Vulnerability index

Browse CVEs

98 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

CRITICAL 10.0 CVE-2026-3611EPSS 6% The Honeywell IQ4x building management controller, exposes its full web-based HMI without authentication in its factory-default configuration. With n… Iq4e Firmware 3.30+ Fix from $2,3002026-03-12 HIGH 8.8 CVE-2025-2605EPSS 13% Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in Honeywell MB-Secure allows Privilege Abus… Mb Secure Firmware 03.09 / 12.53+ Fix from $1,9502025-05-02 MEDIUM 6.1 CVE-2024-46453 A cross-site scripting (XSS) vulnerability in the component /test/ of iq3xcite v2.31 to v3.05 allows attackers to execute arbitrary web scripts or HT… Iq3xcite Firmware 3.11+ Fix from $1,6002024-09-27 CRITICAL 9.8 CVE-2024-2420 LenelS2 NetBox access control and event monitoring system was discovered to contain Hardcoded Credentials in versions prior to and including 5.6.1 wh… Lenels2 Netbox 5.6.2+ Fix from $2,3002024-05-30 CRITICAL 9.8 CVE-2024-2421 LenelS2 NetBox access control and event monitoring system was discovered to contain an unauthenticated RCE in versions prior to and including 5.6.1, … Lenels2 Netbox 5.6.2+ Fix from $2,3002024-05-30 HIGH 8.8 CVE-2024-2422 LenelS2 NetBox access control and event monitoring system was discovered to contain an authenticated RCE in versions prior to and including 5.6.1, wh… Lenels2 Netbox 5.6.2+ Fix from $1,9502024-05-30 MEDIUM 6.5 CVE-2023-51605 Honeywell Saia PG5 Controls Suite XML External Entity Processing Information Disclosure Vulnerability. This vulnerability allows remote attackers to … Saia Pg5 Controls Suite Mitigation only Fix from $1,6002024-05-03 HIGH 8.8 CVE-2023-51599 Honeywell Saia PG5 Controls Suite Directory Traversal Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbi… Saia Pg5 Controls Suite Mitigation only Fix from $1,9502024-05-03 HIGH 8.8 CVE-2023-51603 Honeywell Saia PG5 Controls Suite CAB File Parsing Directory Traversal Remote Code Execution Vulnerability. This vulnerability allows remote attacker… Saia Pg5 Controls Suite Mitigation only Fix from $1,9502024-05-03 MEDIUM 6.5 CVE-2023-51600 Honeywell Saia PG5 Controls Suite XML External Entity Processing Information Disclosure Vulnerability. This vulnerability allows remote attackers to … Saia Pg5 Controls Suite Mitigation only Fix from $1,6002024-05-03 MEDIUM 6.5 CVE-2023-51601 Honeywell Saia PG5 Controls Suite XML External Entity Processing Information Disclosure Vulnerability. This vulnerability allows remote attackers to … Saia Pg5 Controls Suite Mitigation only Fix from $1,6002024-05-03 MEDIUM 6.5 CVE-2023-51602 Honeywell Saia PG5 Controls Suite XML External Entity Processing Information Disclosure Vulnerability. This vulnerability allows remote attackers to … Saia Pg5 Controls Suite Mitigation only Fix from $1,6002024-05-03 MEDIUM 6.5 CVE-2023-51604 Honeywell Saia PG5 Controls Suite XML External Entity Processing Information Disclosure Vulnerability. This vulnerability allows remote attackers to … Saia Pg5 Controls Suite Mitigation only Fix from $1,6002024-05-03 MEDIUM 6.5 CVE-2023-36483 Authorization bypass can be achieved by session ID prediction in MASmobile Classic Android  version 1.16.18 and earlier and MASmobile Classic iOS v… Masmobile Asp.net Services after 1.16.18 Fix from $1,6002024-03-16 HIGH 7.5 CVE-2024-1309 Uncontrolled Resource Consumption vulnerability in Honeywell Niagara Framework on Windows, Linux, QNX allows Content Spoofing.This issue affects Niag… Niagara Framework 