openplcproject kayıtları
openplcproject üreticisine ait 13 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 0 · %0
- Silahlaştırılmış
- 0 · %0
- Pre-auth RCE
- 1
- Düzeltme kaydı olan
- %0
- Yayından KEV’e ortanca
- KEV’e giren kayıt yok
Tekrar eden sınıflar
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')2
- CWE-125 Out-of-bounds Read2
- CWE-704 Incorrect Type Conversion or Cast2
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')1
- CWE-256 Plaintext Storage of a Password1
- CWE-862 Missing Authorization1
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWETüm kayıtlar
13 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
43Planlayın | CVE-2021-31630Kavram kanıtı | Command Injection in Open PLC Webserver v3 allows remote attackers to execute arbitrary code via the "Hardware Layer Code Box" component on openplcproject · openplc v3 firmware · CWE-94 | Yüksek8,8 | — | %27,1 | 3 Ağu 2021 |
40Planlayın | CVE-2024-34026İstismar yok | A stack-based buffer overflow vulnerability exists in the OpenPLC Runtime EtherNet/IP parser functionality of OpenPLC _v3 b4702061dc14d10248openplcproject · openplc v3 firmware · CWE-121 | Kritik9,8 | — | %2,4 | 18 Eyl 2024 |
39İzleyin | CVE-2018-20818İstismar yok | A buffer overflow vulnerability was discovered in the OpenPLC controller, in the OpenPLC_v2 and OpenPLC_v3 versions.openplcproject · openplc v2 firmware · CWE-119 | Kritik9,8 | — | %1,5 | 22 Nis 2019 |
36İzleyin | CVE-2026-28205İstismar yok | Initialization of a resource with an insecure default in OpenPLC_V3openplcproject · openplc v3 firmware · CWE-1188 | Kritik9,2 | — | %0,7 | 9 Nis 2026 |
36İzleyin | CVE-2026-35556İstismar yok | Plaintext storage of a password in OpenPLC_V3openplcproject · openplc v3 firmware · CWE-256 | Kritik9,2 | — | %0,4 | 9 Nis 2026 |
34İzleyin | CVE-2026-35063İstismar yok | Missing Authorization in OpenPLC_V3openplcproject · openplc v3 firmware · CWE-862 | Yüksek8,7 | — | %0,4 | 9 Nis 2026 |
30İzleyin | CVE-2024-36980İstismar yok | An out-of-bounds read vulnerability exists in the OpenPLC Runtime EtherNet/IP PCCC parser functionality of OpenPLC_v3 b4702061dc14d1024856f7openplcproject · openplc v3 firmware · CWE-125 | Yüksek7,5 | — | %1,1 | 18 Eyl 2024 |
30İzleyin | CVE-2024-39590İstismar yok | Multiple invalid pointer dereference vulnerabilities exist in the OpenPLC Runtime EtherNet/IP parser functionality of OpenPLC_v3 16bf8bac1a3openplcproject · openplc v3 firmware · CWE-704 | Yüksek7,5 | — | %1,0 | 18 Eyl 2024 |
30İzleyin | CVE-2024-36981İstismar yok | An out-of-bounds read vulnerability exists in the OpenPLC Runtime EtherNet/IP PCCC parser functionality of OpenPLC_v3 b4702061dc14d1024856f7openplcproject · openplc v3 firmware · CWE-125 | Yüksek7,5 | — | %1,0 | 18 Eyl 2024 |
30İzleyin | CVE-2024-39589İstismar yok | Multiple invalid pointer dereference vulnerabilities exist in the OpenPLC Runtime EtherNet/IP parser functionality of OpenPLC_v3 16bf8bac1a3openplcproject · openplc v3 firmware · CWE-704 | Yüksek7,5 | — | %1,0 | 18 Eyl 2024 |
26İzleyin | CVE-2026-31156Kavram kanıtı | A path injection vulnerability exists in OpenPLC v3 (2c82b0e79c53f8c1f1458eee15fec173400d6e1a) as the binary program compiled from glue_geneopenplcproject · openplc v3 firmware · CWE-22 | Orta6,5 | — | %0,5 | 13 May 2026 |
21İzleyin | CVE-2021-3351İstismar yok | OpenPLC runtime V3 through 2016-03-14 allows stored XSS via the Device Name to the web server's Add New Device page.openplcproject · openplc · CWE-79 | Orta5,4 | — | %0,5 | 2 Ağu 2021 |
21İzleyin | CVE-2024-37741İstismar yok | OpenPLC 3 through 9cd8f1b allows XSS via an SVG document as a profile picture.openplcproject · openplc v3 firmware · CWE-79 | Orta5,4 | — | %0,3 | 28 Haz 2024 |
- CVE-2021-3163043Planlayın
Command Injection in Open PLC Webserver v3 allows remote attackers to execute arbitrary code via the "Hardware Layer Code Box" component on
YüksekCVSS 8,8Kavram kanıtıEPSS %27openplcproject · openplc v3 firmware3 Ağu 2021
- CVE-2024-3402640Planlayın
A stack-based buffer overflow vulnerability exists in the OpenPLC Runtime EtherNet/IP parser functionality of OpenPLC _v3 b4702061dc14d10248
KritikCVSS 9,8İstismar yokEPSS %2openplcproject · openplc v3 firmware18 Eyl 2024
- CVE-2018-2081839İzleyin
A buffer overflow vulnerability was discovered in the OpenPLC controller, in the OpenPLC_v2 and OpenPLC_v3 versions.
