Vulnerabilities
Summary — last 7 days
New vulnerabilities3,029▼ 65 vs. last week
Critical / high1,425▲ 60 vs. last week
New active exploitation (KEV)4▼ 5 vs. last week
Unscored (no CVSS)382▼ 128 vs. last week
2 results, sorted by published date (most recent first)
| CVE | Status | Severity | EPSS | Active exploitation | Affected technologies | Published ▼ | Modified | Description |
|---|---|---|---|---|---|---|---|---|
| Modified | Critical (9.1) | 0.91% | — | Omron Cj1g-cpu45p FirmwareOmron Cj1g-cpu45p-gtc FirmwareOmron Cj1g-cpu44p FirmwareOmron Cj1g-cpu43p Firmware+42 | 1/22/2024 | 6/17/2026 | The Omron FINS protocol has an authenticated feature to prevent access to memory regions. Authentication is susceptible to bruteforce attack, which may allow an adversary to gain access to protected memory. This access can allow overwrite of values including programmed logic. | |
| Modified | High (7.5) | 0.54% | — | Omron Sysmac Cj2h-cpu64-eip FirmwareOmron Sysmac Cj2h-cpu64 FirmwareOmron Sysmac Cj2h-cpu65-eip FirmwareOmron Sysmac Cj2h-cpu65 Firmware+37 | 1/10/2024 | 6/17/2026 | An attacker with network access to the affected PLC (CJ-series and CS-series PLCs, all versions) may use a network protocol to read and write files on the PLC internal memory and memory card. |