openplcproject records
13 published records for vendor openplcproject.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 1
- With a fix record
- 0%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')2
- CWE-125 Out-of-bounds Read2
- CWE-704 Incorrect Type Conversion or Cast2
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')1
- CWE-256 Plaintext Storage of a Password1
- CWE-862 Missing Authorization1
The weakness classes this vendor ships most often: where to look.
CWEAll records
13 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
43Plan | CVE-2021-31630Proof of concept | Command Injection in Open PLC Webserver v3 allows remote attackers to execute arbitrary code via the "Hardware Layer Code Box" component on openplcproject · openplc v3 firmware · CWE-94 | High8.8 | — | 27.1% | Aug 3, 2021 |
40Plan | CVE-2024-34026No exploit | A stack-based buffer overflow vulnerability exists in the OpenPLC Runtime EtherNet/IP parser functionality of OpenPLC _v3 b4702061dc14d10248openplcproject · openplc v3 firmware · CWE-121 | Critical9.8 | — | 2.4% | Sep 18, 2024 |
39Monitor | CVE-2018-20818No exploit | A buffer overflow vulnerability was discovered in the OpenPLC controller, in the OpenPLC_v2 and OpenPLC_v3 versions.openplcproject · openplc v2 firmware · CWE-119 | Critical9.8 | — | 1.5% | Apr 22, 2019 |
36Monitor | CVE-2026-28205No exploit | Initialization of a resource with an insecure default in OpenPLC_V3openplcproject · openplc v3 firmware · CWE-1188 | Critical9.2 | — | 0.7% | Apr 9, 2026 |
36Monitor | CVE-2026-35556No exploit | Plaintext storage of a password in OpenPLC_V3openplcproject · openplc v3 firmware · CWE-256 | Critical9.2 | — | 0.4% | Apr 9, 2026 |
34Monitor | CVE-2026-35063No exploit | Missing Authorization in OpenPLC_V3openplcproject · openplc v3 firmware · CWE-862 | High8.7 | — | 0.4% | Apr 9, 2026 |
30Monitor | CVE-2024-36980No exploit | An out-of-bounds read vulnerability exists in the OpenPLC Runtime EtherNet/IP PCCC parser functionality of OpenPLC_v3 b4702061dc14d1024856f7openplcproject · openplc v3 firmware · CWE-125 | High7.5 | — | 1.1% | Sep 18, 2024 |
30Monitor | CVE-2024-39590No exploit | Multiple invalid pointer dereference vulnerabilities exist in the OpenPLC Runtime EtherNet/IP parser functionality of OpenPLC_v3 16bf8bac1a3openplcproject · openplc v3 firmware · CWE-704 | High7.5 | — | 1.0% | Sep 18, 2024 |
30Monitor | CVE-2024-36981No exploit | An out-of-bounds read vulnerability exists in the OpenPLC Runtime EtherNet/IP PCCC parser functionality of OpenPLC_v3 b4702061dc14d1024856f7openplcproject · openplc v3 firmware · CWE-125 | High7.5 | — | 1.0% | Sep 18, 2024 |
30Monitor | CVE-2024-39589No exploit | Multiple invalid pointer dereference vulnerabilities exist in the OpenPLC Runtime EtherNet/IP parser functionality of OpenPLC_v3 16bf8bac1a3openplcproject · openplc v3 firmware · CWE-704 | High7.5 | — | 1.0% | Sep 18, 2024 |
26Monitor | CVE-2026-31156Proof of concept | A path injection vulnerability exists in OpenPLC v3 (2c82b0e79c53f8c1f1458eee15fec173400d6e1a) as the binary program compiled from glue_geneopenplcproject · openplc v3 firmware · CWE-22 | Medium6.5 | — | 0.5% | May 13, 2026 |
21Monitor | CVE-2021-3351No exploit | OpenPLC runtime V3 through 2016-03-14 allows stored XSS via the Device Name to the web server's Add New Device page.openplcproject · openplc · CWE-79 | Medium5.4 | — | 0.5% | Aug 2, 2021 |
21Monitor | CVE-2024-37741No exploit | OpenPLC 3 through 9cd8f1b allows XSS via an SVG document as a profile picture.openplcproject · openplc v3 firmware · CWE-79 | Medium5.4 | — | 0.3% | Jun 28, 2024 |
- CVE-2021-3163043Plan
Command Injection in Open PLC Webserver v3 allows remote attackers to execute arbitrary code via the "Hardware Layer Code Box" component on
HighCVSS 8.8Proof of conceptEPSS 27%openplcproject · openplc v3 firmwareAug 3, 2021
- CVE-2024-3402640Plan
A stack-based buffer overflow vulnerability exists in the OpenPLC Runtime EtherNet/IP parser functionality of OpenPLC _v3 b4702061dc14d10248
CriticalCVSS 9.8No exploitEPSS 2%openplcproject · openplc v3 firmwareSep 18, 2024
- CVE-2018-2081839Monitor
A buffer overflow vulnerability was discovered in the OpenPLC controller, in the OpenPLC_v2 and OpenPLC_v3 versions.
