Vulnerability index

Browse CVEs

62 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Process Optimization HIGH 8.8
CVE-2025-65118

The vulnerability, if exploited, could allow an authenticated miscreant (OS Standard User) to trick Process Optimization services into loading arbi…

Fix: 2025+
Fix from $1,950 2026-01-16
Process Optimization HIGH 8.8
CVE-2025-64691

The vulnerability, if exploited, could allow an authenticated miscreant (OS standard user) to tamper with TCL Macro scripts and escalate privileges…

Fix: 2025+
Fix from $1,950 2026-01-16
Process Optimization HIGH 8.2
CVE-2025-64729

The vulnerability, if exploited, could allow an authenticated miscreant (OS Standard User) to tamper with Process Optimization project files, embed…

Fix: 2025+
Fix from $1,950 2026-01-16
Process Optimization HIGH 7.8
CVE-2025-61943

The vulnerability, if exploited, could allow an authenticated miscreant (Process Optimization Standard User) to tamper with queries in Captive Hist…

Fix: 2025+
Fix from $1,950 2026-01-16
Process Optimization HIGH 7.7
CVE-2025-65117

The vulnerability, if exploited, could allow an authenticated miscreant (Process Optimization Designer User) to embed OLE objects into graphics, an…

Fix: 2025+
Fix from $1,950 2026-01-16
Process Optimization HIGH 7.1
CVE-2025-64769

The Process Optimization application suite leverages connection channels/protocols that by-default are not encrypted and could become subject to hi…

Fix: 2025+
Fix from $1,950 2026-01-16
Process Optimization CRITICAL 10.0
CVE-2025-61937

The vulnerability, if exploited, could allow an unauthenticated miscreant to achieve remote code execution under OS system privileges of “taoimr” s…

Fix: 2025+
Fix from $2,300 2026-01-16
Pi Asset Framework Client HIGH 7.8
CVE-2024-3467

There is a vulnerability in AVEVA PI Asset Framework Client that could allow malicious code to execute on the PI System Explorer environment under th…

Mitigation only
Fix from $1,950 2024-06-12
Platform Common Services HIGH 7.8
CVE-2023-6132

The vulnerability, if exploited, could allow a malicious entity with access to the file system to achieve arbitrary code execution and privilege esca…

Mitigation only
Fix from $1,950 2024-02-29
Pi Server HIGH 7.5
CVE-2023-34348

AVEVA PI Server versions 2023 and 2018 SP3 P05 and prior contain a vulnerability that could allow an unauthenticated user to remotely crash the PI Me…

Fix: 2018+
Fix from $1,950 2024-01-18
Pi Server MEDIUM 5.3
CVE-2023-31274

AVEVA PI Server versions 2023 and 2018 SP3 P05 and prior contain a vulnerability that could allow an unauthenticated user to cause the PI Message Sub…

Fix: 2018+
Fix from $1,600 2024-01-18
Edge CRITICAL 9.8
CVE-2021-42796

An issue was discovered in ExecuteCommand() in AVEVA Edge (formerly InduSoft Web Studio) versions R2020 and prior that allows unauthenticated arbitra…

Fix: 2020+
Fix from $2,300 2023-12-16
Edge HIGH 7.5
CVE-2021-42797

Path traversal vulnerability in AVEVA Edge (formerly InduSoft Web Studio) versions R2020 and prior allows an unauthenticated user to steal the Window…

Fix: 2020+
Fix from $1,950 2023-12-16
Edge MEDIUM 5.3
CVE-2021-42794

An issue was discovered in AVEVA Edge (formerly InduSoft Web Studio) versions R2020 and prior. The application allows a client to provide a malicious…

Fix: 2020+
Fix from $1,600 2023-12-16
Batch Management HIGH 7.8
CVE-2023-33873

This privilege escalation vulnerability, if exploited, cloud allow a local OS-authenticated user with standard privileges to escalate to System privi…

Fix: 2020+
Fix from $1,950 2023-11-15
Batch Management HIGH 7.1
CVE-2023-34982

This external control vulnerability, if exploited, could allow a local OS-authenticated user with standard privileges to delete files with System pri…

