Skip to content
Noroxi

ScadaBR records

11 published records for vendor scadabr.

All records

11 records
  • CVE-2021-26828
    77This week

    OpenPLC ScadaBR through 0.9.1 on Linux and through 1.12.4 on Windows allows remote authenticated users to upload and execute arbitrary JSP f

    HighCVSS 8.8KEVWeaponizedEPSS 39%

    scadabr · scadabrJun 11, 2021

  • CVE-2021-26829
    65This week

    OpenPLC ScadaBR through 0.9.1 on Linux and through 1.12.4 on Windows allows stored XSS via system_settings.shtm.

    MediumCVSS 5.4KEVWeaponizedEPSS 48%

    scadabr · scadabrJun 11, 2021

  • CVE-2026-9645
    39Monitor

    ScadaBR Authenticated Remote Code Execution

    CriticalCVSS 9.9Proof of conceptEPSS 1%

    scadabr · scadabrMay 28, 2026

  • CVE-2026-8603
    35Monitor

    Improper neutralization of special elements used in an OS command ('OS command injection') in ScadaBR

    HighCVSS 8.7No exploitEPSS 2%

    scadabr · scadabrMay 19, 2026

  • CVE-2026-8602
    35Monitor

    Missing authentication for critical function in ScadaBR

    HighCVSS 8.8No exploitEPSS 1%

    scadabr · scadabrMay 19, 2026

  • CVE-2026-8604
    34Monitor

    Cross-Site request forgery (CSRF) in ScadaBR

    HighCVSS 8.6No exploitEPSS 0%

    scadabr · scadabrMay 19, 2026

  • A cross-site scripting (XSS) vulnerability in the login form (/ScadaBR/login.htm) in ScadaBR 1.0CE allows a remote attacker to inject arbitr

    MediumCVSS 6.1No exploitEPSS 1%

    scadabr · scadabrOct 14, 2019

  • ScadaBR 1.0CE, and 1.1.x through 1.1.0-RC, has XSS via a request for a nonexistent resource, as demonstrated by the dwr/test/ PATH_INFO.

    MediumCVSS 6.1No exploitEPSS 1%

    scadabr · scadabrSep 15, 2019

  • CVE-2026-9646
    24Monitor

    ScadaBR Unauthenticated Reflected Cross-Site Scripting

    MediumCVSS 6.1No exploitEPSS 0%

    scadabr · scadabrMay 28, 2026

  • CVE-2026-8605
    20Monitor

    Use of Hard-coded Credentials in ScadaBR

    MediumCVSS 5.1No exploitEPSS 0%

    scadabr · scadabrMay 19, 2026

  • ScadaBR 1.12.4 is vulnerable to Session Fixation.

    MediumCVSS 4.8No exploitEPSS 0%

    scadabr · scadabrMar 9, 2026