Vulnerabilities
Summary — last 7 days
New vulnerabilities2,952▲ 10 vs. last week
Critical / high1,451▲ 185 vs. last week
New active exploitation (KEV)5▼ 3 vs. last week
Unscored (no CVSS)272▼ 254 vs. last week
2 results, sorted by published date (most recent first)
| CVE | Status | Severity | EPSS | Active exploitation | Affected technologies | Published ▼ | Modified | Description |
|---|---|---|---|---|---|---|---|---|
| Modified | Medium (6.5) | 0.83% | — | Endress Rsg35 FirmwareEndress Rsg45 FirmwareEndress Orsg35 FirmwareEndress Orsg45 Firmware | 11/19/2020 | 6/17/2026 | Endress+Hauser Ecograph T (Neutral/Private Label) (RSG35, ORSG35) and Memograph M (Neutral/Private Label) (RSG45, ORSG45) with Firmware version V2.0.0 and above is prone to exposure of sensitive information to an unauthorized actor. The firmware release has a dynamic token for each request submitted to the server,… | |
| Modified | High (8.8) | 0.92% | — | Endress Rsg35 FirmwareEndress Rsg45 FirmwareEndress Orsg35 FirmwareEndress Orsg45 Firmware | 11/19/2020 | 6/17/2026 | Endress+Hauser Ecograph T (Neutral/Private Label) (RSG35, ORSG35) with Firmware version prior to V2.0.0 is prone to improper privilege management. The affected device has a web-based user interface with a role-based access system. Users with different roles have different write and read privileges. The access system… |