Vulnerability index

Browse CVEs

159 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Ecostruxure Power Monitoring Expert HIGH 7.8
CVE-2025-11739

CWE‑502: Deserialization of Untrusted Data vulnerability exists that could cause arbitrary code execution with administrative privileges when a local…

Mitigation only
Fix from $1,950 2026-03-10
Whc 5918a Firmware HIGH 7.5
CVE-2024-6407

CWE-200: Information Exposure vulnerability exists that could cause disclosure of credentials when a specially crafted message is sent to the device.

No fix yet
Fix from $1,950 2024-07-11
Modicon M241 Firmware MEDIUM 6.1
CVE-2024-6528

CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability exists that could cause a vulnerability le…

Mitigation only
Fix from $1,600 2024-07-11
Sage Rtu Firmware CRITICAL 9.8
CVE-2024-37036

CWE-787: Out-of-bounds Write vulnerability exists that could result in an authentication bypass when sending a malformed POST request and particular …

No fix yet
Fix from $2,300 2024-06-12
Evlink Home Firmware MEDIUM 6.5
CVE-2024-5313

CWE-668: Exposure of the Resource Wrong Sphere vulnerability exists that exposes a SSH interface over the product network interface. This does not al…

Mitigation only
Fix from $1,600 2024-06-12
Modicon M340 Firmware MEDIUM 6.5
CVE-2024-5056

CWE-552: Files or Directories Accessible to External Parties vulnerability exists which may prevent user to update the device firmware and prevent pr…

Mitigation only
Fix from $1,600 2024-06-12
Eb450 Firmware MEDIUM 6.1
CVE-2023-5629

A CWE-601:URL Redirection to Untrusted Site (‘Open Redirect’) vulnerability exists that could cause disclosure of information through phishing attemp…

No fix yet
Fix from $1,600 2023-12-14
Ecostruxure Power Monitoring Expert MEDIUM 6.1
CVE-2023-5986

A CWE-601 URL Redirection to Untrusted Site vulnerability exists that could cause an openredirect vulnerability leading to a cross site scripting att…

Mitigation only
Fix from $1,600 2023-11-15
Galaxy Vl Firmware MEDIUM 5.3
CVE-2023-6032

A CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability exists that could cause a file system enumerat…

Mitigation only
Fix from $1,600 2023-11-15
Ecostruxure Power Monitoring Expert CRITICAL 9.8
CVE-2023-5391

A CWE-502: Deserialization of untrusted data vulnerability exists that could allow an attacker to execute arbitrary code on the targeted system by se…

No fix yet
Fix from $2,300 2023-10-04
Ecostruxure Foxboro Dcs Control Core Services HIGH 7.8
CVE-2023-2569

A CWE-787: Out-of-Bounds Write vulnerability exists that could cause local denial-of-service, elevation of privilege, and potentially kernel executio…

Mitigation only
Fix from $1,950 2023-06-14
Ecostruxure Foxboro Dcs Control Core Services HIGH 7.8
CVE-2023-2570

A CWE-129: Improper Validation of Array Index vulnerability exists that could cause local denial-of-service, and potentially kernel execution when a …

Mitigation only
Fix from $1,950 2023-06-14
Merten Instabus Tastermodul 1fach System M Firmware HIGH 8.8
CVE-2023-25556

A CWE-287: Improper Authentication vulnerability exists that could allow a device to be compromised when a key of less than seven digits is entered a…

Mitigation only
Fix from $1,950 2023-04-18
Ecostruxure Control Expert HIGH 8.8
CVE-2023-27976

A CWE-668: Exposure of Resource to Wrong Sphere vulnerability exists that could cause remote code execution when a valid user visits a malicious link…

No fix yet
Fix from $1,950 2023-04-18
Ecostruxure Control Expert MEDIUM 5.5
CVE-2023-1548

A CWE-269: Improper Privilege Management vulnerability exists that could cause a local user to perform a denial of service through the console server…

Mitigation only
Fix from $1,600 2023-04-18
Clearscada MEDIUM 5.3
CVE-2023-0595

A CWE-117: Improper Output Neutralization for Logs vulnerability exists that could cause the misinterpretation of log files when malicious packets ar…

