Vulnerabilities
Summary — last 7 days
New vulnerabilities2,732▼ 549 vs. last week
Critical / high1,295▼ 233 vs. last week
New active exploitation (KEV)3▼ 5 vs. last week
Unscored (no CVSS)244▼ 258 vs. last week
152 results, sorted by published date (most recent first)
| CVE | Status | Severity | EPSS | Active exploitation | Affected technologies | Published ▼ | Modified | Description |
|---|---|---|---|---|---|---|---|---|
| Analyzed | High (7.1) | 0.39% | — | Schneider-electric Struxureware Data Center Expert | 6/9/2026 | 7/20/2026 | CWE-611 Improper Restriction of XML External Entity Reference vulnerability exists that could cause information disclosure of server-side file contents when an attacker with a Data Center Expert user account submits crafted XML payloads to SOAP service endpoints. | |
| Analyzed | Medium (6.8) | 0.20% | — | Schneider-electric Ecostruxure Machine Expert Hvac | 5/14/2026 | 6/17/2026 | CWE-312: Cleartext Storage of Sensitive Information vulnerability exists that could cause the disclosure of a sensitive information which could result in revealing protected source code and loss of confidentiality, When an authorized attacker accesses the source code for editing or compiling it. | |
| Analyzed | High (8.2) | 0.49% | — | Schneider-electric Ecostruxure Panel Server Pas400 FirmwareSchneider-electric Ecostruxure Panel Server Pas600 FirmwareSchneider-electric Ecostruxure Panel Server Pas600v2 FirmwareSchneider-electric Ecostruxure Panel Server Pas800 Firmware+1 | 5/12/2026 | 6/24/2026 | CWE-1188 Initialization of a Resource with an Insecure Default vulnerability exists that could cause unauthorized disclosure of sensitive information when credentials revert to initial settings in rare circumstances, enabling unauthorized authentication using known credentials. | |
| Analyzed | High (7.2) | 0.24% | — | Schneider-electric Ecostruxure Automation Expert | 3/10/2026 | 6/23/2026 | CWE-94: Improper Control of Generation of Code ('Code Injection') vulnerability exist that could cause execution of untrusted commands on the engineering workstation which could result in a limited compromise of the workstation and a potential loss of Confidentiality, Integrity and Availability of the subsequent… | |
| Analyzed | High (7) | 0.33% | — | Schneider-electric Ecostruxure Foxboro DCS Control Software | 3/10/2026 | 6/24/2026 | CWE-502: Deserialization of untrusted data vulnerability exists that could lead to loss of confidentiality, integrity and potential remote code execution on workstation when an admin authenticated user opens a malicious project file. | |
| Analyzed | High (8.5) | 0.19% | — | Schneider-electric Ecostruxure Power Monitoring ExpertSchneider-electric Ecostruxure Power Operation | 3/10/2026 | 6/24/2026 | CWE‑502: Deserialization of Untrusted Data vulnerability exists that could cause arbitrary code execution with administrative privileges when a locally authenticated attacker sends a crafted data stream, triggering unsafe deserialization. | |
| Analyzed | High (8.4) | 0.35% | — | Schneider-electric Ecostruxure Power Build - Rapsody | 1/15/2026 | 9/3/2026 | CWE-416: Use After Free vulnerability that could cause remote code execution when the end user imports the malicious project file (SSD file) into Rapsody. | |
| Analyzed | High (8.4) | 0.16% | — | Schneider-electric Ecostruxure Power Build - Rapsody | 1/15/2026 | 9/3/2026 | CWE-415: Double Free vulnerability exists that could cause heap memory corruption when the end user imports a malicious project file (SSD file) shared by the attacker into Rapsody. | |
| Deferred | High (8.1) | 0.53% | — | Ancorathemes StruxAI | 12/18/2025 | 6/17/2026 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in AncoraThemes Strux strux allows PHP Local File Inclusion.This issue affects Strux: from n/a through <= 1.9. | |
| Analyzed | Critical (10) | 0.65% | — | Schneider-electric Ecostruxure IT Gateway | 11/13/2024 | 6/17/2026 | CWE-862: Missing Authorization vulnerability exists that could cause unauthorized access when enabled on the network and potentially impacting connected devices. | |
| Analyzed | High (7.8) | 0.21% | — | Schneider-electric Vijeo DesignerSchneider-electric Vijeo Designer Embedded IN Ecostruxure Machine Expert | 9/11/2024 | 6/17/2026 | CWE-269: Improper Privilege Management vulnerability exists that could cause unauthorized access, loss of confidentiality, integrity and availability of the workstation when non-admin authenticated user tries to perform privilege escalation by tampering with the binaries. | |
| Modified | High (7.8) | 0.24% | — | Schneider-electric Ecostruxure Foxboro DCS Control Core Services | 7/11/2024 | 6/17/2026 | CWE-20: Improper Input Validation vulnerability exists that could cause local denial-of-service, privilege escalation, and potentially kernel execution when a malicious actor with local user access crafts a script/program using an IOCTL call in the Foxboro.sys driver. | |
