Записи openplcproject
13 опубликованных записей вендора openplcproject.
Профиль для исследователя
- Попали в KEV
- 0 · 0 %
- С эксплойтом
- 0 · 0 %
- Pre-auth RCE
- 1
- С записью об исправлении
- 0 %
- Медиана: публикация → KEV
- Ни одна запись не попала в KEV
Повторяющиеся классы
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')2
- CWE-125 Out-of-bounds Read2
- CWE-704 Incorrect Type Conversion or Cast2
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')1
- CWE-256 Plaintext Storage of a Password1
- CWE-862 Missing Authorization1
Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.
CWEВсе записи
13 записей| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
43В плане | CVE-2021-31630Proof of concept | Command Injection in Open PLC Webserver v3 allows remote attackers to execute arbitrary code via the "Hardware Layer Code Box" component on openplcproject · openplc v3 firmware · CWE-94 | Высокая8,8 | — | 27,1 % | 3 авг. 2021 г. |
40В плане | CVE-2024-34026Эксплойта нет | A stack-based buffer overflow vulnerability exists in the OpenPLC Runtime EtherNet/IP parser functionality of OpenPLC _v3 b4702061dc14d10248openplcproject · openplc v3 firmware · CWE-121 | Критическая9,8 | — | 2,4 % | 18 сент. 2024 г. |
39Наблюдать | CVE-2018-20818Эксплойта нет | A buffer overflow vulnerability was discovered in the OpenPLC controller, in the OpenPLC_v2 and OpenPLC_v3 versions.openplcproject · openplc v2 firmware · CWE-119 | Критическая9,8 | — | 1,5 % | 22 апр. 2019 г. |
36Наблюдать | CVE-2026-28205Эксплойта нет | Initialization of a resource with an insecure default in OpenPLC_V3openplcproject · openplc v3 firmware · CWE-1188 | Критическая9,2 | — | 0,7 % | 9 апр. 2026 г. |
36Наблюдать | CVE-2026-35556Эксплойта нет | Plaintext storage of a password in OpenPLC_V3openplcproject · openplc v3 firmware · CWE-256 | Критическая9,2 | — | 0,4 % | 9 апр. 2026 г. |
34Наблюдать | CVE-2026-35063Эксплойта нет | Missing Authorization in OpenPLC_V3openplcproject · openplc v3 firmware · CWE-862 | Высокая8,7 | — | 0,4 % | 9 апр. 2026 г. |
30Наблюдать | CVE-2024-36980Эксплойта нет | An out-of-bounds read vulnerability exists in the OpenPLC Runtime EtherNet/IP PCCC parser functionality of OpenPLC_v3 b4702061dc14d1024856f7openplcproject · openplc v3 firmware · CWE-125 | Высокая7,5 | — | 1,1 % | 18 сент. 2024 г. |
30Наблюдать | CVE-2024-39590Эксплойта нет | Multiple invalid pointer dereference vulnerabilities exist in the OpenPLC Runtime EtherNet/IP parser functionality of OpenPLC_v3 16bf8bac1a3openplcproject · openplc v3 firmware · CWE-704 | Высокая7,5 | — | 1,0 % | 18 сент. 2024 г. |
30Наблюдать | CVE-2024-36981Эксплойта нет | An out-of-bounds read vulnerability exists in the OpenPLC Runtime EtherNet/IP PCCC parser functionality of OpenPLC_v3 b4702061dc14d1024856f7openplcproject · openplc v3 firmware · CWE-125 | Высокая7,5 | — | 1,0 % | 18 сент. 2024 г. |
30Наблюдать | CVE-2024-39589Эксплойта нет | Multiple invalid pointer dereference vulnerabilities exist in the OpenPLC Runtime EtherNet/IP parser functionality of OpenPLC_v3 16bf8bac1a3openplcproject · openplc v3 firmware · CWE-704 | Высокая7,5 | — | 1,0 % | 18 сент. 2024 г. |
26Наблюдать | CVE-2026-31156Proof of concept | A path injection vulnerability exists in OpenPLC v3 (2c82b0e79c53f8c1f1458eee15fec173400d6e1a) as the binary program compiled from glue_geneopenplcproject · openplc v3 firmware · CWE-22 | Средняя6,5 | — | 0,5 % | 13 мая 2026 г. |
21Наблюдать | CVE-2021-3351Эксплойта нет | OpenPLC runtime V3 through 2016-03-14 allows stored XSS via the Device Name to the web server's Add New Device page.openplcproject · openplc · CWE-79 | Средняя5,4 | — | 0,5 % | 2 авг. 2021 г. |
21Наблюдать | CVE-2024-37741Эксплойта нет | OpenPLC 3 through 9cd8f1b allows XSS via an SVG document as a profile picture.openplcproject · openplc v3 firmware · CWE-79 | Средняя5,4 | — | 0,3 % | 28 июн. 2024 г. |
- CVE-2021-3163043В плане
Command Injection in Open PLC Webserver v3 allows remote attackers to execute arbitrary code via the "Hardware Layer Code Box" component on
ВысокаяCVSS 8,8Proof of conceptEPSS 27 %openplcproject · openplc v3 firmware3 авг. 2021 г.
