Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6649
Adobe 6383
Ibm 6266
Cisco 5746
Debian 3919
Apache 2864
Mozilla 2857
Redhat 2581
MEDIUM 6.5
CVE-2023-2913
An executable used in Rockwell Automation ThinManager ThinServer can be configured to enable an API feature in the HTTPS Server Settings. This featur…
Thinmanager
after 13.0.2
HIGH 7.5
CVE-2023-2263
The Rockwell Automation Kinetix 5700 DC Bus Power Supply Series A is vulnerable to CIP fuzzing. The new ENIP connections cannot be established if im…
Kinetix 5700 Firmware
Mitigation only
CRITICAL 9.8
CVE-2023-3595
Where this vulnerability exists in the Rockwell Automation 1756 EN2* and 1756 EN3* ControlLogix communication products, it could allow a malicious us…
1756 En2f Series A Firmware
Mitigation only
HIGH 7.5
CVE-2023-3596
Where this vulnerability exists in the Rockwell Automation 1756-EN4* Ethernet/IP communication products, it could allow a malicious user to cause a d…
1756 En4tr Firmware
Mitigation only
CRITICAL 9.6
CVE-2023-2746
The Rockwell Automation Enhanced HIM software contains
an API that the application uses that is not protected sufficiently and uses incorrect Cross…
Enhanced Him
No fix yet
HIGH 8.8
CVE-2023-2072
The Rockwell Automation PowerMonitor 1000 contains stored cross-site scripting vulnerabilities within the web page of the product. The vulnerable pa…
Powermonitor 1000 Firmware
Mitigation only
HIGH 7.5
CVE-2023-2778
A denial-of-service vulnerability exists in Rockwell Automation FactoryTalk Transaction Manager. This vulnerability can be exploited by sending a mod…
Factorytalk Transaction Manager
after 13.10
HIGH 8.2
CVE-2023-2637
Rockwell Automation's FactoryTalk System Services uses a hard-coded cryptographic key to generate administrator cookies. Hard-coded cryptographic ke…
Factorytalk Policy Manager
Mitigation only
MEDIUM 5.0
CVE-2023-2638
Rockwell Automation's FactoryTalk System Services does not verify that a backup configuration archive is password protected.
Improper authorizati…
Factorytalk Policy Manager
Mitigation only
CRITICAL 9.1
CVE-2023-1834
Rockwell Automation was made aware that Kinetix 5500 drives, manufactured between May 2022 and January 2023, and are running v7.13 may have the telne…
Kinetix 5500 Firmware
Mitigation only
HIGH 8.8
CVE-2023-2444
A cross site request forgery vulnerability exists in Rockwell Automation's FactoryTalk Vantagepoint. This vulnerability can be exploited in two ways.…
Factorytalk Vantagepoint
8.40+
HIGH 7.5
CVE-2023-2443
Rockwell Automation ThinManager product allows the use of medium strength ciphers. If the client requests an insecure cipher, a malicious actor coul…
Thinmanager
after 13.0
HIGH 7.1
CVE-2023-29030
A cross site scripting vulnerability was discovered in Rockwell Automation's ArmorStart ST product that could potentially allow a malicious user to v…
Armorstart St 284ee Firmware
Mitigation only
HIGH 7.1
CVE-2023-29031
A cross site scripting vulnerability was discovered in Rockwell Automation's ArmorStart ST product that could potentially allow a malicious user to v…
Armorstart St 284ee Firmware
Mitigation only
MEDIUM 6.5
CVE-2023-29024
A cross site scripting vulnerability was discovered in Rockwell Automation's ArmorStart ST product
A cross site scripting vulnerability was discove…
Armorstart St 284ee Firmware
Mitigation only
MEDIUM 6.1
CVE-2023-29023
A cross site scripting vulnerability was discovered in Rockwell Automation's ArmorStart ST product that could potentially allow a malicious user to v…
Armorstart St 284ee Firmware
Mitigation only
MEDIUM 5.9
CVE-2023-29022
A cross site scripting vulnerability was discovered in Rockwell Automation's ArmorStart ST product
that could potentially allow a malicious user wi…
Armorstart St 284ee Firmware
Mitigation only
MEDIUM 5.9
CVE-2023-29025
A cross site scripting vulnerability was discovered in Rockwell Automation's ArmorStart ST product
that could potentially allow a malicious user wi…
Armorstart St 284ee Firmware
Mitigation only
MEDIUM 5.9
CVE-2023-29026
A cross site scripting vulnerability was discovered in Rockwell Automation's ArmorStart ST product
that could potentially allow a malicious user wi…
Armorstart St 284ee Firmware
Mitigation only
MEDIUM 5.9
CVE-2023-29027
A cross site scripting vulnerability was discovered in Rockwell Automation's ArmorStart ST product
that could potentially allow a malicious user wi…
Armorstart St 284ee Firmware
Mitigation only
MEDIUM 5.9
CVE-2023-29028
A cross site scripting vulnerability was discovered in Rockwell Automation's ArmorStart ST product
that could potentially allow a malicious user wi…
Armorstart St 284ee Firmware
Mitigation only
MEDIUM 5.9
CVE-2023-29029
A cross site scripting vulnerability was discovered in Rockwell Automation's ArmorStart ST product
that could potentially allow a malicious user wi…
Armorstart St 284ee Firmware
Mitigation only
CRITICAL 9.8
CVE-2023-29460
An arbitrary code execution vulnerability contained in Rockwell Automation's Arena Simulation software was reported that could potentially allow a ma…
Arena
Mitigation only
CRITICAL 9.8
CVE-2023-29461
An arbitrary code execution vulnerability contained in Rockwell Automation's Arena Simulation software was reported that could potentially allow a ma…
Arena
Mitigation only
HIGH 8.8
CVE-2023-29462
An arbitrary code execution vulnerability contained in Rockwell Automation's Arena Simulation software was reported that could potentially allow a ma…
Arena
Mitigation only
HIGH 7.5
CVE-2023-27857EPSS 18%
In affected versions, a heap-based buffer over-read condition occurs when the message field indicates more data than is present in the message field
…
Thinmanager
11.0.5 / 11.1.5+
CRITICAL 9.8
CVE-2023-27855EPSS 13%
In affected versions, a path traversal exists when processing a message in Rockwell Automation's ThinManager ThinServer. An unauthenticated remote at…
Thinmanager
after 12.1.5
HIGH 7.5
CVE-2023-27856EPSS 77%
In affected versions, path traversal exists when processing a message of type 8
in Rockwell Automation's ThinManager ThinServer.
An unauthenticat…
Thinmanager
after 12.1.5
HIGH 7.8
CVE-2022-3156
A remote code execution vulnerability exists in Rockwell Automation Studio 5000 Logix Emulate software. Users are granted elevated permissions on ce…
Studio 5000 Logix Emulate
34.00+
HIGH 7.5
CVE-2022-3752
An unauthorized user could use a specially crafted sequence of Ethernet/IP messages, combined with heavy traffic
loading to cause a denial-of-servic…
Compactlogix 5480 Firmware
Mitigation only