CriticalCVSS 9.8No exploitEPSS 2%openplcproject · openplc v2 firmwareApr 22, 2019
- CVE-2026-2820536Monitor
Initialization of a resource with an insecure default in OpenPLC_V3
CriticalCVSS 9.2No exploitEPSS 1%openplcproject · openplc v3 firmwareApr 9, 2026
- CVE-2026-3555636Monitor
Plaintext storage of a password in OpenPLC_V3
CriticalCVSS 9.2No exploitEPSS 0%openplcproject · openplc v3 firmwareApr 9, 2026
- CVE-2026-3506334Monitor
Missing Authorization in OpenPLC_V3
HighCVSS 8.7No exploitEPSS 0%openplcproject · openplc v3 firmwareApr 9, 2026
- CVE-2024-3698030Monitor
An out-of-bounds read vulnerability exists in the OpenPLC Runtime EtherNet/IP PCCC parser functionality of OpenPLC_v3 b4702061dc14d1024856f7
HighCVSS 7.5No exploitEPSS 1%openplcproject · openplc v3 firmwareSep 18, 2024
- CVE-2024-3959030Monitor
Multiple invalid pointer dereference vulnerabilities exist in the OpenPLC Runtime EtherNet/IP parser functionality of OpenPLC_v3 16bf8bac1a3
HighCVSS 7.5No exploitEPSS 1%openplcproject · openplc v3 firmwareSep 18, 2024
- CVE-2024-3698130Monitor
An out-of-bounds read vulnerability exists in the OpenPLC Runtime EtherNet/IP PCCC parser functionality of OpenPLC_v3 b4702061dc14d1024856f7
HighCVSS 7.5No exploitEPSS 1%openplcproject · openplc v3 firmwareSep 18, 2024
- CVE-2024-3958930Monitor
Multiple invalid pointer dereference vulnerabilities exist in the OpenPLC Runtime EtherNet/IP parser functionality of OpenPLC_v3 16bf8bac1a3
HighCVSS 7.5No exploitEPSS 1%openplcproject · openplc v3 firmwareSep 18, 2024
- CVE-2026-3115626Monitor
A path injection vulnerability exists in OpenPLC v3 (2c82b0e79c53f8c1f1458eee15fec173400d6e1a) as the binary program compiled from glue_gene
MediumCVSS 6.5Proof of conceptEPSS 0%openplcproject · openplc v3 firmwareMay 13, 2026
- CVE-2021-335121Monitor
OpenPLC runtime V3 through 2016-03-14 allows stored XSS via the Device Name to the web server's Add New Device page.
MediumCVSS 5.4No exploitEPSS 1%openplcproject · openplcAug 2, 2021
- CVE-2024-3774121Monitor
OpenPLC 3 through 9cd8f1b allows XSS via an SVG document as a profile picture.
MediumCVSS 5.4No exploitEPSS 0%openplcproject · openplc v3 firmwareJun 28, 2024