Mitigation only
Fix from $1,600 2023-02-24
Conext Combox Firmware CRITICAL 9.8
CVE-2022-32515

A CWE-307: Improper Restriction of Excessive Authentication Attempts vulnerability exists that could cause brute force attacks to take over the admin…

Mitigation only
Fix from $2,300 2023-01-30
Conext Combox Firmware MEDIUM 6.5
CVE-2022-32516

A CWE-352: Cross-Site Request Forgery (CSRF) vulnerability exists that could cause system’s configurations override and cause a reboot loop when the …

Mitigation only
Fix from $1,600 2023-01-30
Conext Combox Firmware MEDIUM 6.5
CVE-2022-32517

A CWE-1021: Improper Restriction of Rendered UI Layers or Frames vulnerability exists that could cause an adversary to trick the interface user/admin…

Mitigation only
Fix from $1,600 2023-01-30
Ritto Wiser Door HIGH 7.6
CVE-2021-22783

A CWE-200: Information Exposure vulnerability exists which could allow a session hijack when the door panel is communicating with the door. Affected …

Mitigation only
Fix from $1,950 2022-03-09
Connexium Network Manager CRITICAL 9.8
CVE-2021-22801

A CWE-269: Improper Privilege Management vulnerability exists that could cause an arbitrary command execution when the software is configured with sp…

Mitigation only
Fix from $2,300 2022-02-11
Conext Combox Firmware HIGH 7.5
CVE-2021-22798

A CWE-522: Insufficiently Protected Credentials vulnerability exists that could cause Sensitive data such as login credentials being exposed when a N…

Mitigation only
Fix from $1,950 2022-02-11
Easergy P141 Firmware CRITICAL 9.8
CVE-2022-22813

A CWE-798: Use of Hard-coded Credentials vulnerability exists. If an attacker were to obtain the TLS cryptographic key and take active control of the…

Mitigation only
Fix from $2,300 2022-02-09
Hmibmuhi29d2801 Firmware HIGH 7.8
CVE-2021-22817

A CWE-276: Incorrect Default Permissions vulnerability exists that could cause unauthorized access to the base installation directory leading to loca…

Mitigation only
Fix from $1,950 2022-02-09
T200i Firmware CRITICAL 9.8
CVE-2021-22772

A CWE-306: Missing Authentication for Critical Function vulnerability exists in Easergy T200 ((Modbus) SC2-04MOD-07000100 and earlier), Easergy T200 …

Mitigation only
Fix from $2,300 2021-07-21
Evlink City Evc1s22p4 Firmware HIGH 7.5
CVE-2021-22774

A CWE-759: Use of a One-Way Hash without a Salt vulnerability exists in EVlink City (EVC1S22P4 / EVC1S7P4 all versions prior to R8 V3.4.0.1), EVlink …

Mitigation only
Fix from $1,950 2021-07-21
Evlink City Evc1s22p4 Firmware MEDIUM 6.5
CVE-2021-22773

A CWE-620: Unverified Password Change vulnerability exists in EVlink City (EVC1S22P4 / EVC1S7P4 all versions prior to R8 V3.4.0.1), EVlink Parking (E…

Mitigation only
Fix from $1,600 2021-07-21
Evlink City Evc1s22p4 Firmware CRITICAL 9.8
CVE-2021-22707EPSS 65%

A CWE-798: Use of Hard-coded Credentials vulnerability exists in EVlink City (EVC1S22P4 / EVC1S7P4 all versions prior to R8 V3.4.0.1), EVlink Parking…

Mitigation only
Fix from $2,300 2021-07-21
Evlink City Evc1s22p4 Firmware CRITICAL 9.8
CVE-2021-22727

A CWE-331: Insufficient Entropy vulnerability exists in EVlink City (EVC1S22P4 / EVC1S7P4 all versions prior to R8 V3.4.0.1), EVlink Parking (EVW2 / …

Mitigation only
Fix from $2,300 2021-07-21
Evlink City Evc1s22p4 Firmware CRITICAL 9.8
CVE-2021-22729

A CWE-259: Use of Hard-coded Password vulnerability exists in EVlink City (EVC1S22P4 / EVC1S7P4 all versions prior to R8 V3.4.0.1), EVlink Parking (E…

Mitigation only
Fix from $2,300 2021-07-21