KritikCVSS 9,8İstismar yokEPSS %2openplcproject · openplc v2 firmware22 Nis 2019
- CVE-2026-2820536İzleyin
Initialization of a resource with an insecure default in OpenPLC_V3
KritikCVSS 9,2İstismar yokEPSS %1openplcproject · openplc v3 firmware9 Nis 2026
- CVE-2026-3555636İzleyin
Plaintext storage of a password in OpenPLC_V3
KritikCVSS 9,2İstismar yokEPSS %0openplcproject · openplc v3 firmware9 Nis 2026
- CVE-2026-3506334İzleyin
Missing Authorization in OpenPLC_V3
YüksekCVSS 8,7İstismar yokEPSS %0openplcproject · openplc v3 firmware9 Nis 2026
- CVE-2024-3698030İzleyin
An out-of-bounds read vulnerability exists in the OpenPLC Runtime EtherNet/IP PCCC parser functionality of OpenPLC_v3 b4702061dc14d1024856f7
YüksekCVSS 7,5İstismar yokEPSS %1openplcproject · openplc v3 firmware18 Eyl 2024
- CVE-2024-3959030İzleyin
Multiple invalid pointer dereference vulnerabilities exist in the OpenPLC Runtime EtherNet/IP parser functionality of OpenPLC_v3 16bf8bac1a3
YüksekCVSS 7,5İstismar yokEPSS %1openplcproject · openplc v3 firmware18 Eyl 2024
- CVE-2024-3698130İzleyin
An out-of-bounds read vulnerability exists in the OpenPLC Runtime EtherNet/IP PCCC parser functionality of OpenPLC_v3 b4702061dc14d1024856f7
YüksekCVSS 7,5İstismar yokEPSS %1openplcproject · openplc v3 firmware18 Eyl 2024
- CVE-2024-3958930İzleyin
Multiple invalid pointer dereference vulnerabilities exist in the OpenPLC Runtime EtherNet/IP parser functionality of OpenPLC_v3 16bf8bac1a3
YüksekCVSS 7,5İstismar yokEPSS %1openplcproject · openplc v3 firmware18 Eyl 2024
- CVE-2026-3115626İzleyin
A path injection vulnerability exists in OpenPLC v3 (2c82b0e79c53f8c1f1458eee15fec173400d6e1a) as the binary program compiled from glue_gene
OrtaCVSS 6,5Kavram kanıtıEPSS %0openplcproject · openplc v3 firmware13 May 2026
- CVE-2021-335121İzleyin
OpenPLC runtime V3 through 2016-03-14 allows stored XSS via the Device Name to the web server's Add New Device page.
OrtaCVSS 5,4İstismar yokEPSS %1openplcproject · openplc2 Ağu 2021
- CVE-2024-3774121İzleyin
OpenPLC 3 through 9cd8f1b allows XSS via an SVG document as a profile picture.
OrtaCVSS 5,4İstismar yokEPSS %0openplcproject · openplc v3 firmware28 Haz 2024