.2.6 / 2.0.16+
CRITICAL 9.8
CVE-2022-24116
Certain General Electric Renewable Energy products have inadequate encryption strength. This affects iNET and iNET II before 8.3.0.
Inet 900 Firmware
1.2.6 / 2.0.16+
CRITICAL 9.8
CVE-2022-24117
Certain General Electric Renewable Energy products download firmware without an integrity check. This affects iNET and iNET II before 8.3.0, SD befor…
Inet 900 Firmware
1.2.6 / 2.0.16+
HIGH 7.8
CVE-2022-3092
GE CIMPICITY versions 2022 and prior is
vulnerable to an out-of-bounds write, which could allow an attacker to execute arbitrary code.
Cimplicity
after 2022
HIGH 7.8
CVE-2022-3084
GE CIMPICITY versions 2022 and prior is vulnerable when data from a faulting address controls code flow starting at gmmiObj!CGmmiRootOptionTable, whi…
Cimplicity
after 2022
HIGH 7.8
CVE-2022-2952
GE CIMPICITY versions 2022 and prior is
vulnerable when data from a faulting address controls code flow starting at gmmiObj!CGmmiOptionContainer, w…
Cimplicity
after 2022
HIGH 7.8
CVE-2022-2002
GE CIMPICITY versions 2022 and prior is
vulnerable when data from faulting address controls code flow starting at gmmiObj!CGmmiOptionContainer, w…
Cimplicity
after 2022
HIGH 7.8
CVE-2022-2948
GE CIMPICITY versions 2022 and prior is
vulnerable to a heap-based buffer overflow, which could allow an attacker to execute arbitrary code.
Cimplicity
after 2022
MEDIUM 6.1
CVE-2022-37952
A reflected cross-site scripting (XSS) vulnerability exists in the iHistorian Data Display of WorkstationST (<v07.09.15) could allow an attacker to c…
Workstationst
07.09.15+
MEDIUM 6.1
CVE-2022-37953
An HTTP response splitting vulnerability exists in the AM Gateway Challenge-Response dialog of WorkstationST (<v07.09.15) and could allow an attacker…
Workstationst
07.09.15+