Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6649
Adobe 6383
Ibm 6266
Cisco 5746
Debian 3919
Apache 2864
Mozilla 2857
Redhat 2581
MEDIUM 6.5
CVE-2026-12620
The GridTime 3000 GNSS Time Server leaks the access token in the URL parameters of some endpoints.
This issue affects GridTime 3000: from 1.0r0.03 t…
Gridtime 3000 Firmware
1.2r0.0+
MEDIUM 5.4
CVE-2026-12621
Improper neutralization of input during web page generation XSS
vulnerability in the GridTime 3000 (password reset form) allows XSS.
This issue aff…
Gridtime 3000 Firmware
1.2r0.0+
MEDIUM 5.4
CVE-2026-12622
The GridTime 3000 GNSS Time Server has an open redirect vulnerability in the password change form submission.
This issue affects GridTime 3000: from…
Gridtime 3000 Firmware
1.2r0.0+
MEDIUM 5.4
CVE-2026-12619
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Microchip GridTime 3000 allows Cross-Sit…
Gridtime 3000 Firmware
1.2r0.0+
HIGH 8.8
CVE-2026-2336
A privilege escalation vulnerability in Microchip IStaX allows an authenticated low-privileged user to recover a shared per-device cookie secret from…
Istax
2026.03+
CRITICAL 9.8
CVE-2025-9497
Use of Hard-coded Credentials vulnerability in Microchip Time Provider 4100 allows Malicious Manual Software Update.This issue affects Time Provider …
Timeprovider 4100 Firmware
2.5.0+
MEDIUM 6.1
CVE-2026-3010
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Microchip TimePictra allows Query System…
Timepictra
after 11.3
HIGH 7.5
CVE-2026-2844
Missing Authentication for Critical Function vulnerability in Microchip TimePictra allows Configuration/Environment Manipulation.This issue affects T…
Timepictra
after 11.3
HIGH 8.8
CVE-2025-47900
Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in Microchip Time Provider 4100 allows OS Co…
Timeprovider 4100 Firmware
2.5+
HIGH 8.8
CVE-2025-47901
Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in Microchip Time Provider 4100 allows OS Co…
Timeprovider 4100 Firmware
2.5+
HIGH 8.8
CVE-2025-47902
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Microchip Time Provider 4100 allows SQL Injecti…
Timeprovider 4100 Firmware
2.5+
HIGH 8.8
CVE-2024-9054EPSS 16%
Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection'), Exposure of Sensitive Information to an Unauthorized Acto…
Timeprovider 4100 Firmware
2.4.7+
MEDIUM 6.5
CVE-2024-7801
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Microchip TimeProvider 4100 (Data plot modules)…
Timeprovider 4100 Firmware
2.4.7+
MEDIUM 6.1
CVE-2024-43687
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Microchip TimeProvider 4100 (banner conf…
Timeprovider 4100 Firmware
2.4.7+
CRITICAL 9.8
CVE-2024-43685
Improper Authentication vulnerability in Microchip TimeProvider 4100 (login modules) allows Session Hijacking.This issue affects TimeProvider 4100: f…
Timeprovider 4100 Firmware
2.4.7+
HIGH 8.8
CVE-2024-43684
Cross-Site Request Forgery (CSRF) vulnerability in Microchip TimeProvider 4100 allows Cross Site Request Forgery, Cross-Site Scripting (XSS).This iss…
Timeprovider 4100 Firmware
2.4.7+
MEDIUM 6.1
CVE-2024-43683
URL Redirection to Untrusted Site ('Open Redirect') vulnerability in Microchip TimeProvider 4100 allows XSS Through HTTP Headers.This issue affects T…
Timeprovider 4100 Firmware
2.4.7+
MEDIUM 6.1
CVE-2024-43686EPSS 12%
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Microchip TimeProvider 4100 (data plot m…
Timeprovider 4100 Firmware
2.4.7+
CRITICAL 9.8
CVE-2024-7490
Improper Input Validation vulnerability in Microchip Techology Advanced Software Framework example DHCP server can cause remote code execution throug…
Advanced Software Framework
after 3.52.0.2574
CRITICAL 9.8
CVE-2023-51438
A vulnerability has been identified in SIMATIC IPC1047E (All versions with maxView Storage Manager < V4.14.00.26068 on Windows), SIMATIC IPC647E (All…
Maxview Storage Manager
4.14.00.26068+
CRITICAL 10.0
CVE-2024-22216
In default installations of Microchip maxView Storage Manager (for Adaptec Smart Storage Controllers) where Redfish server is configured for remote s…
Maxview Storage Manager
after 4.14.00.26064
CRITICAL 9.1
CVE-2020-27636
In Microchip MPLAB Net 3.6.1, TCP ISNs are improperly random.
Mplab Network Creator
Mitigation only
CRITICAL 9.8
CVE-2022-40022EPSS 92%
Microchip Technology (Microsemi) SyncServer S650 was discovered to contain a command injection vulnerability.
Syncserver S650 Firmware
No fix yet
MEDIUM 6.5
CVE-2022-40480
Nordic Semiconductor, Microchip Technology NRF5340-DK DT100112 was discovered to contain an issue which allows attackers to cause a Denial of Service…
Dt100112 Firmware
Mitigation only
MEDIUM 6.5
CVE-2022-45191
An issue was discovered on Microchip RN4870 1.43 devices. An attacker within BLE radio range can cause a denial of service by sending a pair confirm …
Rn4870 Firmware
Mitigation only
MEDIUM 6.5
CVE-2022-45192
An issue was discovered on Microchip RN4870 1.43 devices. An attacker within BLE radio range can cause a denial of service by sending a cleartext enc…
Rn4870 Firmware
Mitigation only
MEDIUM 5.3
CVE-2022-45190
An issue was discovered on Microchip RN4870 1.43 devices. An attacker within BLE radio range can bypass passkey entry in the legacy pairing of the de…
Rn4870 Firmware
Mitigation only
HIGH 8.6
CVE-2022-46403
The Microchip RN4870 module firmware 1.43 (and the Microchip PIC LightBlue Explorer Demo 4.2 DT100112) mishandles reject messages.
Bm78 Firmware
No fix yet
MEDIUM 6.5
CVE-2022-46402
The Microchip RN4870 module firmware 1.43 (and the Microchip PIC LightBlue Explorer Demo 4.2 DT100112) accepts PairCon_rmSend with incorrect values.
Bm78 Firmware
No fix yet
MEDIUM 5.4
CVE-2022-46401
The Microchip RN4870 module firmware 1.43 (and the Microchip PIC LightBlue Explorer Demo 4.2 DT100112) accepts PauseEncReqPlainText before pairing is…
Bm78 Firmware
No fix yet