Vulnerability index

Browse CVEs

689 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

CRITICAL 9.8 CVE-2022-32523 A CWE-120: Buffer Copy without Checking Size of Input vulnerability exists that could cause a stack-based buffer overflow, potentially leading to rem… Interactive Graphical Scada System after 15.0.0.22170 Fix from $2,3002023-01-30 CRITICAL 9.8 CVE-2022-32524 A CWE-120: Buffer Copy without Checking Size of Input vulnerability exists that could cause a stack-based buffer overflow, potentially leading to rem… Interactive Graphical Scada System after 15.0.0.22170 Fix from $2,3002023-01-30 CRITICAL 9.8 CVE-2022-32525 A CWE-120: Buffer Copy without Checking Size of Input vulnerability exists that could cause a stack-based buffer overflow, potentially leading to rem… Interactive Graphical Scada System after 15.0.0.22170 Fix from $2,3002023-01-30 CRITICAL 9.8 CVE-2022-32526 A CWE-120: Buffer Copy without Checking Size of Input vulnerability exists that could cause a stack-based buffer overflow, potentially leading to rem… Interactive Graphical Scada System after 15.0.0.22170 Fix from $2,3002023-01-30 CRITICAL 9.8 CVE-2022-32527 A CWE-120: Buffer Copy without Checking Size of Input vulnerability exists that could cause a stack-based buffer overflow, potentially leading to rem… Interactive Graphical Scada System after 15.0.0.22170 Fix from $2,3002023-01-30 HIGH 8.8 CVE-2022-32521 A CWE 502: Deserialization of Untrusted Data vulnerability exists that could allow code to be remotely executed on the server when unsafely deseriali… Data Center Expert 7.9.0+ Fix from $1,9502023-01-30 MEDIUM 6.5 CVE-2022-32516 A CWE-352: Cross-Site Request Forgery (CSRF) vulnerability exists that could cause system’s configurations override and cause a reboot loop when the … Conext Combox Firmware Mitigation only Fix from $1,6002023-01-30 MEDIUM 6.5 CVE-2022-32517 A CWE-1021: Improper Restriction of Rendered UI Layers or Frames vulnerability exists that could cause an adversary to trick the interface user/admin… Conext Combox Firmware Mitigation only Fix from $1,6002023-01-30 CRITICAL 9.8 CVE-2022-0223 A CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability exists that could allow an attacker to create … Ecostruxure Power Commission 2.22+ Fix from $2,3002023-01-30 CRITICAL 9.8 CVE-2022-22731 A CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability exists in a function that could allow an attac… Ecostruxure Power Commission 2.22+ Fix from $2,3002023-01-30 CRITICAL 9.8 CVE-2022-32513 A CWE-521: Weak Password Requirements vulnerability exists that could allow an attacker to gain control of the device when the attacker brute forces … 5500ac2 Firmware 1.11.0+ Fix from $2,3002023-01-30 HIGH 7.8 CVE-2022-32512 A CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability exists that could cause remote code execution when a… Canbrass 7.5.1+ Fix from $1,9502023-01-30 HIGH 7.5 CVE-2022-22732 A CWE-668: Exposure of Resource to Wrong Sphere vulnerability exists that could cause all remote domains to access the resources (data) supplied by t… Ecostruxure Power Commission 2.22+ Fix from $1,9502023-01-30 CRITICAL 9.8 CVE-2022-45788 A CWE-754: Improper Check for Unusual or Exceptional Conditions vulnerability exists that could cause arbitrary code execution, denial of service and… Ecostruxure Control Expert 2021+ Fix from $2,3002023-01-30 HIGH 7.5 CVE-2022-2988 A CWE-787: Out-of-bounds Write vulnerability exists that could cause sensitive information leakage when accessing a malicious web page from the commi… Ecostruxure Machine Expert Hvac 1.4.0 / 2.1.0+ Fix from $1,9502023-01-30 HIGH 7.5 CVE-2022-0222 A CWE-269: Improper Privilege Management vulnerability exists that could cause a denial of service of the Ethernet communication of the controller wh… Modicon M340 Bmxp341000 Firmware 3.50+ Fix from $1,9502022-11-22 HIGH 7.5 CVE-2022-37301 A CWE-191: Integer Underflow (Wrap or Wraparound) vulnerability exists that could cause a denial of service of the controller due to memory access vi… Modicon M340 Bmx P34 2010 Firmware 3.50 / 4.01+ Fix from $1,9502022-11-22 HIGH 7.8 CVE-2022-41671 A CWE-89: Improper Neutralization of Special Elements used in SQL Command (‘SQL Injection’) vulnerability exists that allows adversaries with local u… Ecostruxure Operator Terminal Expert 3.3+ Fix from $1,9502022-11-04 HIGH 7.8 CVE-2022-41670 A CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability exists in the SGIUtility component that allows… Ecostruxure Operator Terminal Expert 3.3+ Fix from $1,9502022-11-04 HIGH 7.8 CVE-2022-41669 A CWE-347: Improper Verification of Cryptographic Signature vulnerability exists in the SGIUtility component that allows adversaries with local user … Ecostruxure Operator Terminal Expert 3.3+ Fix from $1,9502022-11-04 HIGH 7.8 CVE-2022-41668 A CWE-704: Incorrect Project Conversion vulnerability exists that allows adversaries with local user privileges to load a project file from an advers… Ecostruxure Operator Terminal Expert 3.3+ Fix from $1,9502022-11-04 HIGH 7.8 CVE-2022-41667 A CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability exists that allows adversaries with local user… Ecostruxure Operator Terminal Expert 3.3+ Fix from $1,9502022-11-04 HIGH 7.8 CVE-2022-41666 A CWE-347: Improper Verification of Cryptographic Signature vulnerability exists that allows adversaries with local user privileges to load a malicio… Ecostruxure Operator Terminal Expert 3.3+ Fix from $1,9502022-11-04 MEDIUM 5.5 CVE-2022-37302 A CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability exists that could cause a crash of the Control Exper… Ecostruxure Control Expert 15.1+ Fix from $1,6002022-09-13 CRITICAL 9.8 CVE-2022-37300 A CWE-640: Weak Password Recovery Mechanism for Forgotten Password vulnerability exists that could cause unauthorized access in read and write mode t… Ecostruxure Control Expert 3.50 / 15.1+ Fix from $2,3002022-09-12 CRITICAL 9.8 CVE-2022-34756 A CWE-120: Buffer Copy without Checking Size of Input vulnerability exists that could result in remote code execution or the crash of HTTPs stack whi… Easergy P5 Firmware after 01.401.102 Fix from $2,3002022-07-13 HIGH 8.8 CVE-2022-34753EPSS 71% A CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability exists that could cause remote roo… Spacelogic C Bus Home Controller Firmware after 1.31.460 Fix from $1,9502022-07-13 HIGH 7.5 CVE-2022-34759 A CWE-787: Out-of-bounds Write vulnerability exists that could cause a denial of service of the webserver due to improper parsing of the HTTP Headers… Opc Ua Module For M580 Firmware after 1.10 Fix from $1,9502022-07-13 HIGH 7.5 CVE-2022-34760 A CWE-835: Loop with Unreachable Exit Condition ('Infinite Loop') vulnerability exists that could cause a denial of service of the webserver due to i… Opc Ua Module For M580 Firmware after 1.10 Fix from $1,9502022-07-13 HIGH 7.5 CVE-2022-34761 A CWE-476: NULL Pointer Dereference vulnerability exists that could cause a denial of service of the webserver when parsing JSON content type. Affect… Opc Ua Module For M580 Firmware after 1.10 Fix from $1,9502022-07-13