Vulnerability index

Browse CVEs

98 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Iq4e Firmware CRITICAL 10.0
CVE-2026-3611EPSS 6%

The Honeywell IQ4x building management controller, exposes its full web-based HMI without authentication in its factory-default configuration. With n…

Fix: 3.30+
Fix from $2,300 2026-03-12
Mb Secure Firmware HIGH 8.8
CVE-2025-2605EPSS 13%

Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in Honeywell MB-Secure allows Privilege Abus…

Fix: 03.09 / 12.53+
Fix from $1,950 2025-05-02
Iq3xcite Firmware MEDIUM 6.1
CVE-2024-46453

A cross-site scripting (XSS) vulnerability in the component /test/ of iq3xcite v2.31 to v3.05 allows attackers to execute arbitrary web scripts or HT…

Fix: 3.11+
Fix from $1,600 2024-09-27
Lenels2 Netbox CRITICAL 9.8
CVE-2024-2420

LenelS2 NetBox access control and event monitoring system was discovered to contain Hardcoded Credentials in versions prior to and including 5.6.1 wh…

Fix: 5.6.2+
Fix from $2,300 2024-05-30
Lenels2 Netbox CRITICAL 9.8
CVE-2024-2421

LenelS2 NetBox access control and event monitoring system was discovered to contain an unauthenticated RCE in versions prior to and including 5.6.1, …

Fix: 5.6.2+
Fix from $2,300 2024-05-30
Lenels2 Netbox HIGH 8.8
CVE-2024-2422

LenelS2 NetBox access control and event monitoring system was discovered to contain an authenticated RCE in versions prior to and including 5.6.1, wh…

Fix: 5.6.2+
Fix from $1,950 2024-05-30
Saia Pg5 Controls Suite MEDIUM 6.5
CVE-2023-51605

Honeywell Saia PG5 Controls Suite XML External Entity Processing Information Disclosure Vulnerability. This vulnerability allows remote attackers to …

Mitigation only
Fix from $1,600 2024-05-03
Saia Pg5 Controls Suite HIGH 8.8
CVE-2023-51599

Honeywell Saia PG5 Controls Suite Directory Traversal Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbi…

Mitigation only
Fix from $1,950 2024-05-03
Saia Pg5 Controls Suite HIGH 8.8
CVE-2023-51603

Honeywell Saia PG5 Controls Suite CAB File Parsing Directory Traversal Remote Code Execution Vulnerability. This vulnerability allows remote attacker…

Mitigation only
Fix from $1,950 2024-05-03
Saia Pg5 Controls Suite MEDIUM 6.5
CVE-2023-51600

Honeywell Saia PG5 Controls Suite XML External Entity Processing Information Disclosure Vulnerability. This vulnerability allows remote attackers to …

Mitigation only
Fix from $1,600 2024-05-03
Saia Pg5 Controls Suite MEDIUM 6.5
CVE-2023-51601

Honeywell Saia PG5 Controls Suite XML External Entity Processing Information Disclosure Vulnerability. This vulnerability allows remote attackers to …

Mitigation only
Fix from $1,600 2024-05-03
Saia Pg5 Controls Suite MEDIUM 6.5
CVE-2023-51602

Honeywell Saia PG5 Controls Suite XML External Entity Processing Information Disclosure Vulnerability. This vulnerability allows remote attackers to …

Mitigation only
Fix from $1,600 2024-05-03
Saia Pg5 Controls Suite MEDIUM 6.5
CVE-2023-51604

Honeywell Saia PG5 Controls Suite XML External Entity Processing Information Disclosure Vulnerability. This vulnerability allows remote attackers to …

Mitigation only
Fix from $1,600 2024-05-03
Masmobile Asp.net Services MEDIUM 6.5
CVE-2023-36483

Authorization bypass can be achieved by session ID prediction in MASmobile Classic Android  version 1.16.18 and earlier and MASmobile Classic iOS v…

Fix: after 1.16.18
Fix from $1,600 2024-03-16
Niagara Framework HIGH 7.5
CVE-2024-1309