3.8.1+ Fix from $1,9502024-02-13 MEDIUM 5.3 CVE-2023-5390 An attacker could potentially exploit this vulnerability, leading to files being read from the Honeywell Experion ControlEdge VirtualUOC and ControlE… Controledge Unit Operations Controller Firmware Mitigation only Fix from $1,6002024-01-31 HIGH 7.5 CVE-2023-5389 An attacker could potentially exploit this vulnerability, leading to the ability to modify files on Honeywell Experion ControlEdge VirtualUOC and Con… Controledge Unit Operations Controller Firmware Mitigation only Fix from $1,9502024-01-30 HIGH 7.8 CVE-2023-6179 Honeywell ProWatch, 4.5, including all Service Pack versions, contain a Vulnerability in Application Server's executable folder(s). A(n) attacker cou… Prowatch Mitigation only Fix from $1,9502023-11-17 CRITICAL 9.8 CVE-2023-3710EPSS 33% Improper Input Validation vulnerability in Honeywell PM43 on 32 bit, ARM (Printer web page modules) allows Command Injection.This issue affects PM43 … Pm43 Firmware Mitigation only Fix from $2,3002023-09-12 HIGH 8.8 CVE-2023-3711 Session Fixation vulnerability in Honeywell PM43 on 32 bit, ARM (Printer web page modules) allows Session Credential Falsification through Prediction… Pm43 Firmware Mitigation only Fix from $1,9502023-09-12 HIGH 7.8 CVE-2023-3712 Files or Directories Accessible to External Parties vulnerability in Honeywell PM43 on 32 bit, ARM (Printer web page modules) allows Privilege Escala… Pm43 Firmware Mitigation only Fix from $1,9502023-09-12 HIGH 7.5 CVE-2023-25948 Server information leak of configuration data when an error is generated in response to a specially crafted message. See Honeywell Security Notificat… Experion Server after 520.2tcu2 Fix from $1,9502023-07-13 HIGH 7.5 CVE-2023-26597 Controller DoS due to buffer overflow in the handling of a specially crafted message received by the controller. See Honeywell Security Notification … C300 Firmware after 520.2tcu2 Fix from $1,9502023-07-13 CRITICAL 9.8 CVE-2023-25178 Controller may be loaded with malicious firmware which could enable remote code execution. See Honeywell Security Notification for recommendations on… C300 Firmware after 520.2tcu2 Fix from $2,3002023-07-13 HIGH 7.5 CVE-2023-25078 Server or Console Station DoS due to heap overflow occurring during the handling of a specially crafted message for a specific configuration operatio… Experion Server after 520.2tcu2 Fix from $1,9502023-07-13 HIGH 7.5 CVE-2023-25770 Controller DoS may occur due to buffer overflow when an error is generated in response to a specially crafted message. See Honeywell Security Notific… C300 Firmware after 520.2tcu2 Fix from $1,9502023-07-13 HIGH 7.5 CVE-2023-22435 Experion server may experience a DoS due to a stack overflow when handling a specially crafted message. Experion Server after 520.2tcu2 Fix from $1,9502023-07-13 HIGH 7.5 CVE-2023-23585 Experion server DoS due to heap overflow occurring during the handling of a specially crafted message for a specific configuration operation.  See H… Experion Server after 520.2tcu2 Fix from $1,9502023-07-13 HIGH 7.5 CVE-2023-24474 Experion server may experience a DoS due to a heap overflow which could occur when handling a specially crafted message Experion Server after 520.2tcu2 Fix from $1,9502023-07-13 HIGH 7.5 CVE-2023-24480 Controller DoS due to stack overflow when decoding a message from the server.  See Honeywell Security Notification for recommendations on upgrading … C300 Firmware after 520.2tcu2 Fix from $1,9502023-07-13