Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6649
Adobe 6383
Ibm 6266
Cisco 5746
Debian 3919
Apache 2864
Mozilla 2857
Redhat 2581
HIGH 7.8
CVE-2024-2747
CWE-428: Unquoted search path or element vulnerability exists in Easergy Studio, which could
cause privilege escalation when a valid user replaces a …
Easergy Studio
after 9.3.3
HIGH 7.8
CVE-2024-0865
CWE-798: Use of hard-coded credentials vulnerability exists that could cause local privilege
escalation when logged in as a non-administrative user.
Ecostruxure It Gateway
1.21.0+
HIGH 7.5
CVE-2024-5560
CWE-125: Out-of-bounds Read vulnerability exists that could cause denial of service of the
device’s web interface when an attacker sends a specially …
Sage Rtu Firmware
Patch available
MEDIUM 6.4
CVE-2024-5558
CWE-367: Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability exists that could
cause escalation of privileges when an attacker abuses a l…
Spacelogic As B Firmware
6.0.1+
HIGH 8.8
CVE-2024-37038
CWE-276: Incorrect Default Permissions vulnerability exists that could allow an authenticated
user with access to the device’s web interface to perfo…
Sage Rtu Firmware
Patch available
HIGH 8.1
CVE-2024-37040
CWE-120: Buffer Copy without Checking Size of Input (‘Classic Buffer Overflow’) vulnerability
exists that could allow a user with access to the devic…
Sage Rtu Firmware
Patch available
HIGH 7.5
CVE-2024-37039
CWE-252: Unchecked Return Value vulnerability exists that could cause denial of service of the
device when an attacker sends a specially crafted HTTP…
Sage Rtu Firmware
Patch available
CRITICAL 9.8
CVE-2024-37036
CWE-787: Out-of-bounds Write vulnerability exists that could result in an authentication bypass
when sending a malformed POST request and particular …
Sage Rtu Firmware
No fix yet
HIGH 8.1
CVE-2024-37037
CWE-22: Improper Limitation of a Pathname to a Restricted Directory (‘Path
Traversal’) vulnerability exists that could allow an authenticated user wi…
Sage Rtu Firmware
Patch available
MEDIUM 6.5
CVE-2024-5313
CWE-668: Exposure of the Resource Wrong Sphere vulnerability exists that exposes a SSH
interface over the product network interface. This does not al…
Evlink Home Firmware
Mitigation only
MEDIUM 6.5
CVE-2024-5056
CWE-552: Files or Directories Accessible to External Parties vulnerability exists which may
prevent user to update the device firmware and prevent pr…
Modicon M340 Firmware
Mitigation only
HIGH 8.1
CVE-2023-6408
CWE-924: Improper Enforcement of Message Integrity During Transmission in a
Communication Channel vulnerability exists that could cause a denial of s…
Modicon M340 Bmxp341000 Firmware
3.60+
HIGH 7.7
CVE-2023-6409
CWE-798: Use of Hard-coded Credentials vulnerability exists that could cause unauthorized
access to a project file protected with application passwor…
Ecostruxure Control Expert
16.0 / 2023+
HIGH 7.1
CVE-2023-27975
CWE-522: Insufficiently Protected Credentials vulnerability exists that could cause unauthorized
access to the project file in EcoStruxure Control Ex…
Ecostruxure Control Expert
16.0 / 2023+
HIGH 7.8
CVE-2023-7032
A CWE-502: Deserialization of untrusted data vulnerability exists that could allow an attacker
logged in with a user level account to gain higher pri…
Easergy Studio
after 9.3.5
HIGH 7.1
CVE-2023-6407
A CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
vulnerability exists that could cause arbitrary file deletio…
Easy Ups Online Monitoring Software
2.6-ga-01-23248+
MEDIUM 6.1
CVE-2023-5629
A CWE-601:URL Redirection to Untrusted Site (‘Open Redirect’) vulnerability exists that could
cause disclosure of information through phishing attemp…
Eb450 Firmware
No fix yet
MEDIUM 6.1
CVE-2023-5986
A CWE-601 URL Redirection to Untrusted Site vulnerability exists that could cause an openredirect vulnerability leading to a cross site scripting att…
Ecostruxure Power Monitoring Expert
Mitigation only
MEDIUM 6.1
CVE-2023-5987
A CWE-79 Improper Neutralization of Input During Web Page Generation (Cross-site Scripting)
vulnerability that could cause a vulnerability leading to…
Ecostruxure Power Monitoring Expert
Patch available
MEDIUM 5.3
CVE-2023-6032
A CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
vulnerability exists that could cause a file system enumerat…
Galaxy Vl Firmware
Mitigation only
CRITICAL 9.8
CVE-2023-5391
A CWE-502: Deserialization of untrusted data vulnerability exists that could allow an attacker to
execute arbitrary code on the targeted system by se…
Ecostruxure Power Monitoring Expert
No fix yet
CRITICAL 9.8
CVE-2023-5399EPSS 39%
A CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path
Traversal') vulnerability exists that could cause tampering of files on …
Spacelogic C Bus Toolkit
1.16.4+
CRITICAL 9.8
CVE-2023-5402
A CWE-269: Improper Privilege Management vulnerability exists that could cause a remote
code execution when the transfer command is used over the net…
C Bus Toolkit
after 1.16.3
HIGH 7.8
CVE-2023-4516
A CWE-306: Missing Authentication for Critical Function vulnerability exists in the IGSS Update
Service that could allow a local attacker to change u…
Interactive Graphical Scada System
after 16.0.0.23211
MEDIUM 5.3
CVE-2023-3953
A CWE-119: Improper Restriction of Operations within the Bounds of a Memory
Buffer vulnerability exists that could cause memory corruption when an au…
Pro Face Gp Pro Ex
4.09.500+
HIGH 7.8
CVE-2023-29414
A CWE-120: Buffer Copy without Checking Size of Input (Classic Buffer Overflow) vulnerability
exists that could cause user privilege escalation if a …
Accutech Manager
after 2.7
HIGH 7.2
CVE-2023-37199
A CWE-94: Improper Control of Generation of Code ('Code Injection') vulnerability exists that
could cause remote code execution when an admin user on…
Struxureware Data Center Expert
after 7.9.3
HIGH 8.8
CVE-2023-37196
A CWE-89: Improper Neutralization of Special Elements vulnerability used in an SQL Command
('SQL Injection') vulnerability exists that could allow a …
Struxureware Data Center Expert
after 7.9.3
HIGH 8.8
CVE-2023-37197
A CWE-89: Improper Neutralization of Special Elements vulnerability used in an SQL Command
('SQL Injection') vulnerability exists that could allow a …
Struxureware Data Center Expert
after 7.9.3
HIGH 7.2
CVE-2023-37198
A CWE-94: Improper Control of Generation of Code ('Code Injection') vulnerability exists that
could cause remote code execution when an admin user on…
Struxureware Data Center Expert
after 7.9.3