Network and edge
Industrial and building systems
PLCs, industrial control (SCADA), building automation and physical access control.
For example: Siemens, Rockwell, Schneider Electric, Unitronics.
-
5 vulnerabilities added in the last 12 months
-
17 exploited vulnerabilities in the catalog, in total
-
0 added in the last 30 days
Affected brands
In alphabetical order, with their number of vulnerabilities in this category.
- Audinate 1 vulnerability
- CONTEC (SolarView) 1 vulnerability
- Crestron 1 vulnerability
- Delta Electronics 1 vulnerability
- InduSoft 1 vulnerability
- KNX Association 1 vulnerability · 1 in the last 12 months
- Lantronix 1 vulnerability · 1 in the last 12 months
- Nice (Linear) 1 vulnerability
- OpenPLC 2 vulnerabilities · 2 in the last 12 months
- Rockwell Automation 1 vulnerability · 1 in the last 12 months
- Schneider Electric 1 vulnerability
- Siemens 1 vulnerability
- Sunhillo 1 vulnerability
- Trihedral 1 vulnerability
- Unitronics 1 vulnerability
- ZKTeco 1 vulnerability
A high count also reflects how widely a product is deployed and how much attackers care about it: it is not a security rating.
See also
- Home and small-office routers, cameras and IoT 90 vulnerabilities
Patch first
In the order of the main list (Patch first): recent additions first, then the most severe. The number is the rank within this category.
- Rank 1
Lantronix EDS5000CVE-2025-67038
Lantronix EDS5000 Code Injection Vulnerability
CVSS severity 9.8critical
Added Jun 23, 2026
- Rank 2
Rockwell Automation Logix (PLCs, Studio 5000)CVE-2021-22681
Rockwell Multiple Products Insufficient Protected Credentials Vulnerability
CVE from 2021, added in 2026
CVSS severity 9.8critical
Added Mar 5, 2026
- Rank 3
OpenPLC ScadaBRCVE-2021-26828
OpenPLC ScadaBR Unrestricted Upload of File with Dangerous Type Vulnerability
CVE from 2021, added in 2025
CVSS severity 8.8high
Added Dec 3, 2025
- Rank 4
KNX Association Protocole KNXCVE-2023-4346
KNX Association KNX Protocol Connection Authorization Option 1 Overly Restrictive Account Lockout Mechanism Vulnerability
CVE from 2023, added in 2026
CVSS severity 7.5high
Added Jul 15, 2026
- Rank 5
OpenPLC ScadaBRCVE-2021-26829
OpenPLC ScadaBR Cross-site Scripting Vulnerability
CVE from 2021, added in 2025
CVSS severity 5.4medium
Added Nov 28, 2025
- Rank 6
Nice (Linear) Linear eMerge E3-SeriesCVE-2019-7256
Nice Linear eMerge E3-Series OS Command Injection Vulnerability
CVE from 2019, added in 2024
CVSS severity 9.8critical
Added Mar 25, 2024
- Rank 7
Sunhillo SureLineCVE-2021-36380
Sunhillo SureLine OS Command Injection Vulnerablity
CVE from 2021, added in 2024
CVSS severity 9.8critical
Added Mar 5, 2024
- Rank 8
Unitronics Vision PLC and HMICVE-2023-6448
Unitronics Vision PLC and HMI Insecure Default Password Vulnerability
CVSS severity 9.8critical
Added Dec 11, 2023
- Rank 9
CONTEC (SolarView) SolarView CompactCVE-2022-29303
SolarView Compact Command Injection Vulnerability
CVSS severity 9.8critical
Added Jul 13, 2023
- Rank 10
InduSoft Web StudioCVE-2014-0780
InduSoft Web Studio NTWebServer Directory Traversal Vulnerability
CVE from 2014, added in 2022
CVSS severity 9.8critical
Added Apr 15, 2022
Show 5 more vulnerabilities
- Rank 11
Crestron AirMedia (AM-100, AM-101)CVE-2019-3929
Crestron Multiple Products Command Injection Vulnerability
CVE from 2019, added in 2022
CVSS severity 9.8critical
Added Apr 15, 2022
- Rank 12
Audinate Dante DiscoveryCVE-2022-23748
Dante Discovery Process Control Vulnerability
CVE from 2022, added in 2025
CVSS severity 7.8high
Added Feb 6, 2025
- Rank 13
ZKTeco BioTimeCVE-2023-38950
ZKTeco BioTime Path Traversal Vulnerability
CVE from 2023, added in 2025
CVSS severity 7.5high
Added May 19, 2025
- Rank 14
Trihedral VTScada (formerly VTS)CVE-2016-4523
Trihedral VTScada (formerly VTS) Denial-of-Service Vulnerability
CVE from 2016, added in 2022
CVSS severity 7.5high
Added Apr 15, 2022
- Rank 15
Siemens SIMATIC CPCVE-2016-8562
Siemens SIMATIC CP 1543-1 Improper Privilege Management Vulnerability
CVE from 2016, added in 2022
CVSS severity 7.5high
Added Mar 3, 2022
End of life: remove
These products are no longer supported: no patch is coming. Remove them or isolate them from the network.
Delta Electronics DOPSoft 2CVE-2021-38406
Delta Electronics DOPSoft 2 Improper Input Validation Vulnerability
End of life
CVSS severity 7.8high
Added Aug 25, 2022
Schneider Electric U.motion BuilderCVE-2018-7841
Schneider Electric U.motion Builder SQL Injection Vulnerability
End of lifeCVE from 2018, added in 2022
CVSS severity 9.8critical
Added Apr 15, 2022
Follow and verify
Get new vulnerabilities in this category: RSS feed (add it to Outlook, Teams, Slack or your feed reader).
Indicative classification, based on the vendor and product names given by CISA. How products are classified.