Vulnerability index

Browse CVEs

689 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Powerlogic P7 Firmware HIGH 7.5
CVE-2026-9716

CWE-476 NULL Pointer Dereference vulnerability exists that could cause a denial-of-service condition, rendering the device’s HMI and configuration fu…

Fix: 02.004.001.000+
Fix from $1,950 2026-06-25
Powerlogic P7 Firmware HIGH 7.2
CVE-2026-9717

CWE-78 Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability exists that could allow unauthorized execution…

Fix: 02.004.001.000+
Fix from $1,950 2026-06-25
Powerlogic P7 Firmware MEDIUM 6.5
CVE-2026-9718

CWE-617 Reachable Assertion vulnerability exists that could allow an authenticated attacker to trigger a denial-of-service condition, impacting syste…

Fix: 02.004.001.000+
Fix from $1,600 2026-06-25
Easylogic T150 Firmware HIGH 7.5
CVE-2026-9650

CWE-522 Insufficiently Protected Credentials vulnerability that could cause unauthorized access and exposure of sensitive information when unauthenti…

Fix: 11.06.32 / 11.06.38+
Fix from $1,950 2026-06-25
Struxureware Data Center Expert MEDIUM 6.5
CVE-2026-8045

CWE-611 Improper Restriction of XML External Entity Reference vulnerability exists that could cause information disclosure of server-side file conten…

Fix: 9.1.2+
Fix from $1,600 2026-06-09
Ecostruxure Machine Expert Hvac HIGH 7.5
CVE-2026-6332

CWE-312: Cleartext Storage of Sensitive Information vulnerability exists that could cause the disclosure of a sensitive information which could resu…

Fix: 1.10.0+
Fix from $1,950 2026-05-14
Ecostruxure Panel Server Pas400 Firmware HIGH 7.5
CVE-2026-6866

CWE-1188 Initialization of a Resource with an Insecure Default vulnerability exists that could cause unauthorized disclosure of sensitive information…

Fix: 002.006.000+
Fix from $1,950 2026-05-12
Powerchute Serial Shutdown MEDIUM 6.5
CVE-2026-2405

CWE-400 Uncontrolled Resource Consumption vulnerability exists that could cause excessive troubleshooting zip file creation and denial of service whe…

Fix: 1.5+
Fix from $1,600 2026-04-14
Powerchute Serial Shutdown MEDIUM 5.3
CVE-2026-2404

CWE-116 Improper Encoding or Escaping of Output vulnerability exists that could cause log injection and forged log when an attacker alters the POST /…

Fix: 1.5+
Fix from $1,600 2026-04-14
Powerchute Serial Shutdown MEDIUM 6.1
CVE-2026-2399

CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability exists that could cause critical files overwritte…

Fix: 1.5+
Fix from $1,600 2026-04-14
Powerchute Serial Shutdown MEDIUM 5.3
CVE-2026-2402

CWE-307 Improper Restriction of Excessive Authentication Attempts vulnerability exists that would allow an attacker to gain access to the user accoun…

Fix: 1.5+
Fix from $1,600 2026-04-14
Powerchute Serial Shutdown MEDIUM 5.0
CVE-2026-2401

CWE-532 Insertion of Sensitive Information into Log File vulnerability exists that could cause confidential information to be exposed when a Web Adm…

Fix: 1.5+
Fix from $1,600 2026-04-14
Ecostruxure Automation Expert HIGH 8.2
CVE-2026-2273

CWE-94: Improper Control of Generation of Code ('Code Injection') vulnerability exist that could cause execution of untrusted commands on the enginee…

Fix: 25.0.1+
Fix from $1,950 2026-03-10
Ecostruxure Foxboro Dcs Control Software MEDIUM 6.5
CVE-2026-1286

CWE-502: Deserialization of untrusted data vulnerability exists that could lead to loss of confidentiality, integrity and potential remote code execu…

Fix: 8.1+
Fix from $1,600 2026-03-10
Modicon M258 Firmware MEDIUM 5.4
CVE-2025-13902

CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability exists that could cause condition where aut…

