Vulnerability index

Browse CVEs

689 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Guicon HIGH 7.8
CVE-2018-7813

A Type Confusion (CWE-843) vulnerability exists in Eurotherm by Schneider Electric GUIcon V2.0 (Gold Build 683.0) on pcwin.dll which could cause remo…

Mitigation only
Fix from $1,950 2019-02-06
Guicon HIGH 7.8
CVE-2018-7814

A Stack-based Buffer Overflow (CWE-121) vulnerability exists in Eurotherm by Schneider Electric GUIcon V2.0 (Gold Build 683.0) which could cause remo…

Mitigation only
Fix from $1,950 2019-02-06
Guicon HIGH 7.8
CVE-2018-7815

A Type Confusion (CWE-843) vulnerability exists in Eurotherm by Schneider Electric GUIcon V2.0 (Gold Build 683.0) on c3core.dll which could cause rem…

Mitigation only
Fix from $1,950 2019-02-06
Zelio Soft 2 HIGH 7.8
CVE-2018-7817

A Use After Free (CWE-416) vulnerability exists in Zelio Soft 2 v5.1 and prior versions which could cause remote code execution when opening a specia…

Fix: after 5.1
Fix from $1,950 2019-02-06
Iiot Monitor MEDIUM 5.5
CVE-2018-7839

A Cryptographic Issue (CWE-310) vulnerability exists in IIoT Monitor 3.1.38 which could allow information disclosure.

No fix yet
Fix from $1,600 2019-02-06
Evlink Parking Firmware CRITICAL 9.8
CVE-2018-7800

A Hard-coded Credentials vulnerability exists in EVLink Parking, v3.2.0-12_v1 and earlier, which could enable an attacker to gain access to the devic…

Fix: after 3.2.0-12
Fix from $2,300 2018-12-24
Iiot Monitor CRITICAL 9.8
CVE-2018-7836EPSS 32%

An unrestricted Upload of File with Dangerous Type vulnerability exists on numerous methods of the IIoT Monitor 3.1.38 software that could allow uplo…

Mitigation only
Fix from $2,300 2018-12-24
Evlink Parking Firmware HIGH 8.8
CVE-2018-7801EPSS 6%

A Code Injection vulnerability exists in EVLink Parking, v3.2.0-12_v1 and earlier, which could enable access with maximum privileges when a remote co…

Fix: after 3.2.0-12
Fix from $1,950 2018-12-24
Evlink Parking Firmware HIGH 8.8
CVE-2018-7802

A SQL Injection vulnerability exists in EVLink Parking, v3.2.0-12_v1 and earlier, which could give access to the web interface with full privileges.

Fix: after 3.2.0-12
Fix from $1,950 2018-12-24
Pro Face Gp Pro Ex HIGH 8.8
CVE-2018-7832

An Improper Input Validation vulnerability exists in Pro-Face GP-Pro EX v4.08 and previous versions which could cause the execution arbitrary executa…

Fix: after 4.08
Fix from $1,950 2018-12-24
Foxboro Dcs HIGH 8.7
CVE-2018-7793

A Credential Management vulnerability exists in FoxView HMI SCADA (All Foxboro DCS, Foxboro Evo, and IA Series versions prior to Foxboro DCS Control …

Mitigation only
Fix from $1,950 2018-12-24
Iiot Monior HIGH 7.5
CVE-2018-7835

An Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability exists in IIoT Monitor 3.1.38 which could allow acces…

Mitigation only
Fix from $1,950 2018-12-24
Iiot Monior HIGH 7.5
CVE-2018-7837

An Improper Restriction of XML External Entity Reference ('XXE') vulnerability exists on numerous methods of the IIoT Monitor 3.1.38 software that co…

Mitigation only
Fix from $1,950 2018-12-24
Powersuite 2 MEDIUM 6.3
CVE-2018-7796

A Buffer Error vulnerability exists in PowerSuite 2, all released versions (VW3A8104 & Patches), which could cause an overflow in the memcpy function…

Mitigation only
Fix from $1,600 2018-12-24
Modicom M340 Firmware HIGH 7.5
CVE-2018-7812

An Information Exposure through Discrepancy vulnerability exists in the embedded web servers in all Modicon M340, Premium, Quantum PLCs and BMXNOR020…

