Vulnerabilities (CVE)

Filtered by vendor Openplcproject Subscribe
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2021-31630 1 Openplcproject 2 Openplc V3, Openplc V3 Firmware 2022-05-03 9.0 HIGH 8.8 HIGH
Command Injection in Open PLC Webserver v3 allows remote attackers to execute arbitrary code via the "Hardware Layer Code Box" component on the "/hardware" page of the application.
CVE-2021-26828 1 Openplcproject 1 Scadabr 2021-06-21 6.5 MEDIUM 8.8 HIGH
OpenPLC ScadaBR through 0.9.1 on Linux and through 1.12.4 on Windows allows remote authenticated users to upload and execute arbitrary JSP files via view_edit.shtm.