Fix: 5.4.13.12+
Fix from $1,600 2026-03-10
Modicon M241 Firmware MEDIUM 5.3
CVE-2025-13901

CWE-404 Improper Resource Shutdown or Release vulnerability exists that could cause partial Denial of Service on Machine Expert protocol when an unau…

Fix: 5.4.10.12 / 5.4.13.12+
Fix from $1,600 2026-03-10
Ecostruxure Power Monitoring Expert HIGH 7.8
CVE-2025-11739

CWE‑502: Deserialization of Untrusted Data vulnerability exists that could cause arbitrary code execution with administrative privileges when a local…

Mitigation only
Fix from $1,950 2026-03-10
Ecostruxure Power Build Rapsody HIGH 7.8
CVE-2025-13845

CWE-416: Use After Free vulnerability that could cause remote code execution when the end user imports the malicious project file (SSD file) into Rap…

Fix: after 2.8.8.0100
Fix from $1,950 2026-01-15
Ecostruxure Power Build Rapsody MEDIUM 5.3
CVE-2025-13844

CWE-415: Double Free vulnerability exists that could cause heap memory corruption when the end user imports a malicious project file (SSD file) share…

Fix: after 2.8.8
Fix from $1,600 2026-01-15
Powerlogic Pm5341 Firmware HIGH 7.5
CVE-2024-9409

CWE-400: An Uncontrolled Resource Consumption vulnerability exists that could cause the device to become unresponsive resulting in communication loss…

Fix: 2.4.0 / 2.7.0+
Fix from $1,950 2024-11-13
Ecostruxure It Gateway CRITICAL 9.8
CVE-2024-10575

CWE-862: Missing Authorization vulnerability exists that could cause unauthorized access when enabled on the network and potentially impacting connec…

Patch available
Fix from $2,300 2024-11-13
Zelio Soft 2 HIGH 7.8
CVE-2024-8422

CWE-416: Use After Free vulnerability exists that could cause arbitrary code execution, denial of service and loss of confidentiality & integrity whe…

Fix: 5.4.2.2+
Fix from $1,950 2024-10-08
Vijeo Designer HIGH 7.8
CVE-2024-8306

CWE-269: Improper Privilege Management vulnerability exists that could cause unauthorized access, loss of confidentiality, integrity and availability…

Fix: 6.3+
Fix from $1,950 2024-09-11
Whc 5918a Firmware HIGH 7.5
CVE-2024-6407

CWE-200: Information Exposure vulnerability exists that could cause disclosure of credentials when a specially crafted message is sent to the device.

No fix yet
Fix from $1,950 2024-07-11
Ecostruxure Foxboro Dcs Control Core Services HIGH 7.8
CVE-2024-5681

CWE-20: Improper Input Validation vulnerability exists that could cause local denial-of-service, privilege escalation, and potentially kernel executi…

Fix: after 9.8
Fix from $1,950 2024-07-11
Modicon M241 Firmware MEDIUM 6.1
CVE-2024-6528

CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability exists that could cause a vulnerability le…

Mitigation only
Fix from $1,600 2024-07-11
Foxrtu Station HIGH 7.8
CVE-2024-2602

CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability exists that could result in remote code executio…

Fix: 9.3.0+
Fix from $1,950 2024-07-11
Ecostruxure Foxboro Dcs Control Core Services HIGH 7.1
CVE-2024-5679

CWE-787: Out-of-Bounds Write vulnerability exists that could cause local denial-of-service, or kernel memory leak when a malicious actor with local u…

Fix: after 9.8
Fix from $1,950 2024-07-11
Ecostruxure Foxboro Dcs Control Core Services MEDIUM 5.5
CVE-2024-5680

CWE-129: Improper Validation of Array Index vulnerability exists that could cause local denial-of-service when a malicious actor with local user acce…

Fix: after 9.8
Fix from $1,600 2024-07-11
Powerlogic P5 Firmware MEDIUM 6.8
CVE-2024-5559

CWE-327: Use of a Broken or Risky Cryptographic Algorithm vulnerability exists that could cause denial of service, device reboot, or an attacker gain…

Fix: after 01.500.104
Fix from $1,600 2024-06-12