Vulnerability index

Browse CVEs

107 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

CRITICAL 9.8 CVE-2025-41732 An unauthenticated remote attacker can abuse unsafe sscanf calls within the check_cookie() function to write arbitrary data into fixed-size stack buf… 0852 1328 Firmware 02.64+ Fix from $2,3002025-12-10 CRITICAL 9.8 CVE-2025-41730 An unauthenticated remote attacker can abuse unsafe sscanf calls within the check_account() function to write arbitrary data into fixed-size stack bu… 0852 1328 Firmware 02.64+ Fix from $2,3002025-12-10 HIGH 7.5 CVE-2023-5188 The MMS Interpreter of WagoAppRTU in versions below 1.4.6.0 which is used by the WAGO Telecontrol Configurator is vulnerable to malformed packets. An… Telecontrol Configurator 1.4.6.0+ Fix from $1,9502023-12-05 CRITICAL 9.8 CVE-2023-4149 A vulnerability in the web-based management allows an unauthenticated remote attacker to inject arbitrary system commands and gain full system contro… 0852 0602 Firmware 1.0.6.s0 / 1.2.5.s0+ Fix from $2,3002023-11-21 MEDIUM 5.3 CVE-2023-3379 Wago web-based management of multiple products has a vulnerability which allows an local authenticated attacker to change the passwords of other non… Compact Controller 100 Firmware 22+ Fix from $1,6002023-11-20 HIGH 7.5 CVE-2023-1150 Uncontrolled resource consumption in Series WAGO 750-3x/-8x products may allow an unauthenticated remote attacker to DoS the MODBUS server with speci… 750 363\/040 000 Firmware Mitigation only Fix from $1,9502023-06-26 CRITICAL 9.8 CVE-2023-1698EPSS 82% In multiple products of WAGO a vulnerability allows an unauthenticated, remote attacker to create new users and change the device configuration which… Compact Controller 100 Firmware after 23 Fix from $2,3002023-05-15 CRITICAL 9.8 CVE-2022-45138 The configuration backend of the web-based management can be used by unauthenticated users, although only authenticated users should be able to use t… 751 9301 Firmware 22+ Fix from $2,3002023-02-27 CRITICAL 9.8 CVE-2022-45140 The configuration backend allows an unauthenticated user to write arbitrary data with root privileges to the storage, which could lead to unauthentic… 751 9301 Firmware 22+ Fix from $2,3002023-02-27 MEDIUM 6.1 CVE-2022-45137 The configuration backend of the web-based management is vulnerable to reflected XSS (Cross-Site Scripting) attacks that targets the users browser. T… 751 9301 Firmware 22+ Fix from $1,6002023-02-27 MEDIUM 5.3 CVE-2022-45139 A CORS Misconfiguration in the web-based management allows a malicious third party webserver to misuse all basic information pages on the webserver. … 751 9301 Firmware 22+ Fix from $1,6002023-02-27 CRITICAL 9.1 CVE-2022-3843 In WAGO Unmanaged Switch (852-111/000-001) in firmware version 01 an undocumented configuration interface without authorization allows an remote atta… 852 111\/000 001 Firmware Mitigation only Fix from $2,3002023-02-16 MEDIUM 5.9 CVE-2022-3738 The vulnerability allows a remote unauthenticated attacker to download a backup file, if one exists. That backup file might contain sensitive informa… Pfc100 Firmware after 22 Fix from $1,6002023-01-19 CRITICAL 9.8 CVE-2021-34569 In WAGO I/O-Check Service in multiple products an attacker can send a specially crafted packet containing OS commands to crash the diagnostic tool an… 750 8100 Firmware 18+ Fix from $2,3002022-11-09 HIGH 7.5 CVE-2021-34568 In WAGO I/O-Check Service in multiple products an unauthenticated remote attacker can