Uncontrolled Resource Consumption vulnerability in Honeywell Niagara Framework on Windows, Linux, QNX allows Content Spoofing.This issue affects Niag…

Fix: 3.8.1+
Fix from $1,950 2024-02-13
Controledge Unit Operations Controller Firmware MEDIUM 5.3
CVE-2023-5390

An attacker could potentially exploit this vulnerability, leading to files being read from the Honeywell Experion ControlEdge VirtualUOC and ControlE…

Mitigation only
Fix from $1,600 2024-01-31
Controledge Unit Operations Controller Firmware HIGH 7.5
CVE-2023-5389

An attacker could potentially exploit this vulnerability, leading to the ability to modify files on Honeywell Experion ControlEdge VirtualUOC and Con…

Mitigation only
Fix from $1,950 2024-01-30
Prowatch HIGH 7.8
CVE-2023-6179

Honeywell ProWatch, 4.5, including all Service Pack versions, contain a Vulnerability in Application Server's executable folder(s). A(n) attacker cou…

Mitigation only
Fix from $1,950 2023-11-17
Pm43 Firmware CRITICAL 9.8
CVE-2023-3710EPSS 33%

Improper Input Validation vulnerability in Honeywell PM43 on 32 bit, ARM (Printer web page modules) allows Command Injection.This issue affects PM43 …

Mitigation only
Fix from $2,300 2023-09-12
Pm43 Firmware HIGH 8.8
CVE-2023-3711

Session Fixation vulnerability in Honeywell PM43 on 32 bit, ARM (Printer web page modules) allows Session Credential Falsification through Prediction…

Mitigation only
Fix from $1,950 2023-09-12
Pm43 Firmware HIGH 7.8
CVE-2023-3712

Files or Directories Accessible to External Parties vulnerability in Honeywell PM43 on 32 bit, ARM (Printer web page modules) allows Privilege Escala…

Mitigation only
Fix from $1,950 2023-09-12
Experion Server HIGH 7.5
CVE-2023-25948

Server information leak of configuration data when an error is generated in response to a specially crafted message. See Honeywell Security Notificat…

Fix: after 520.2tcu2
Fix from $1,950 2023-07-13
C300 Firmware HIGH 7.5
CVE-2023-26597

Controller DoS due to buffer overflow in the handling of a specially crafted message received by the controller. See Honeywell Security Notification …

Fix: after 520.2tcu2
Fix from $1,950 2023-07-13
C300 Firmware CRITICAL 9.8
CVE-2023-25178

Controller may be loaded with malicious firmware which could enable remote code execution. See Honeywell Security Notification for recommendations on…

Fix: after 520.2tcu2
Fix from $2,300 2023-07-13
Experion Server HIGH 7.5
CVE-2023-25078

Server or Console Station DoS due to heap overflow occurring during the handling of a specially crafted message for a specific configuration operatio…

Fix: after 520.2tcu2
Fix from $1,950 2023-07-13
C300 Firmware HIGH 7.5
CVE-2023-25770

Controller DoS may occur due to buffer overflow when an error is generated in response to a specially crafted message. See Honeywell Security Notific…

Fix: after 520.2tcu2
Fix from $1,950 2023-07-13
Experion Server HIGH 7.5
CVE-2023-22435

Experion server may experience a DoS due to a stack overflow when handling a specially crafted message.

Fix: after 520.2tcu2
Fix from $1,950 2023-07-13
Experion Server HIGH 7.5
CVE-2023-23585

Experion server DoS due to heap overflow occurring during the handling of a specially crafted message for a specific configuration operation.  See H…

Fix: after 520.2tcu2
Fix from $1,950 2023-07-13
Experion Server HIGH 7.5
CVE-2023-24474

Experion server may experience a DoS due to a heap overflow which could occur when handling a specially crafted message

Fix: after 520.2tcu2
Fix from $1,950 2023-07-13
C300 Firmware HIGH 7.5
CVE-2023-24480

Controller DoS due to stack overflow when decoding a message from the server.  See Honeywell Security Notification for recommendations on upgrading …

Fix: after 520.2tcu2
Fix from $1,950 2023-07-13