ScadaBR records
11 published records for vendor scadabr.
Researcher profile
- Entered KEV
- 2 · 18.2%
- Weaponized
- 2 · 18.2%
- Pre-auth RCE
- 0
- With a fix record
- 0%
- Median publish → KEV
- 1634 days
Recurring classes
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')3
- CWE-78 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')2
- CWE-384 Session Fixation1
- CWE-434 Unrestricted Upload of File with Dangerous Type1
- CWE-798 Use of Hard-coded Credentials1
- CWE-306 Missing Authentication for Critical Function1
The weakness classes this vendor ships most often: where to look.
CWEAll records
11 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
77This week | CVE-2021-26828Weaponized | OpenPLC ScadaBR through 0.9.1 on Linux and through 1.12.4 on Windows allows remote authenticated users to upload and execute arbitrary JSP fscadabr · scadabr · CWE-434 | High8.8 | KEV | 39.4% | Jun 11, 2021 |
65This week | CVE-2021-26829Weaponized | OpenPLC ScadaBR through 0.9.1 on Linux and through 1.12.4 on Windows allows stored XSS via system_settings.shtm.scadabr · scadabr · CWE-79 | Medium5.4 | KEV | 48.1% | Jun 11, 2021 |
39Monitor | CVE-2026-9645Proof of concept | ScadaBR Authenticated Remote Code Executionscadabr · scadabr · CWE-78 | Critical9.9 | — | 0.5% | May 28, 2026 |
35Monitor | CVE-2026-8603No exploit | Improper neutralization of special elements used in an OS command ('OS command injection') in ScadaBRscadabr · scadabr · CWE-78 | High8.7 | — | 2.1% | May 19, 2026 |
35Monitor | CVE-2026-8602No exploit | Missing authentication for critical function in ScadaBRscadabr · scadabr · CWE-306 | High8.8 | — | 0.6% | May 19, 2026 |
34Monitor | CVE-2026-8604No exploit | Cross-Site request forgery (CSRF) in ScadaBRscadabr · scadabr · CWE-352 | High8.6 | — | 0.2% | May 19, 2026 |
24Monitor | CVE-2019-16344No exploit | A cross-site scripting (XSS) vulnerability in the login form (/ScadaBR/login.htm) in ScadaBR 1.0CE allows a remote attacker to inject arbitrscadabr · scadabr · CWE-79 | Medium6.1 | — | 1.0% | Oct 14, 2019 |
24Monitor | CVE-2019-16321No exploit | ScadaBR 1.0CE, and 1.1.x through 1.1.0-RC, has XSS via a request for a nonexistent resource, as demonstrated by the dwr/test/ PATH_INFO.scadabr · scadabr · CWE-79 | Medium6.1 | — | 0.8% | Sep 15, 2019 |
24Monitor | CVE-2026-9646No exploit | ScadaBR Unauthenticated Reflected Cross-Site Scriptingscadabr · scadabr · CWE-80 | Medium6.1 | — | 0.3% | May 28, 2026 |
20Monitor | CVE-2026-8605No exploit | Use of Hard-coded Credentials in ScadaBRscadabr · scadabr · CWE-798 | Medium5.1 | — | 0.5% | May 19, 2026 |
19Monitor | CVE-2025-70973No exploit | ScadaBR 1.12.4 is vulnerable to Session Fixation.scadabr · scadabr · CWE-384 | Medium4.8 | — | 0.2% | Mar 9, 2026 |
- CVE-2021-2682877This week
OpenPLC ScadaBR through 0.9.1 on Linux and through 1.12.4 on Windows allows remote authenticated users to upload and execute arbitrary JSP f
HighCVSS 8.8KEVWeaponizedEPSS 39%scadabr · scadabrJun 11, 2021
- CVE-2021-2682965This week
OpenPLC ScadaBR through 0.9.1 on Linux and through 1.12.4 on Windows allows stored XSS via system_settings.shtm.
MediumCVSS 5.4KEVWeaponizedEPSS 48%scadabr · scadabrJun 11, 2021
- CVE-2026-964539Monitor
ScadaBR Authenticated Remote Code Execution
CriticalCVSS 9.9Proof of conceptEPSS 1%scadabr · scadabrMay 28, 2026
- CVE-2026-860335Monitor
Improper neutralization of special elements used in an OS command ('OS command injection') in ScadaBR
HighCVSS 8.7No exploitEPSS 2%scadabr · scadabrMay 19, 2026
- CVE-2026-860235Monitor
Missing authentication for critical function in ScadaBR
HighCVSS 8.8No exploitEPSS 1%scadabr · scadabrMay 19, 2026
- CVE-2026-860434Monitor
Cross-Site request forgery (CSRF) in ScadaBR
HighCVSS 8.6No exploitEPSS 0%scadabr · scadabrMay 19, 2026
- CVE-2019-1634424Monitor
A cross-site scripting (XSS) vulnerability in the login form (/ScadaBR/login.htm) in ScadaBR 1.0CE allows a remote attacker to inject arbitr
MediumCVSS 6.1No exploitEPSS 1%scadabr · scadabrOct 14, 2019
- CVE-2019-1632124Monitor
ScadaBR 1.0CE, and 1.1.x through 1.1.0-RC, has XSS via a request for a nonexistent resource, as demonstrated by the dwr/test/ PATH_INFO.
MediumCVSS 6.1No exploitEPSS 1%scadabr · scadabrSep 15, 2019
- CVE-2026-964624Monitor
ScadaBR Unauthenticated Reflected Cross-Site Scripting
MediumCVSS 6.1No exploitEPSS 0%scadabr · scadabrMay 28, 2026
- CVE-2026-860520Monitor
Use of Hard-coded Credentials in ScadaBR
MediumCVSS 5.1No exploitEPSS 0%scadabr · scadabrMay 19, 2026
- CVE-2025-7097319Monitor
ScadaBR 1.12.4 is vulnerable to Session Fixation.
MediumCVSS 4.8No exploitEPSS 0%scadabr · scadabrMar 9, 2026