Vulnerability index

Browse CVEs

689 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

HIGH 7.8 CVE-2024-2747 CWE-428: Unquoted search path or element vulnerability exists in Easergy Studio, which could cause privilege escalation when a valid user replaces a … Easergy Studio after 9.3.3 Fix from $1,9502024-06-12 HIGH 7.8 CVE-2024-0865 CWE-798: Use of hard-coded credentials vulnerability exists that could cause local privilege escalation when logged in as a non-administrative user. Ecostruxure It Gateway 1.21.0+ Fix from $1,9502024-06-12 HIGH 7.5 CVE-2024-5560 CWE-125: Out-of-bounds Read vulnerability exists that could cause denial of service of the device’s web interface when an attacker sends a specially … Sage Rtu Firmware Patch available Fix from $1,9502024-06-12 MEDIUM 6.4 CVE-2024-5558 CWE-367: Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability exists that could cause escalation of privileges when an attacker abuses a l… Spacelogic As B Firmware 6.0.1+ Fix from $1,6002024-06-12 HIGH 8.8 CVE-2024-37038 CWE-276: Incorrect Default Permissions vulnerability exists that could allow an authenticated user with access to the device’s web interface to perfo… Sage Rtu Firmware Patch available Fix from $1,9502024-06-12 HIGH 8.1 CVE-2024-37040 CWE-120: Buffer Copy without Checking Size of Input (‘Classic Buffer Overflow’) vulnerability exists that could allow a user with access to the devic… Sage Rtu Firmware Patch available Fix from $1,9502024-06-12 HIGH 7.5 CVE-2024-37039 CWE-252: Unchecked Return Value vulnerability exists that could cause denial of service of the device when an attacker sends a specially crafted HTTP… Sage Rtu Firmware Patch available Fix from $1,9502024-06-12 CRITICAL 9.8 CVE-2024-37036 CWE-787: Out-of-bounds Write vulnerability exists that could result in an authentication bypass when sending a malformed POST request and particular … Sage Rtu Firmware No fix yet Fix from $2,3002024-06-12 HIGH 8.1 CVE-2024-37037 CWE-22: Improper Limitation of a Pathname to a Restricted Directory (‘Path Traversal’) vulnerability exists that could allow an authenticated user wi… Sage Rtu Firmware Patch available Fix from $1,9502024-06-12 MEDIUM 6.5 CVE-2024-5313 CWE-668: Exposure of the Resource Wrong Sphere vulnerability exists that exposes a SSH interface over the product network interface. This does not al… Evlink Home Firmware Mitigation only Fix from $1,6002024-06-12 MEDIUM 6.5 CVE-2024-5056 CWE-552: Files or Directories Accessible to External Parties vulnerability exists which may prevent user to update the device firmware and prevent pr… Modicon M340 Firmware Mitigation only Fix from $1,6002024-06-12 HIGH 8.1 CVE-2023-6408 CWE-924: Improper Enforcement of Message Integrity During Transmission in a Communication Channel vulnerability exists that could cause a denial of s… Modicon M340 Bmxp341000 Firmware 3.60+ Fix from $1,9502024-02-14 HIGH 7.7 CVE-2023-6409 CWE-798: Use of Hard-coded Credentials vulnerability exists that could cause unauthorized access to a project file protected with application passwor… Ecostruxure Control Expert 16.0 / 2023+ Fix from $1,9502024-02-14 HIGH 7.1 CVE-2023-27975 CWE-522: Insufficiently Protected Credentials vulnerability exists that could cause unauthorized access to the project file in EcoStruxure Control Ex… Ecostruxure Control Expert 16.0 / 2023+ Fix from $1,9502024-02-14 HIGH 7.8 CVE-2023-7032 A CWE-502: Deserialization of untrusted data vulnerability exists that could allow an attacker logged in with a user level account to gain higher pri… Easergy Studio after 9.3.5 Fix from $1,9502024-01-09 HIGH 7.1 CVE-2023-6407 A CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability exists that could cause arbitrary file deletio… Easy Ups Online Monitoring Software 2.6-ga-01-23248+ Fix from $1,9502023-12-14 MEDIUM 6.1 CVE-2023-5629 A CWE-601:URL Redirection to Untrusted Site (‘Open Redirect’) vulnerability exists that could cause disclosure of information through phishing attemp… Eb450 Firmware No fix yet Fix from $1,6002023-12-14 MEDIUM 6.1 CVE-2023-5986 A CWE-601 URL Redirection to Untrusted Site vulnerability exists that could cause an openredirect vulnerability leading to a cross site scripting att… Ecostruxure Power Monitoring Expert Mitigation only Fix from $1,6002023-11-15 MEDIUM 6.1 CVE-2023-5987 A CWE-79 Improper Neutralization of Input During Web Page Generation (Cross-site Scripting) vulnerability that could cause a vulnerability leading to… Ecostruxure Power Monitoring Expert Patch available Fix from $1,6002023-11-15 MEDIUM 5.3 CVE-2023-6032 A CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability exists that could cause a file system enumerat… Galaxy Vl Firmware Mitigation only Fix from $1,6002023-11-15 CRITICAL 9.8 CVE-2023-5391 A CWE-502: Deserialization of untrusted data vulnerability exists that could allow an attacker to execute arbitrary code on the targeted system by se… Ecostruxure Power Monitoring Expert No fix yet Fix from $2,3002023-10-04 CRITICAL 9.8 CVE-2023-5399EPSS 39% A CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability exists that could cause tampering of files on … Spacelogic C Bus Toolkit 1.16.4+ Fix from $2,3002023-10-04 CRITICAL 9.8 CVE-2023-5402 A CWE-269: Improper Privilege Management vulnerability exists that could cause a remote code execution when the transfer command is used over the net… C Bus Toolkit after 1.16.3 Fix from $2,3002023-10-04 HIGH 7.8 CVE-2023-4516 A CWE-306: Missing Authentication for Critical Function vulnerability exists in the IGSS Update Service that could allow a local attacker to change u… Interactive Graphical Scada System after 16.0.0.23211 Fix from $1,9502023-09-14 MEDIUM 5.3 CVE-2023-3953 A CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability exists that could cause memory corruption when an au… Pro Face Gp Pro Ex 4.09.500+ Fix from $1,6002023-08-09 HIGH 7.8 CVE-2023-29414 A CWE-120: Buffer Copy without Checking Size of Input (Classic Buffer Overflow) vulnerability exists that could cause user privilege escalation if a … Accutech Manager after 2.7 Fix from $1,9502023-07-12 HIGH 7.2 CVE-2023-37199 A CWE-94: Improper Control of Generation of Code ('Code Injection') vulnerability exists that could cause remote code execution when an admin user on… Struxureware Data Center Expert after 7.9.3 Fix from $1,9502023-07-12 HIGH 8.8 CVE-2023-37196 A CWE-89: Improper Neutralization of Special Elements vulnerability used in an SQL Command ('SQL Injection') vulnerability exists that could allow a … Struxureware Data Center Expert after 7.9.3 Fix from $1,9502023-07-12 HIGH 8.8 CVE-2023-37197 A CWE-89: Improper Neutralization of Special Elements vulnerability used in an SQL Command ('SQL Injection') vulnerability exists that could allow a … Struxureware Data Center Expert after 7.9.3 Fix from $1,9502023-07-12 HIGH 7.2 CVE-2023-37198 A CWE-94: Improper Control of Generation of Code ('Code Injection') vulnerability exists that could cause remote code execution when an admin user on… Struxureware Data Center Expert after 7.9.3 Fix from $1,9502023-07-12