- CVE-2024-3402640В плане
A stack-based buffer overflow vulnerability exists in the OpenPLC Runtime EtherNet/IP parser functionality of OpenPLC _v3 b4702061dc14d10248
КритическаяCVSS 9,8Эксплойта нетEPSS 2 %openplcproject · openplc v3 firmware18 сент. 2024 г.
- CVE-2018-2081839Наблюдать
A buffer overflow vulnerability was discovered in the OpenPLC controller, in the OpenPLC_v2 and OpenPLC_v3 versions.
КритическаяCVSS 9,8Эксплойта нетEPSS 2 %openplcproject · openplc v2 firmware22 апр. 2019 г.
- CVE-2026-2820536Наблюдать
Initialization of a resource with an insecure default in OpenPLC_V3
КритическаяCVSS 9,2Эксплойта нетEPSS 1 %openplcproject · openplc v3 firmware9 апр. 2026 г.
- CVE-2026-3555636Наблюдать
Plaintext storage of a password in OpenPLC_V3
КритическаяCVSS 9,2Эксплойта нетEPSS 0 %openplcproject · openplc v3 firmware9 апр. 2026 г.
- CVE-2026-3506334Наблюдать
Missing Authorization in OpenPLC_V3
ВысокаяCVSS 8,7Эксплойта нетEPSS 0 %openplcproject · openplc v3 firmware9 апр. 2026 г.
- CVE-2024-3698030Наблюдать
An out-of-bounds read vulnerability exists in the OpenPLC Runtime EtherNet/IP PCCC parser functionality of OpenPLC_v3 b4702061dc14d1024856f7
ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %openplcproject · openplc v3 firmware18 сент. 2024 г.
- CVE-2024-3959030Наблюдать
Multiple invalid pointer dereference vulnerabilities exist in the OpenPLC Runtime EtherNet/IP parser functionality of OpenPLC_v3 16bf8bac1a3
ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %openplcproject · openplc v3 firmware18 сент. 2024 г.
- CVE-2024-3698130Наблюдать
An out-of-bounds read vulnerability exists in the OpenPLC Runtime EtherNet/IP PCCC parser functionality of OpenPLC_v3 b4702061dc14d1024856f7
ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %openplcproject · openplc v3 firmware18 сент. 2024 г.
- CVE-2024-3958930Наблюдать
Multiple invalid pointer dereference vulnerabilities exist in the OpenPLC Runtime EtherNet/IP parser functionality of OpenPLC_v3 16bf8bac1a3
ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %openplcproject · openplc v3 firmware18 сент. 2024 г.
- CVE-2026-3115626Наблюдать
A path injection vulnerability exists in OpenPLC v3 (2c82b0e79c53f8c1f1458eee15fec173400d6e1a) as the binary program compiled from glue_gene
СредняяCVSS 6,5Proof of conceptEPSS 0 %openplcproject · openplc v3 firmware13 мая 2026 г.
- CVE-2021-335121Наблюдать
OpenPLC runtime V3 through 2016-03-14 allows stored XSS via the Device Name to the web server's Add New Device page.
СредняяCVSS 5,4Эксплойта нетEPSS 1 %openplcproject · openplc2 авг. 2021 г.
- CVE-2024-3774121Наблюдать
OpenPLC 3 through 9cd8f1b allows XSS via an SVG document as a profile picture.
СредняяCVSS 5,4Эксплойта нетEPSS 0 %openplcproject · openplc v3 firmware28 июн. 2024 г.