Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6673
Adobe 6383
Ibm 6286
Cisco 5751
Debian 3919
Mozilla 2886
Apache 2864
Redhat 2586
MEDIUM 6.1
CVE-2026-9646
A reflected cross-site scripting issue exists in URL handling.
Scadabr
No fix yet
CRITICAL 9.9
CVE-2026-9645
Exposed methods allow authenticated users to create and execute arbitrary JavaScript code on the server. The scripts execute with full access, enabli…
Scadabr
Mitigation only
CRITICAL 9.8
CVE-2026-8605
In ScadaBR version 1.2.0, a Use of Hard-Coded Credentials vulnerability could allow an attacker to access the SCADA system as admin.
Scadabr
Mitigation only
HIGH 8.8
CVE-2026-8604
In ScadaBR version 1.2.0, a CSRF vulnerability could allow an attacker to trigger any authenticated action through a victim's session by luring any l…
Scadabr
Mitigation only
CRITICAL 9.8
CVE-2026-8603
In ScadaBR version 1.2.0, an OS Command Injection vulnerability could allow an attacker to execute commands as root on the SCADA system.
Scadabr
Mitigation only
CRITICAL 9.1
CVE-2026-8602
In ScadaBR version 1.2.0, a Missing Authentication for Critical Function vulnerability could allow an unauthenticated attacker to send a HTTP GET req…
Scadabr
Mitigation only
HIGH 8.8
CVE-2021-26828 KEVEPSS 39%
OpenPLC ScadaBR through 0.9.1 on Linux and through 1.12.4 on Windows allows remote authenticated users to upload and execute arbitrary JSP files via …
Scadabr
after 1.12.4
MEDIUM 5.4
CVE-2021-26829 KEVEPSS 48%
OpenPLC ScadaBR through 0.9.1 on Linux and through 1.12.4 on Windows allows stored XSS via system_settings.shtm.
Scadabr
after 1.12.4
MEDIUM 6.1
CVE-2019-16344
A cross-site scripting (XSS) vulnerability in the login form (/ScadaBR/login.htm) in ScadaBR 1.0CE allows a remote attacker to inject arbitrary web s…
Scadabr
No fix yet
MEDIUM 6.1
CVE-2019-16321
ScadaBR 1.0CE, and 1.1.x through 1.1.0-RC, has XSS via a request for a nonexistent resource, as demonstrated by the dwr/test/ PATH_INFO.
Scadabr
No fix yet