Skip to content
Noroxi

siemens records

2,243 published records for vendor siemens.

Researcher profile

Entered KEV
29 · 1.3%
Weaponized
38 · 1.7%
Pre-auth RCE
108
With a fix record
10.1%
Median publish → KEV
150 days

All records

2,243 records
  • Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints

    CriticalCVSS 10.0KEVWeaponizedEPSS 100%

    apache · log4jDec 10, 2021

  • A remote code execution vulnerability exists in Remote Desktop Services formerly known as Terminal Services when an unauthenticated attacker

    CriticalCVSS 9.8KEVWeaponizedEPSS 100%

    microsoft · windows 7May 16, 2019

  • A Spring MVC or Spring WebFlux application running on JDK 9+ may be vulnerable to remote code execution (RCE) via data binding.

    CriticalCVSS 9.8KEVWeaponizedEPSS 100%

    vmware · spring frameworkApr 1, 2022

  • An unprivileged network attacker could gain system privileges to provisioned Intel manageability SKUs: Intel Active Management Technology (A

    CriticalCVSS 9.8KEVWeaponizedEPSS 92%

    intel · active management technology firmwareMay 2, 2017

  • A crafted request uri-path can cause mod_proxy to forward the request to an origin server choosen by the remote user.

    CriticalCVSS 9.0KEVWeaponizedEPSS 100%

    resf · rocky linuxSep 16, 2021

  • Apache Log4j2 Thread Context Message Pattern and Context Lookup Pattern vulnerable to a denial of service attack

    CriticalCVSS 9.0KEVWeaponizedEPSS 100%

    apache · log4jDec 14, 2021

  • The SMBv1 server in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows Server 2012 Gold an

    HighCVSS 8.8KEVWeaponizedEPSS 99%

    microsoft · server message blockMar 16, 2017

  • An Authentication Bypass Using an Alternate Path or Channel vulnerability [CWE-288] vulnerability in Fortinet FortiAnalyzer 7.6.0 through 7.

    CriticalCVSS 9.8KEVWeaponizedEPSS 86%

    fortinet · fortianalyzerJan 27, 2026

  • The SMBv1 server in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows Server 2012 Gold an

    HighCVSS 8.8KEVWeaponizedEPSS 93%

    microsoft · server message blockMar 16, 2017

  • The SMBv1 server in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows Server 2012 Gold an

    HighCVSS 8.1KEVWeaponizedEPSS 99%

    microsoft · server message blockMar 16, 2017

  • The SMBv1 server in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows Server 2012 Gold an

    HighCVSS 8.8KEVWeaponizedEPSS 90%

    microsoft · server message blockMar 16, 2017

  • The SMBv1 server in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows Server 2012 Gold an

    HighCVSS 8.8KEVWeaponizedEPSS 90%

    microsoft · server message blockMar 16, 2017

  • The (1) TLS and (2) DTLS implementations in OpenSSL 1.0.1 before 1.0.1g do not properly handle Heartbeat Extension packets, which allows rem

    HighCVSS 7.5KEVWeaponizedEPSS 100%

    openssl · opensslApr 7, 2014

  • The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many streams quickly, as

    HighCVSS 7.5KEVWeaponizedEPSS 100%

    siemens · simatic s7-1500 cpu 1518f-4 pn\/dp mfp firmwareOct 10, 2023

  • The SMBv1 server in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows Server 2012 Gold an

    HighCVSS 7.5KEVWeaponizedEPSS 100%

    microsoft · windows 10 1507Mar 16, 2017

  • PAN-OS: GlobalProtect Authentication Bypass Vulnerabilities

    HighCVSS 7.8KEVWeaponizedEPSS 96%

    paloaltonetworks · pan-osMay 13, 2026

  • A local privilege escalation vulnerability was found on polkit's pkexec utility.

    HighCVSS 7.8KEVWeaponizedEPSS 94%

    polkit project · polkitJan 28, 2022

  • A flaw was found in the way the "flags" member of the new pipe buffer structure was lacking proper initialization in copy_page_to_iter_pipe

    HighCVSS 7.8KEVWeaponizedEPSS 93%

    linux · linux kernelMar 10, 2022

  • A improper verification of cryptographic signature vulnerability in Fortinet FortiOS 7.6.0 through 7.6.3, FortiOS 7.4.0 through 7.4.8, Forti

    CriticalCVSS 9.8KEVWeaponizedEPSS 68%

    fortinet · fortiproxyDec 9, 2025

  • Glibc: buffer overflow in ld.so leading to privilege escalation

    HighCVSS 7.8KEVWeaponizedEPSS 81%

    gnu · glibcOct 3, 2023

  • CVE-2026-0300
    77This week

    PAN-OS: Unauthenticated user initiated Buffer Overflow Vulnerability in User-ID™ Authentication Portal

    CriticalCVSS 9.3KEVWeaponizedEPSS 32%

    paloaltonetworks · pan-osMay 6, 2026

  • CVE-2025-10585
    71This week

    Type confusion in V8 in Google Chrome prior to 140.0.7339.185 allowed a remote attacker to potentially exploit heap corruption via a crafted

    CriticalCVSS 9.8KEVWeaponizedEPSS 5%

    google · chromeSep 24, 2025

  • CVE-2025-25249
    70This week

    A heap-based buffer overflow vulnerability in Fortinet FortiOS 7.6.0 through 7.6.3, FortiOS 7.4.0 through 7.4.8, FortiOS 7.2.0 through 7.2.1

    CriticalCVSS 9.8KEVWeaponizedEPSS 4%

    fortinet · fortiosJan 13, 2026

  • CVE-2025-39682
    70This week

    tls: fix handling of zero-length records on the rx_list

    CriticalCVSS 9.8KEVWeaponizedEPSS 3%

    linux · linux kernelSep 5, 2025

  • CVE-2025-13223
    67This week

    Type Confusion in V8 in Google Chrome prior to 142.0.7444.175 allowed a remote attacker to potentially exploit heap corruption via a crafted

    HighCVSS 8.8KEVWeaponizedEPSS 5%

    google · chromeNov 17, 2025