Vulnerability index

Browse CVEs

37 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Ignition MEDIUM 6.8
CVE-2025-13913

A privileged Ignition user, intentionally or otherwise, imports an external file with a specially crafted payload, which executes embedded malicious …

Fix: 8.3.0+
Fix from $1,600 2026-03-12
Ignition HIGH 8.8
CVE-2023-50232

Inductive Automation Ignition getParams Argument Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute…

Fix: 8.1.33+
Fix from $1,950 2024-05-03
Ignition HIGH 8.8
CVE-2023-50233

Inductive Automation Ignition getJavaExecutable Directory Traversal Remote Code Execution Vulnerability. This vulnerability allows remote attackers t…

Fix: 8.1.33+
Fix from $1,950 2024-05-03
Ignition HIGH 8.8
CVE-2023-50220

Inductive Automation Ignition Base64Element Deserialization of Untrusted Data Remote Code Execution Vulnerability. This vulnerability allows remote a…

Fix: 8.1.35+
Fix from $1,950 2024-05-03
Ignition HIGH 8.8
CVE-2023-50221

Inductive Automation Ignition ResponseParser SerializedResponse Deserialization of Untrusted Data Remote Code Execution Vulnerability. This vulnerabi…

Fix: 8.1.35+
Fix from $1,950 2024-05-03
Ignition HIGH 8.8
CVE-2023-50222

Inductive Automation Ignition ResponseParser Notification Deserialization of Untrusted Data Remote Code Execution Vulnerability. This vulnerability a…

Fix: 8.1.35+
Fix from $1,950 2024-05-03
Ignition HIGH 8.8
CVE-2023-50223EPSS 55%

Inductive Automation Ignition ExtendedDocumentCodec Deserialization of Untrusted Data Remote Code Execution Vulnerability. This vulnerability allows …

Fix: 8.1.35+
Fix from $1,950 2024-05-03
Ignition HIGH 8.8
CVE-2023-50218EPSS 55%

Inductive Automation Ignition ModuleInvoke Deserialization of Untrusted Data Remote Code Execution Vulnerability. This vulnerability allows remote at…

Fix: 8.1.35+
Fix from $1,950 2024-05-03
Ignition HIGH 8.8
CVE-2023-50219

Inductive Automation Ignition RunQuery Deserialization of Untrusted Data Remote Code Execution Vulnerability. This vulnerability allows remote attack…

Fix: 8.1.35+
Fix from $1,950 2024-05-03
Ignition CRITICAL 9.8
CVE-2023-39475EPSS 64%

Inductive Automation Ignition ParameterVersionJavaSerializationCodec Deserialization of Untrusted Data Remote Code Execution Vulnerability. This vuln…

Fix: 8.1.35+
Fix from $2,300 2024-05-03
Ignition CRITICAL 9.8
CVE-2023-39476

Inductive Automation Ignition JavaSerializationCodec Deserialization of Untrusted Data Remote Code Execution Vulnerability. This vulnerability allows…

Fix: 8.1.35+
Fix from $2,300 2024-05-03
Ignition HIGH 8.8
CVE-2023-39473EPSS 62%

Inductive Automation Ignition AbstractGatewayFunction Deserialization of Untrusted Data Remote Code Execution Vulnerability. This vulnerability allow…

Fix: 8.1.35+
Fix from $1,950 2024-05-03
Ignition HIGH 8.8
CVE-2023-39474

Inductive Automation Ignition downloadLaunchClientJar Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbi…

Fix: 8.1.35+
Fix from $1,950 2024-05-03
Ignition HIGH 7.5
CVE-2023-39477

Inductive Automation Ignition ConditionRefresh Resource Exhaustion Denial-of-Service Vulnerability. This vulnerability allows remote attackers to cre…

Fix: 8.1.33+
Fix from $1,950 2024-05-03
Ignition MEDIUM 6.5
CVE-2023-39472

Inductive Automation Ignition SimpleXMLReader XML External Entity Processing Information Disclosure Vulnerability. This vulnerability allows remote a…

