Vulnerability index

Browse CVEs

50 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Gridtime 3000 Firmware MEDIUM 6.5
CVE-2026-12620

The GridTime 3000 GNSS Time Server leaks the access token in the URL parameters of some endpoints. This issue affects GridTime 3000: from 1.0r0.03 t…

Fix: 1.2r0.0+
Fix from $1,600 2026-06-19
Gridtime 3000 Firmware MEDIUM 5.4
CVE-2026-12621

Improper neutralization of input during web page generation XSS vulnerability in the GridTime 3000 (password reset form) allows XSS. This issue aff…

Fix: 1.2r0.0+
Fix from $1,600 2026-06-19
Gridtime 3000 Firmware MEDIUM 5.4
CVE-2026-12622

The GridTime 3000 GNSS Time Server has an open redirect vulnerability in the password change form submission. This issue affects GridTime 3000: from…

Fix: 1.2r0.0+
Fix from $1,600 2026-06-19
Gridtime 3000 Firmware MEDIUM 5.4
CVE-2026-12619

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Microchip GridTime 3000 allows Cross-Sit…

Fix: 1.2r0.0+
Fix from $1,600 2026-06-19
Istax HIGH 8.8
CVE-2026-2336

A privilege escalation vulnerability in Microchip IStaX allows an authenticated low-privileged user to recover a shared per-device cookie secret from…

Fix: 2026.03+
Fix from $1,950 2026-04-16
Timeprovider 4100 Firmware CRITICAL 9.8
CVE-2025-9497

Use of Hard-coded Credentials vulnerability in Microchip Time Provider 4100 allows Malicious Manual Software Update.This issue affects Time Provider …

Fix: 2.5.0+
Fix from $2,300 2026-03-28
Timepictra MEDIUM 6.1
CVE-2026-3010

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Microchip TimePictra allows Query System…

Fix: after 11.3
Fix from $1,600 2026-02-28
Timepictra HIGH 7.5
CVE-2026-2844

Missing Authentication for Critical Function vulnerability in Microchip TimePictra allows Configuration/Environment Manipulation.This issue affects T…

Fix: after 11.3
Fix from $1,950 2026-02-28
Timeprovider 4100 Firmware HIGH 8.8
CVE-2025-47900

Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in Microchip Time Provider 4100 allows OS Co…

Fix: 2.5+
Fix from $1,950 2025-10-20
Timeprovider 4100 Firmware HIGH 8.8
CVE-2025-47901

Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in Microchip Time Provider 4100 allows OS Co…

Fix: 2.5+
Fix from $1,950 2025-10-20
Timeprovider 4100 Firmware HIGH 8.8
CVE-2025-47902

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Microchip Time Provider 4100 allows SQL Injecti…

Fix: 2.5+
Fix from $1,950 2025-10-20
Timeprovider 4100 Firmware HIGH 8.8
CVE-2024-9054EPSS 16%

Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection'), Exposure of Sensitive Information to an Unauthorized Acto…

Fix: 2.4.7+
Fix from $1,950 2024-10-04
Timeprovider 4100 Firmware MEDIUM 6.5
CVE-2024-7801

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Microchip TimeProvider 4100 (Data plot modules)…

Fix: 2.4.7+
Fix from $1,600 2024-10-04
Timeprovider 4100 Firmware MEDIUM 6.1
CVE-2024-43687

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Microchip TimeProvider 4100 (banner conf…

Fix: 2.4.7+
Fix from $1,600 2024-10-04
Timeprovider 4100 Firmware CRITICAL 9.8
CVE-2024-43685

Improper Authentication vulnerability in Microchip TimeProvider 4100 (login modules) allows Session Hijacking.This issue affects TimeProvider 4100: f…

Fix: 2.4.7+
Fix from $2,300 2024-10-04
Timeprovider 4100 Firmware HIGH 8.8
CVE-2024-43684

Cross-Site Request Forgery (CSRF) vulnerability in Microchip TimeProvider 4100 allows Cross Site Request Forgery, Cross-Site Scripting (XSS).This iss…