| Modified | Medium (5.5) | 0.15% | — | Schneider-electric Ecostruxure Foxboro DCS Control Core Services | 7/11/2024 | 6/17/2026 | CWE-129: Improper Validation of Array Index vulnerability exists that could cause local denial-of-service when a malicious actor with local user access crafts a script/program using an IOCTL call in the Foxboro.sys driver. | |
| Modified | High (7.1) | 0.15% | — | Schneider-electric Ecostruxure Foxboro DCS Control Core Services | 7/11/2024 | 6/17/2026 | CWE-787: Out-of-Bounds Write vulnerability exists that could cause local denial-of-service, or kernel memory leak when a malicious actor with local user access crafts a script/program using an IOCTL call in the Foxboro.sys driver. | |
| Modified | High (7.8) | 0.24% | — | Schneider-electric Ecostruxure IT Gateway | 6/12/2024 | 6/17/2026 | CWE-798: Use of hard-coded credentials vulnerability exists that could cause local privilege escalation when logged in as a non-administrative user. | |
| Analyzed | High (7.7) | 0.23% | — | Schneider-electric Ecostruxure Control ExpertSchneider-electric Ecostruxure Process Expert | 2/14/2024 | 6/17/2026 | CWE-798: Use of Hard-coded Credentials vulnerability exists that could cause unauthorized access to a project file protected with application password when opening the file with EcoStruxure Control Expert. | |
| Analyzed | High (8.1) | 0.32% | — | Schneider-electric Modicon M340 Bmxp341000 FirmwareSchneider-electric Modicon M340 Bmxp341000h FirmwareSchneider-electric Modicon M340 Bmxp342000 FirmwareSchneider-electric Modicon M340 Bmxp342010 Firmware+42 | 2/14/2024 | 6/17/2026 | CWE-924: Improper Enforcement of Message Integrity During Transmission in a Communication Channel vulnerability exists that could cause a denial of service and loss of confidentiality, integrity of controllers when conducting a Man in the Middle attack. | |
| Analyzed | High (7.1) | 0.15% | — | Schneider-electric Ecostruxure Control ExpertSchneider-electric Ecostruxure Process Expert | 2/14/2024 | 6/17/2026 | CWE-522: Insufficiently Protected Credentials vulnerability exists that could cause unauthorized access to the project file in EcoStruxure Control Expert when a local user tampers with the memory of the engineering workstation. | |
| Modified | Medium (6.1) | 0.41% | — | Schneider-electric Ecostruxure Power Monitoring Expert | 11/15/2023 | 6/17/2026 | A CWE-79 Improper Neutralization of Input During Web Page Generation (Cross-site Scripting) vulnerability that could cause a vulnerability leading to a cross site scripting condition where attackers can have a victim’s browser run arbitrary JavaScript when they visit a page containing the injected payload. | |
| Modified | Medium (6.1) | 0.45% | — | Schneider-electric Ecostruxure Power Monitoring Expert | 11/15/2023 | 6/17/2026 | A CWE-601 URL Redirection to Untrusted Site vulnerability exists that could cause an openredirect vulnerability leading to a cross site scripting attack. By providing a URL-encoded input attackers can cause the software’s web application to redirect to the chosen domain after a successful login is performed. | |
| Modified | Critical (9.8) | 0.92% | — | Schneider-electric Ecostruxure Power Monitoring ExpertSchneider-electric Ecostruxure Power Operation With Advanced ReportsSchneider-electric Ecostruxure Power Scada Operation With Advanced Reports | 10/4/2023 | 6/17/2026 | A CWE-502: Deserialization of untrusted data vulnerability exists that could allow an attacker to execute arbitrary code on the targeted system by sending a specifically crafted packet to the application. | |
| Modified | Medium (5.5) | 0.21% | — | Ecostruxure OPC UA Server Expert | 7/12/2023 | 6/17/2026 | A CWE-611: Improper Restriction of XML External Entity Reference vulnerability exists that could cause loss of confidentiality when replacing a project file on the local filesystem and after manual restart of the server. | |
| Modified | High (7.2) | 0.86% | — | Schneider-electric Struxureware Data Center Expert | 7/12/2023 | 6/17/2026 | A CWE-94: Improper Control of Generation of Code ('Code Injection') vulnerability exists that could cause remote code execution when an admin user on DCE tampers with backups which are then manually restored. | |
| Modified | High (7.2) | 0.86% | — | Schneider-electric Struxureware Data Center Expert | 7/12/2023 | 6/17/2026 | A CWE-94: Improper Control of Generation of Code ('Code Injection') vulnerability exists that could cause remote code execution when an admin user on DCE uploads or tampers with install packages. | |
| Modified | High (8.8) | 0.60% | — | Schneider-electric Struxureware Data Center Expert | 7/12/2023 | 6/17/2026 | A CWE-89: Improper Neutralization of Special Elements vulnerability used in an SQL Command ('SQL Injection') vulnerability exists that could allow a user already authenticated on DCE to access unauthorized content, change, or delete content, or perform unauthorized actions when tampering with the mass configuration… |