Vulnerability index

Browse CVEs

689 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

HIGH 7.5 CVE-2026-9716 CWE-476 NULL Pointer Dereference vulnerability exists that could cause a denial-of-service condition, rendering the device’s HMI and configuration fu… Powerlogic P7 Firmware 02.004.001.000+ Fix from $1,9502026-06-25 HIGH 7.2 CVE-2026-9717 CWE-78 Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability exists that could allow unauthorized execution… Powerlogic P7 Firmware 02.004.001.000+ Fix from $1,9502026-06-25 MEDIUM 6.5 CVE-2026-9718 CWE-617 Reachable Assertion vulnerability exists that could allow an authenticated attacker to trigger a denial-of-service condition, impacting syste… Powerlogic P7 Firmware 02.004.001.000+ Fix from $1,6002026-06-25 HIGH 7.5 CVE-2026-9650 CWE-522 Insufficiently Protected Credentials vulnerability that could cause unauthorized access and exposure of sensitive information when unauthenti… Easylogic T150 Firmware 11.06.32 / 11.06.38+ Fix from $1,9502026-06-25 MEDIUM 6.5 CVE-2026-8045 CWE-611 Improper Restriction of XML External Entity Reference vulnerability exists that could cause information disclosure of server-side file conten… Struxureware Data Center Expert 9.1.2+ Fix from $1,6002026-06-09 HIGH 7.5 CVE-2026-6332 CWE-312: Cleartext Storage of Sensitive Information vulnerability exists that could cause the disclosure of a sensitive information which could resu… Ecostruxure Machine Expert Hvac 1.10.0+ Fix from $1,9502026-05-14 HIGH 7.5 CVE-2026-6866 CWE-1188 Initialization of a Resource with an Insecure Default vulnerability exists that could cause unauthorized disclosure of sensitive information… Ecostruxure Panel Server Pas400 Firmware 002.006.000+ Fix from $1,9502026-05-12 MEDIUM 6.5 CVE-2026-2405 CWE-400 Uncontrolled Resource Consumption vulnerability exists that could cause excessive troubleshooting zip file creation and denial of service whe… Powerchute Serial Shutdown 1.5+ Fix from $1,6002026-04-14 MEDIUM 5.3 CVE-2026-2404 CWE-116 Improper Encoding or Escaping of Output vulnerability exists that could cause log injection and forged log when an attacker alters the POST /… Powerchute Serial Shutdown 1.5+ Fix from $1,6002026-04-14 MEDIUM 6.1 CVE-2026-2399 CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability exists that could cause critical files overwritte… Powerchute Serial Shutdown 1.5+ Fix from $1,6002026-04-14 MEDIUM 5.3 CVE-2026-2402 CWE-307 Improper Restriction of Excessive Authentication Attempts vulnerability exists that would allow an attacker to gain access to the user accoun… Powerchute Serial Shutdown 1.5+ Fix from $1,6002026-04-14 MEDIUM 5.0 CVE-2026-2401 CWE-532 Insertion of Sensitive Information into Log File vulnerability exists that could cause confidential information to be exposed when a Web Adm… Powerchute Serial Shutdown 1.5+ Fix from $1,6002026-04-14 HIGH 8.2 CVE-2026-2273 CWE-94: Improper Control of Generation of Code ('Code Injection') vulnerability exist that could cause execution of untrusted commands on the enginee… Ecostruxure Automation Expert 25.0.1+ Fix from $1,9502026-03-10 MEDIUM 6.5 CVE-2026-1286 CWE-502: Deserialization of untrusted data vulnerability exists that could lead to loss of confidentiality, integrity and potential remote code execu… Ecostruxure Foxboro Dcs Control Software 8.1+ Fix from $1,6002026-03-10 MEDIUM 5.4 CVE-2025-13902 CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability exists that could cause condition where aut… Modicon M258 Firmware 5.4.13.12+ Fix from $1,6002026-03-10 MEDIUM 5.3 CVE-2025-13901 CWE-404 Improper Resource Shutdown or Release vulnerability exists that could cause partial Denial of Service on Machine Expert protocol when an unau… Modicon M241 Firmware 5.4.10.12 / 5.4.13.12+ Fix from $1,6002026-03-10 HIGH 7.8 CVE-2025-11739 CWE‑502: Deserialization of Untrusted Data vulnerability exists that could cause arbitrary code execution with administrative privileges when a local… Ecostruxure Power Monitoring Expert Mitigation only Fix from $1,9502026-03-10 HIGH 7.8 CVE-2025-13845 CWE-416: Use After Free vulnerability that could cause remote code execution when the end user imports the malicious project file (SSD file) into Rap… Ecostruxure Power Build Rapsody after 2.8.8.0100 Fix from $1,9502026-01-15 MEDIUM 5.3 CVE-2025-13844 CWE-415: Double Free vulnerability exists that could cause heap memory corruption when the end user imports a malicious project file (SSD file) share… Ecostruxure Power Build Rapsody after 2.8.8 Fix from $1,6002026-01-15 HIGH 7.5 CVE-2024-9409 CWE-400: An Uncontrolled Resource Consumption vulnerability exists that could cause the device to become unresponsive resulting in communication loss… Powerlogic Pm5341 Firmware 2.4.0 / 2.7.0+ Fix from $1,9502024-11-13 CRITICAL 9.8 CVE-2024-10575 CWE-862: Missing Authorization vulnerability exists that could cause unauthorized access when enabled on the network and potentially impacting connec… Ecostruxure It Gateway Patch available Fix from $2,3002024-11-13 HIGH 7.8 CVE-2024-8422 CWE-416: Use After Free vulnerability exists that could cause arbitrary code execution, denial of service and loss of confidentiality & integrity whe… Zelio Soft 2 5.4.2.2+ Fix from $1,9502024-10-08 HIGH 7.8 CVE-2024-8306 CWE-269: Improper Privilege Management vulnerability exists that could cause unauthorized access, loss of confidentiality, integrity and availability… Vijeo Designer 6.3+ Fix from $1,9502024-09-11 HIGH 7.5 CVE-2024-6407 CWE-200: Information Exposure vulnerability exists that could cause disclosure of credentials when a specially crafted message is sent to the device. Whc 5918a Firmware No fix yet Fix from $1,9502024-07-11 HIGH 7.8 CVE-2024-5681 CWE-20: Improper Input Validation vulnerability exists that could cause local denial-of-service, privilege escalation, and potentially kernel executi… Ecostruxure Foxboro Dcs Control Core Services after 9.8 Fix from $1,9502024-07-11 MEDIUM 6.1 CVE-2024-6528 CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability exists that could cause a vulnerability le… Modicon M241 Firmware Mitigation only Fix from $1,6002024-07-11 HIGH 7.8 CVE-2024-2602 CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability exists that could result in remote code executio… Foxrtu Station 9.3.0+ Fix from $1,9502024-07-11 HIGH 7.1 CVE-2024-5679 CWE-787: Out-of-Bounds Write vulnerability exists that could cause local denial-of-service, or kernel memory leak when a malicious actor with local u… Ecostruxure Foxboro Dcs Control Core Services after 9.8 Fix from $1,9502024-07-11 MEDIUM 5.5 CVE-2024-5680 CWE-129: Improper Validation of Array Index vulnerability exists that could cause local denial-of-service when a malicious actor with local user acce… Ecostruxure Foxboro Dcs Control Core Services after 9.8 Fix from $1,6002024-07-11 MEDIUM 6.8 CVE-2024-5559 CWE-327: Use of a Broken or Risky Cryptographic Algorithm vulnerability exists that could cause denial of service, device reboot, or an attacker gain… Powerlogic P5 Firmware after 01.500.104 Fix from $1,6002024-06-12