Mitigation only
Fix from $1,950 2018-12-17
Modicom M340 Firmware HIGH 7.5
CVE-2018-7833

An Improper Check for Unusual or Exceptional Conditions vulnerability exists in the embedded web servers in all Modicon M340, Premium, Quantum PLCs a…

Mitigation only
Fix from $1,950 2018-12-17
Ecostruxure Energy Expert MEDIUM 6.1
CVE-2018-7797

A URL redirection vulnerability exists in Power Monitoring Expert, Energy Expert (formerly Power Manager) - EcoStruxure Power Monitoring Expert (PME)…

Mitigation only
Fix from $1,600 2018-12-17
Modicom M340 Firmware MEDIUM 6.1
CVE-2018-7804

A URL Redirection to Untrusted Site vulnerability exists in the embedded web servers in all Modicon M340, Premium, Quantum PLCs and BMXNOR0200 where …

Mitigation only
Fix from $1,600 2018-12-17
Modicom M340 Firmware CRITICAL 9.8
CVE-2018-7809

An Unverified Password Change vulnerability exists in the embedded web servers in all Modicon M340, Premium, Quantum PLCs and BMXNOR0200 which could …

No fix yet
Fix from $2,300 2018-11-30
Modicom M340 Firmware CRITICAL 9.8
CVE-2018-7811

An Unverified Password Change vulnerability exists in the embedded web servers in all Modicon M340, Premium, Quantum PLCs and BMXNOR0200 which could …

No fix yet
Fix from $2,300 2018-11-30
Struxureware Data Center Operation HIGH 8.8
CVE-2018-7806

Data Center Operation allows for the upload of a zip file from its user interface to the server. A carefully crafted, malicious file could be mistake…

Mitigation only
Fix from $1,950 2018-11-30
Struxureware Data Center Expert HIGH 8.8
CVE-2018-7807

Data Center Expert, versions 7.5.0 and earlier, allows for the upload of a zip file from its user interface to the server. A carefully crafted, malic…

Fix: after 7.5.0
Fix from $1,950 2018-11-30
Modicom M340 Firmware HIGH 8.8
CVE-2018-7831

An Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability exists in the embedded web servers in all Modicon M340…

No fix yet
Fix from $1,950 2018-11-30
Modicom M340 Firmware HIGH 7.5
CVE-2018-7830

Improper Neutralization of CRLF Sequences in HTTP Headers ('HTTP Response Splitting') vulnerability exists in the embedded web servers in all Modicon…

No fix yet
Fix from $1,950 2018-11-30
Modicom M340 Firmware MEDIUM 6.1
CVE-2018-7810

An Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability exists in the embedded web servers in all Modic…

No fix yet
Fix from $1,600 2018-11-30
Somachine Basic HIGH 8.2
CVE-2018-7798

A Insufficient Verification of Data Authenticity (CWE-345) vulnerability exists in the Modicon M221, all versions, which could cause a change of IPv4…

Mitigation only
Fix from $1,950 2018-11-02
Software Update Utility HIGH 7.8
CVE-2018-7799

A DLL hijacking vulnerability exists in Schneider Electric Software Update (SESU), all versions prior to V2.2.0, which could allow an attacker to exe…

Fix: 2.2.0+
Fix from $1,950 2018-11-02
Modicon M221 Firmware CRITICAL 9.8
CVE-2018-7790

An Information Management Error vulnerability exists in Schneider Electric's Modicon M221 product (all references, all versions prior to firmware V1.…

Fix: 1.6.2.0+
Fix from $2,300 2018-08-29
Modicon M221 Firmware CRITICAL 9.8
CVE-2018-7791

A Permissions, Privileges, and Access Control vulnerability exists in Schneider Electric's Modicon M221 product (all references, all versions prior t…

Fix: 1.6.2.0+
Fix from $2,300 2018-08-29
Modicon M221 Firmware HIGH 7.5
CVE-2018-7792

A Permissions, Privileges, and Access Control vulnerability exists in Schneider Electric's Modicon M221 product (all references, all versions prior t…

Fix: 1.6.2.0+
Fix from $1,950 2018-08-29