send a specially crafted packet containing OS commands to provo… 750 8100 Firmware 18+ Fix from $1,9502022-11-09 HIGH 8.2 CVE-2021-34567 In WAGO I/O-Check Service in multiple products an unauthenticated remote attacker can send a specially crafted packet containing OS commands to provo… 750 8100 Firmware 18+ Fix from $1,9502022-11-09 CRITICAL 9.1 CVE-2021-34566 In WAGO I/O-Check Service in multiple products an unauthenticated remote attacker can send a specially crafted packet containing OS commands to crash… 750 8100 Firmware 18+ Fix from $2,3002022-11-09 HIGH 7.5 CVE-2022-3281 WAGO Series PFC100/PFC200, Series Touch Panel 600, Compact Controller CC100 and Edge Controller in multiple versions are prone to a loss of MAC-Addre… 750 8100 Firmware after 03.10.08 Fix from $1,9502022-10-17 MEDIUM 5.4 CVE-2022-22511 Various configuration pages of the device are vulnerable to reflected XSS (Cross-Site Scripting) attacks. An authorized attacker with user privileges… 750 8100 Firmware Mitigation only Fix from $1,6002022-03-09 HIGH 8.1 CVE-2021-34595 A crafted request with invalid offsets may cause an out-of-bounds read or write access in CODESYS V2 Runtime Toolkit 32 Bit full and PLCWinNT prior t… 750 823 Firmware Mitigation only Fix from $1,9502021-10-26 HIGH 7.5 CVE-2021-34593 In CODESYS V2 Runtime Toolkit 32 Bit full and PLCWinNT prior to versions V2.4.7.56 unauthenticated crafted invalid requests may result in several den… 750 8202 Firmware No fix yet Fix from $1,9502021-10-26 MEDIUM 6.5 CVE-2021-34596 A crafted request may cause a read access to an uninitialized pointer in CODESYS V2 Runtime Toolkit 32 Bit full and PLCWinNT prior to versions V2.4.7… 750 823 Firmware Mitigation only Fix from $1,6002021-10-26 CRITICAL 9.1 CVE-2021-34584 Crafted web server requests can be utilised to read partial stack or heap memory or may trigger a denial-of- service condition due to a crash in the … 750 823 Firmware No fix yet Fix from $2,3002021-10-26 HIGH 7.5 CVE-2021-34583EPSS 8% Crafted web server requests may cause a heap-based buffer overflow and could therefore trigger a denial-of- service condition due to a crash in the C… 750 8214 Firmware No fix yet Fix from $1,9502021-10-26 HIGH 7.5 CVE-2021-34585 In the CODESYS V2 web server prior to V1.1.9.22 crafted web server requests can trigger a parser error. Since the parser result is not checked under … 750 823 Firmware No fix yet Fix from $1,9502021-10-26 HIGH 7.5 CVE-2021-34586EPSS 13% In the CODESYS V2 web server prior to V1.1.9.22 crafted web server requests may cause a Null pointer dereference in the CODESYS web server and may re… 750 823 Firmware No fix yet Fix from $1,9502021-10-26 HIGH 8.1 CVE-2021-34578 This vulnerability allows an attacker who has access to the WBM to read and write settings-parameters of the device by sending specifically construct… 750 890\/040 000 Firmware Mitigation only Fix from $1,9502021-08-31 HIGH 7.5 CVE-2021-34581 Missing Release of Resource after Effective Lifetime vulnerability in OpenSSL implementation of WAGO 750-831/xxx-xxx, 750-880/xxx-xxx, 750-881, 750-8… 750 880\/040 000 Firmware Mitigation only Fix from $1,9502021-08-31 CRITICAL 9.8 CVE-2021-30188 CODESYS V2 runtime system SP before 2.4.7.55 has a Stack-based Buffer Overflow. 750 893 Firmware Mitigation only Fix from $2,3002021-05-25 CRITICAL 9.8 CVE-2021-30189 CODESYS V2 Web-Server before 1.1.9.20 has a Stack-based Buffer Overflow. 750 893 Firmware Mitigation only Fix from $2,3002021-05-25