Fix: 8.1.32+
Fix from $1,600 2024-05-03
Ignition HIGH 8.8
CVE-2023-38124EPSS 60%

Inductive Automation Ignition OPC UA Quick Client Task Scheduling Exposed Dangerous Function Remote Code Execution Vulnerability. This vulnerability …

Fix: 8.1.26+
Fix from $1,950 2024-05-03
Ignition CRITICAL 9.0
CVE-2023-38121

Inductive Automation Ignition OPC UA Quick Client Cross-Site Scripting Remote Code Execution Vulnerability. This vulnerability allows remote attacker…

Fix: 8.1.26+
Fix from $2,300 2024-05-03
Ignition HIGH 8.8
CVE-2023-38123

Inductive Automation Ignition OPC UA Quick Client Missing Authentication for Critical Function Authentication Bypass Vulnerability. This vulnerabilit…

Fix: 8.1.26+
Fix from $1,950 2024-05-03
Ignition HIGH 7.2
CVE-2023-38122

Inductive Automation Ignition OPC UA Quick Client Permissive Cross-domain Policy Remote Code Execution Vulnerability. This vulnerability allows remot…

Fix: 8.1.26+
Fix from $1,950 2024-05-03
Ignition CRITICAL 9.8
CVE-2022-1704

Due to an XML external entity reference, the software parses XML in the backup/restore functionality without XML security flags, which may lead to a …

Fix: 7.9.21 / 8.1.8+
Fix from $2,300 2022-08-05
Ignition HIGH 7.8
CVE-2022-35873

This vulnerability allows remote attackers to execute arbitrary code on affected installations of Inductive Automation Ignition 8.1.15 (b2022030114).…

Mitigation only
Fix from $1,950 2022-07-25
Ignition HIGH 7.8
CVE-2022-35872

This vulnerability allows remote attackers to execute arbitrary code on affected installations of Inductive Automation Ignition 8.1.15 (b2022030114).…

Mitigation only
Fix from $1,950 2022-07-25
Ignition HIGH 7.8
CVE-2022-35871EPSS 39%

This vulnerability allows remote attackers to execute arbitrary code on affected installations of Inductive Automation Ignition 8.1.15 (b2022030114).…

Mitigation only
Fix from $1,950 2022-07-25
Ignition CRITICAL 9.8
CVE-2022-35869EPSS 60%

This vulnerability allows remote attackers to bypass authentication on affected installations of Inductive Automation Ignition 8.1.15 (b2022030114). …

Mitigation only
Fix from $2,300 2022-07-25
Ignition HIGH 7.8
CVE-2022-35870EPSS 43%

This vulnerability allows remote attackers to execute arbitrary code on affected installations of Inductive Automation Ignition 8.1.15 (b2022030114).…

Mitigation only
Fix from $1,950 2022-07-25
Ignition HIGH 8.8
CVE-2022-1264

The affected product may allow an attacker with access to the Ignition web configuration to run arbitrary code.

Fix: 8.1.10+
Fix from $1,950 2022-07-20
Ignition HIGH 7.2
CVE-2022-36126

An issue was discovered in Inductive Automation Ignition before 7.9.20 and 8.x before 8.1.17. The ScriptInvoke function allows remote attackers to ex…

Fix: 7.9.20 / 8.1.17+
Fix from $1,950 2022-07-16
Ignition CRITICAL 9.8
CVE-2022-35890

An issue was discovered in Inductive Automation Ignition before 7.9.20 and 8.x before 8.1.17. Designer and Vision Client Session IDs are mishandled. …

Fix: 7.9.20 / 8.1.17+
Fix from $2,300 2022-07-15
Ignition MEDIUM 5.3
CVE-2020-14479

Sensitive information can be obtained through the handling of serialized data. The issue results from the lack of proper authentication required to q…

Fix: 7.9.14+
Fix from $1,600 2022-04-01
Ignition Gateway HIGH 7.5
CVE-2020-14520

The affected product is vulnerable to an information leak, which may allow an attacker to obtain sensitive information on the Ignition 8 (all version…

Fix: 8.0.13+
Fix from $1,950 2020-07-31