Top technology
Linux 13140
Google 12530
Microsoft 12379
Oracle 6737
Apple 6692
Adobe 6387
Ibm 6330
Cisco 5757
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
CRITICAL 9.8
CVE-2026-28252
A Use of a Broken or Risky Cryptographic Algorithm vulnerability in Trane Tracer SC, Tracer SC+, and Tracer Concierge could allow an attacker to bypa…
Tracer Sc Firmware
6.3.2310+
CRITICAL 9.8
CVE-2026-28255
A Use of Hard-coded Credentials vulnerability in Trane Tracer SC, Tracer SC+, and Tracer Concierge could allow an attacker to disclose sensitive info…
Tracer Sc Firmware
6.3.2310+
CRITICAL 9.8
CVE-2026-28256
A Use of Hard-coded, Security-relevant Constants vulnerability in Trane Tracer SC, Tracer SC+, and Tracer Concierge could allow an attacker to disclo…
Tracer Sc\+ Firmware
6.3.2310+
HIGH 7.5
CVE-2026-28253
A Memory Allocation with Excessive Size Value vulnerability in Trane Tracer SC, Tracer SC+, and Tracer Concierge could allow an unauthenticated attac…
Tracer Sc Firmware
6.3.2310+
HIGH 7.5
CVE-2026-28254
A Missing Authorization vulnerability in Trane Tracer SC, Tracer SC+, and Tracer Concierge could allow an unauthenticated attacker to access sensitiv…
Tracer Sc Firmware
6.3.2310+
MEDIUM 6.8
CVE-2023-4212
A command injection vulnerability exists in Trane XL824, XL850, XL1050, and Pivot thermostats allowing an attacker to execute arbitrary commands as …
Xl824 Firmware
after 5.9.8
HIGH 7.6
CVE-2021-38448
The affected controllers do not properly sanitize the input containing code syntax. As a result, an attacker could craft code to alter the intended c…
Symbio 700
1.00.0023 / 1.10.0010+
HIGH 8.8
CVE-2021-38450
The affected controllers do not properly sanitize the input containing code syntax. As a result, an attacker could craft code to alter the intended c…
Tracer Concierge
4.4 / 5.5+
MEDIUM 6.1
CVE-2021-42534
The affected product’s web application does not properly neutralize the input during webpage generation, which could allow an attacker to inject code…
Tracer Sc Firmware
after 3.8
CRITICAL 9.8
CVE-2015-2867
A design flaw in the Trane ComfortLink II SCC firmware version 2.0.2 service allows remote attackers to take complete control of the system.
Comfortlink Ii Firmware
No fix yet
CRITICAL 9.8
CVE-2015-2868EPSS 7%
An exploitable remote code execution vulnerability exists in the Trane ComfortLink II firmware version 2.0.2 in DSS service. An attacker who can conn…
Comfortlink Ii Firmware
No fix yet
HIGH 7.5
CVE-2016-4526
ABB DataManagerPro 1.x before 1.7.1 allows local users to gain privileges by replacing a DLL file in the package directory.
Tracer Sc
after 4.2.1134
MEDIUM 5.3
CVE-2016-0870
The web server in Trane Tracer SC 4.2.1134 and earlier allows remote attackers to read sensitive configuration files via a direct request.
Tracer Sc
after 4.2.1134