Vulnerability index

Browse CVEs

689 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Network Management Card 2 Firmware MEDIUM 6.1
CVE-2021-22810

A CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability exists that could cause arbritrary scrip…

Fix: after 6.9.8
Fix from $1,600 2022-01-28
Guicon MEDIUM 5.5
CVE-2021-22809

A CWE-125:Out-of-Bounds Read vulnerability exists that could cause unintended data disclosure when a malicious *.gd1 configuration file is loaded int…

Fix: after 2.0
Fix from $1,600 2022-01-28
Vijeo Designer CRITICAL 9.1
CVE-2021-22704

A CWE-22: Improper Limitation of a Pathname to a Restricted Directory vulnerability exists in Harmony/HMI Products Configured by Vijeo Designer (all …

Fix: 1.2 / 2.0+
Fix from $2,300 2021-09-02
Gp Pro Ex HIGH 7.8
CVE-2021-22775

A CWE-427: Uncontrolled Search Path Element vulnerability exists in GP-Pro EX,V4.09.250 and prior, that could cause local code execution with elevate…

Fix: after 4.09.250
Fix from $1,950 2021-09-02
Modicon M340 Bmxp341000 HIGH 7.5
CVE-2021-22792

A CWE-476: NULL Pointer Dereference vulnerability that could cause a Denial of Service on the Modicon PLC controller / simulator when updating the co…

Patch available
Fix from $1,950 2021-09-02
Accusine Pcsp Pfvp Firmware HIGH 7.2
CVE-2021-22793

A CWE-200: Exposure of Sensitive Information to an Unauthorized Actor vulnerability exist in AccuSine PCS+ / PFV+ (Versions prior to V1.6.7) and Accu…

Fix: 001.006.007 / 002.002.004+
Fix from $1,950 2021-09-02
Modicon M340 Bmxp341000 MEDIUM 6.5
CVE-2021-22789

A CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability that could cause a Denial of Service on the Modicon …

Patch available
Fix from $1,600 2021-09-02
Modicon M340 Bmxp341000 MEDIUM 6.5
CVE-2021-22790

A CWE-125: Out-of-bounds Read vulnerability that could cause a Denial of Service on the Modicon PLC controller / simulator when updating the controll…

Patch available
Fix from $1,600 2021-09-02
Modicon M340 Bmxp341000 MEDIUM 6.5
CVE-2021-22791

A CWE-787: Out-of-bounds Write vulnerability that could cause a Denial of Service on the Modicon PLC controller / simulator when updating the control…

Patch available
Fix from $1,600 2021-09-02
T200i Firmware CRITICAL 9.8
CVE-2021-22772

A CWE-306: Missing Authentication for Critical Function vulnerability exists in Easergy T200 ((Modbus) SC2-04MOD-07000100 and earlier), Easergy T200 …

Mitigation only
Fix from $2,300 2021-07-21
Sosafe Configurable HIGH 7.8
CVE-2021-22777

A CWE-502: Deserialization of Untrusted Data vulnerability exists that could cause code execution by opening a malicious project file.

Fix: 1.8.1+
Fix from $1,950 2021-07-21
Evlink City Evc1s22p4 Firmware HIGH 7.5
CVE-2021-22774

A CWE-759: Use of a One-Way Hash without a Salt vulnerability exists in EVlink City (EVC1S22P4 / EVC1S7P4 all versions prior to R8 V3.4.0.1), EVlink …

Mitigation only
Fix from $1,950 2021-07-21
Easergy T300 Firmware HIGH 7.3
CVE-2021-22771

A CWE-1236: Improper Neutralization of Formula Elements in a CSV File vulnerability exists in Easergy T300 with firmware V2.7.1 and older that would …

Fix: after 2.7.1
Fix from $1,950 2021-07-21
Evlink City Evc1s22p4 Firmware MEDIUM 6.5
CVE-2021-22773

A CWE-620: Unverified Password Change vulnerability exists in EVlink City (EVC1S22P4 / EVC1S7P4 all versions prior to R8 V3.4.0.1), EVlink Parking (E…

Mitigation only
Fix from $1,600 2021-07-21
C Bus Toolkit MEDIUM 5.7
CVE-2021-22784EPSS 12%

A CWE-306: Missing Authentication for Critical Function vulnerability exists in C-Bus Toolkit v1.15.8 and prior that could allow an attacker to use a…

Fix: 1.15.9+
Fix from $1,600 2021-07-21
Evlink City Evc1s22p4 Firmware CRITICAL 9.8
CVE-2021-22707EPSS 65%

A CWE-798: Use of Hard-coded Credentials vulnerability exists in EVlink City (EVC1S22P4 / EVC1S7P4 all versions prior to R8 V3.4.0.1), EVlink Parking…

