Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6673
Adobe 6383
Ibm 6286
Cisco 5751
Debian 3919
Mozilla 2886
Apache 2864
Redhat 2586
HIGH 7.1
CVE-2021-40333
Weak Password Requirements vulnerability in Hitachi Energy FOX61x, XCM20 allows an attacker to gain unauthorized access to the Data Communication Net…
Fox615 Firmware
Mitigation only
HIGH 7.5
CVE-2021-35533
Improper Input Validation vulnerability in the APDU parser in the Bidirectional Communication Interface (BCI) IEC 60870-5-104 function of Hitachi Ene…
Rtu500 Firmware
Mitigation only
HIGH 7.2
CVE-2021-35534
Insufficient security control vulnerability in internal database access mechanism of Hitachi Energy Relion 670/650/SAM600-IO, Relion 650, GMS600, PWC…
Gms600 Firmware
Mitigation only
HIGH 8.1
CVE-2021-35535
Insecure Boot Image vulnerability in Hitachi Energy Relion Relion 670/650/SAM600-IO series allows an attacker who manages to get access to the front …
Relion 670 Firmware
after 2.2.3.3
HIGH 7.1
CVE-2021-35528
Improper Access Control vulnerability in the application authentication and authorization of Hitachi Energy Retail Operations, Counterparty Settlemen…
Counterparty Settlements And Billing
after 5.7.3
HIGH 7.2
CVE-2021-35529
Insufficiently Protected Credentials vulnerability in client environment of Hitachi ABB Power Grids Retail Operations and Counterparty Settlement Bil…
Counterparty Settlement And Billing
5.7.3+
HIGH 7.5
CVE-2021-35527
Password autocomplete vulnerability in the web application password field of Hitachi ABB Power Grids eSOMS allows attacker to gain access to user cre…
Esoms
6.3.1+
HIGH 7.5
CVE-2021-27196
Improper Input Validation vulnerability in Hitachi ABB Power Grids Relion 670 Series, Relion 670/650 Series, Relion 670/650/SAM600-IO, Relion 650, RE…
Relion 670 Firmware
1.2.3.20 / 1.3.0.7+
HIGH 7.5
CVE-2021-26845
Information Exposure vulnerability in Hitachi ABB Power Grids eSOMS allows unauthorized user to gain access to report data if the URL used to access …
Esoms
6.0.4.2.2 / 6.1.4+
CRITICAL 9.8
CVE-2019-5620EPSS 70%
ABB MicroSCADA Pro SYS600 version 9.3 suffers from an instance of CWE-306: Missing Authentication for Critical Function.
Microscada Pro Sys600
No fix yet
HIGH 7.6
CVE-2019-19094
Lack of input checks for SQL queries in ABB eSOMS versions 3.9 to 6.0.3 might allow an attacker SQL injection attacks against the backend database.
Esoms
after 6.0.3
HIGH 7.5
CVE-2019-19097
ABB eSOMS versions 4.0 to 6.0.3 accept connections using medium strength ciphers. If a connection is enabled using such a cipher, an attacker might b…
Esoms
after 6.0.3
MEDIUM 6.1
CVE-2019-19096
The Redis data structure component used in ABB eSOMS versions 6.0 to 6.0.2 stores credentials in clear text. If an attacker has file system access, t…
Esoms
after 6.0.2
MEDIUM 5.4
CVE-2019-19095
Lack of adequate input/output validation for ABB eSOMS versions 4.0 to 6.0.2 might allow an attacker to attack such as stored cross-site scripting by…
Esoms
after 6.0.2
MEDIUM 6.5
CVE-2019-19093
eSOMS versions 4.0 to 6.0.3 do not enforce password complexity settings, potentially resulting in lower access security due to insecure user password…
Esoms
after 6.0.3
MEDIUM 6.1
CVE-2019-19003
For ABB eSOMS versions 4.0 to 6.0.2, the HTTPOnly flag is not set. This can allow Javascript to access the cookie contents, which in turn might enabl…
Esoms
after 6.0.2
MEDIUM 6.1
CVE-2019-19089
For ABB eSOMS versions 4.0 to 6.0.3, the X-Content-Type-Options Header is missing in the HTTP response, potentially causing the response body to be i…
Esoms
after 6.0.3
MEDIUM 5.4
CVE-2019-19002
For ABB eSOMS versions 4.0 to 6.0.2, the X-XSS-Protection HTTP response header is not set in responses from the web server. For older web browser not…
Esoms
after 6.0.2
MEDIUM 6.5
CVE-2019-19000
For ABB eSOMS 4.0 to 6.0.3, the Cache-Control and Pragma HTTP header(s) have not been properly configured within the application response. This can p…
Esoms
after 6.0.3
MEDIUM 6.5
CVE-2019-19001
For ABB eSOMS versions 4.0 to 6.0.2, the X-Frame-Options header is not configured in HTTP response. This can potentially allow 'ClickJacking' attacks…
Esoms
after 6.0.2
HIGH 7.1
CVE-2019-18998
Insufficient access control in the web interface of ABB Asset Suite versions 9.0 to 9.3, 9.4 prior to 9.4.2.6, 9.5 prior to 9.5.3.2 and 9.6.0 enables…
Asset Suite
9.4.2.6 / 9.5.3.2+
CRITICAL 10.0
CVE-2019-18253
An attacker could use specially crafted paths in a specific request to read or delete files from Relion 670 Series (versions 1p1r26, 1.2.3.17, 2.0.0.…
Relion 670 Firmware
1.2.3.17 / 1p1r26+
HIGH 7.5
CVE-2019-18247
An attacker may use a specially crafted message to force Relion 650 series (versions 1.3.0.5 and prior) or Relion 670 series (versions 1.2.3.18, 2.0.…
Relion 650 Firmware
after 2.1.0.1
HIGH 7.5
CVE-2018-20720
ABB Relion 630 devices 1.1 before 1.1.0.C0, 1.2 before 1.2.0.B3, and 1.3 before 1.3.0.A6 allow remote attackers to cause a denial of service (reboot)…
Relion 630 Firmware
1.1.0.c0 / 1.2.0.b3+
CRITICAL 9.8
CVE-2018-14805
ABB eSOMS version 6.0.2 may allow unauthorized access to the system when LDAP is set to allow anonymous authentication, and specific key values withi…
Esoms
Mitigation only
HIGH 7.8
CVE-2018-1168
This vulnerability allows local attackers to escalate privileges on vulnerable installations of ABB MicroSCADA 9.3 with FP 1-2-3. An attacker must fi…
Sys600 Firmware
Mitigation only
HIGH 8.8
CVE-2017-16731
An Unprotected Transport of Credentials issue was discovered in ABB Ellipse 8.3 through Ellipse 8.9 released prior to December 2017 (including Ellips…
Ellipse
after 8.9.0
MEDIUM 5.5
CVE-2017-14025
An Improper Input Validation issue was discovered in ABB FOX515T release 1.0. An improper input validation vulnerability has been identified, allowin…
Fox515t Firmware
Mitigation only
MEDIUM 6.5
CVE-2017-15583
The embedded web server on ABB Fox515T 1.0 devices is vulnerable to Local File Inclusion. It accepts a parameter that specifies a file for display or…
Fox515t Firmware
Mitigation only