Fix: 2020+
Fix from $1,950 2023-11-15
Aveva Edge HIGH 7.8
CVE-2022-28685EPSS 17%

This vulnerability allows remote attackers to execute arbitrary code on affected installations of AVEVA Edge 2020 SP2 Patch 0(4201.2111.1802.0000). U…

Fix: 2020.2.00.40+
Fix from $1,950 2023-03-29
Aveva Edge HIGH 7.8
CVE-2022-28686

This vulnerability allows remote attackers to execute arbitrary code on affected installations of AVEVA Edge 2020 SP2 Patch 0(4201.2111.1802.0000). U…

Fix: 2020.2.00.40+
Fix from $1,950 2023-03-29
Aveva Edge HIGH 7.8
CVE-2022-28687

This vulnerability allows remote attackers to execute arbitrary code on affected installations of AVEVA Edge 2020 SP2 Patch 0(4201.2111.1802.0000). U…

Fix: 2020.2.00.40+
Fix from $1,950 2023-03-29
Aveva Edge HIGH 7.8
CVE-2022-28688

This vulnerability allows remote attackers to execute arbitrary code on affected installations of AVEVA Edge 2020 SP2 Patch 0(4201.2111.1802.0000). U…

Fix: 2020.2.00.40+
Fix from $1,950 2023-03-29
Aveva Edge HIGH 7.8
CVE-2022-36970

This vulnerability allows remote attackers to execute arbitrary code on affected installations of AVEVA Edge 20.0 Build: 4201.2111.1802.0000 Service …

Fix: 2020.2.00.40+
Fix from $1,950 2023-03-29
Aveva Edge HIGH 7.1
CVE-2022-36969EPSS 14%

This vulnerability allows remote attackers to disclose sensitive information on affected installations of AVEVA Edge 2020 SP2 Patch 0(4201.2111.1802.…

Fix: 2020.2.00.40+
Fix from $1,950 2023-03-29
Aveva Plant Scada CRITICAL 9.8
CVE-2023-1256

The listed versions of AVEVA Plant SCADA and AVEVA Telemetry Server are vulnerable to an improper authorization exploit which could allow an unauthen…

Mitigation only
Fix from $2,300 2023-03-16
Intouch Access Anywhere HIGH 7.5
CVE-2022-23854EPSS 46%

AVEVA InTouch Access Anywhere versions 2020 R2 and older are vulnerable to a path traversal exploit that could allow an unauthenticated user with net…

Fix: 2020+
Fix from $1,950 2022-12-23
Batch Management HIGH 7.8
CVE-2021-38410

AVEVA Software Platform Common Services (PCS) Portal versions 4.5.2, 4.5.1, 4.5.0, and 4.4.6 are vulnerable to DLL hijacking through an uncontrolled …

Mitigation only
Fix from $1,950 2022-07-27
Intouch Access Anywhere CRITICAL 9.9
CVE-2022-1467

Windows OS can be configured to overlay a “language bar” on top of any application. When this OS functionality is enabled, the OS language bar UI wil…

Mitigation only
Fix from $2,300 2022-05-23
System Platform MEDIUM 5.5
CVE-2022-0835

AVEVA System Platform 2020 stores sensitive information in cleartext, which may allow access to an attacker or a low-privileged user.

Mitigation only
Fix from $1,600 2022-04-11
System Platform CRITICAL 9.8
CVE-2021-33008

AVEVA System Platform versions 2017 through 2020 R2 P01 does not perform any authentication for functionality that requires a provable user identity.

Fix: 2020+
Fix from $2,300 2022-04-04
System Platform HIGH 7.5
CVE-2021-33010

An exception is thrown from a function in AVEVA System Platform versions 2017 through 2020 R2 P01, but it is not caught, which may cause a denial-of-…

Fix: 2020+
Fix from $1,950 2022-04-04
System Platform HIGH 7.2
CVE-2021-32985

AVEVA System Platform versions 2017 through 2020 R2 P01 does not properly verify that the source of data or communication is valid.

Fix: 2020+
Fix from $1,950 2022-04-04