Fix: 2.4.7+
Fix from $1,950 2024-10-04
Timeprovider 4100 Firmware MEDIUM 6.1
CVE-2024-43683

URL Redirection to Untrusted Site ('Open Redirect') vulnerability in Microchip TimeProvider 4100 allows XSS Through HTTP Headers.This issue affects T…

Fix: 2.4.7+
Fix from $1,600 2024-10-04
Timeprovider 4100 Firmware MEDIUM 6.1
CVE-2024-43686EPSS 12%

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Microchip TimeProvider 4100 (data plot m…

Fix: 2.4.7+
Fix from $1,600 2024-10-04
Advanced Software Framework CRITICAL 9.8
CVE-2024-7490

Improper Input Validation vulnerability in Microchip Techology Advanced Software Framework example DHCP server can cause remote code execution throug…

Fix: after 3.52.0.2574
Fix from $2,300 2024-08-08
Maxview Storage Manager CRITICAL 9.8
CVE-2023-51438

A vulnerability has been identified in SIMATIC IPC1047E (All versions with maxView Storage Manager < V4.14.00.26068 on Windows), SIMATIC IPC647E (All…

Fix: 4.14.00.26068+
Fix from $2,300 2024-01-09
Maxview Storage Manager CRITICAL 10.0
CVE-2024-22216

In default installations of Microchip maxView Storage Manager (for Adaptec Smart Storage Controllers) where Redfish server is configured for remote s…

Fix: after 4.14.00.26064
Fix from $2,300 2024-01-08
Mplab Network Creator CRITICAL 9.1
CVE-2020-27636

In Microchip MPLAB Net 3.6.1, TCP ISNs are improperly random.

Mitigation only
Fix from $2,300 2023-10-10
Syncserver S650 Firmware CRITICAL 9.8
CVE-2022-40022EPSS 92%

Microchip Technology (Microsemi) SyncServer S650 was discovered to contain a command injection vulnerability.

No fix yet
Fix from $2,300 2023-02-13
Dt100112 Firmware MEDIUM 6.5
CVE-2022-40480

Nordic Semiconductor, Microchip Technology NRF5340-DK DT100112 was discovered to contain an issue which allows attackers to cause a Denial of Service…

Mitigation only
Fix from $1,600 2023-02-08
Rn4870 Firmware MEDIUM 6.5
CVE-2022-45191

An issue was discovered on Microchip RN4870 1.43 devices. An attacker within BLE radio range can cause a denial of service by sending a pair confirm …

Mitigation only
Fix from $1,600 2023-02-08
Rn4870 Firmware MEDIUM 6.5
CVE-2022-45192

An issue was discovered on Microchip RN4870 1.43 devices. An attacker within BLE radio range can cause a denial of service by sending a cleartext enc…

Mitigation only
Fix from $1,600 2023-02-08
Rn4870 Firmware MEDIUM 5.3
CVE-2022-45190

An issue was discovered on Microchip RN4870 1.43 devices. An attacker within BLE radio range can bypass passkey entry in the legacy pairing of the de…

Mitigation only
Fix from $1,600 2023-02-08
Bm78 Firmware HIGH 8.6
CVE-2022-46403

The Microchip RN4870 module firmware 1.43 (and the Microchip PIC LightBlue Explorer Demo 4.2 DT100112) mishandles reject messages.

No fix yet
Fix from $1,950 2022-12-19
Bm78 Firmware MEDIUM 6.5
CVE-2022-46402

The Microchip RN4870 module firmware 1.43 (and the Microchip PIC LightBlue Explorer Demo 4.2 DT100112) accepts PairCon_rmSend with incorrect values.

No fix yet
Fix from $1,600 2022-12-19
Bm78 Firmware MEDIUM 5.4
CVE-2022-46401

The Microchip RN4870 module firmware 1.43 (and the Microchip PIC LightBlue Explorer Demo 4.2 DT100112) accepts PauseEncReqPlainText before pairing is…

No fix yet
Fix from $1,600 2022-12-19