Mitigation only
Fix from $2,300 2021-07-21
Evlink City Evc1s22p4 Firmware CRITICAL 9.8
CVE-2021-22727

A CWE-331: Insufficient Entropy vulnerability exists in EVlink City (EVC1S22P4 / EVC1S7P4 all versions prior to R8 V3.4.0.1), EVlink Parking (EVW2 / …

Mitigation only
Fix from $2,300 2021-07-21
Evlink City Evc1s22p4 Firmware CRITICAL 9.8
CVE-2021-22729

A CWE-259: Use of Hard-coded Password vulnerability exists in EVlink City (EVC1S22P4 / EVC1S7P4 all versions prior to R8 V3.4.0.1), EVlink Parking (E…

Mitigation only
Fix from $2,300 2021-07-21
Evlink City Evc1s22p4 Firmware CRITICAL 9.8
CVE-2021-22730

A CWE-798: Use of Hard-coded Credentials vulnerability exists in EVlink City (EVC1S22P4 / EVC1S7P4 all versions prior to R8 V3.4.0.1), EVlink Parking…

Mitigation only
Fix from $2,300 2021-07-21
Evlink City Evc1s22p4 Firmware HIGH 8.1
CVE-2021-22726

A CWE-918: Server-Side Request Forgery (SSRF) vulnerability exists in EVlink City (EVC1S22P4 / EVC1S7P4 all versions prior to R8 V3.4.0.1), EVlink Pa…

Mitigation only
Fix from $1,950 2021-07-21
Evlink City Evc1s22p4 Firmware HIGH 7.2
CVE-2021-22708

A CWE-347: Improper Verification of Cryptographic Signature vulnerability exists in EVlink City (EVC1S22P4 / EVC1S7P4 all versions prior to R8 V3.4.0…

Mitigation only
Fix from $1,950 2021-07-21
Evlink City Evc1s22p4 Firmware MEDIUM 6.5
CVE-2021-22728

A CWE-200: Information Exposure vulnerability exists in EVlink City (EVC1S22P4 / EVC1S7P4 all versions prior to R8 V3.4.0.1), EVlink Parking (EVW2 / …

Mitigation only
Fix from $1,600 2021-07-21
Easergy T300 Firmware MEDIUM 6.5
CVE-2021-22770

A CWE-200: Information Exposure vulnerability exists in Easergy T300 with firmware V2.7.1 and older that exposes sensitive information to an actor no…

Fix: after 2.7.1
Fix from $1,600 2021-07-21
Evlink City Evc1s22p4 Firmware MEDIUM 6.1
CVE-2021-22706

A CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability exists in EVlink City (EVC1S22P4 / EVC1S…

Mitigation only
Fix from $1,600 2021-07-21
Evlink City Evc1s22p4 Firmware MEDIUM 6.1
CVE-2021-22723

A CWE-79: Improper Neutralization of Input During Web Page Generation (Cross-siteScripting) through Cross-Site Request Forgery (CSRF) vulnerability e…

Mitigation only
Fix from $1,600 2021-07-21
Evlink City Evc1s22p4 Firmware MEDIUM 5.4
CVE-2021-22722

A CWE-79: Improper Neutralization of Input During Web Page Generation ('Stored Cross-site Scripting') vulnerability exists in EVlink City (EVC1S22P4 …

Mitigation only
Fix from $1,600 2021-07-21
Evlink City Evc1s22p4 Firmware MEDIUM 5.3
CVE-2021-22721

A CWE-200: Information Exposure vulnerability exists in EVlink City (EVC1S22P4 / EVC1S7P4 all versions prior to R8 V3.4.0.1), EVlink Parking (EVW2 / …

Mitigation only
Fix from $1,600 2021-07-21
Ecostruxure Control Expert CRITICAL 9.1
CVE-2021-22779

Authentication Bypass by Spoofing vulnerability exists in EcoStruxure Control Expert (all versions prior to V15.0 SP1, including all versions of Unit…

Fix: 15.0+
Fix from $2,300 2021-07-14
Ecostruxure Control Expert HIGH 7.1
CVE-2021-22778

Insufficiently Protected Credentials vulnerability exists in EcoStruxure Control Expert (all versions prior to V15.0 SP1, including all versions of U…

Fix: 15.0+
Fix from $1,950 2021-07-14
Ecostruxure Control Expert HIGH 7.1
CVE-2021-22780

Insufficiently Protected Credentials vulnerability exists in EcoStruxure Control Expert (all versions prior to V15.0 SP1, including all versions of U…

Fix: 15.0+
Fix from $1,950 2021-07-14