| 07.08.2026 | CVE-2025-71411 | Simultaneous Disconnection of Multiple Aircraft via Broadcast Control Frames | ATN-B1 / CPDLC (Controller-Pilot Data Link Communications) | Medium 5.3 |
| 07.08.2026 | CVE-2025-71413 | Repeated Session Resets from Malformed or Out-of-Sequence Frames | ATN-B1 / CPDLC (Controller-Pilot Data Link Communications) | Medium 5.3 |
| 07.08.2026 | CVE-2025-71409 | Missing Authentication for Critical Function in VDL Messages | ATN-B1 / CPDLC (Controller-Pilot Data Link Communications) | High 7.1 |
| 07.08.2026 | CVE-2025-71410 | Loss of CPDLC Functions via Malicious Link Control Frames | ATN-B1 / CPDLC (Controller-Pilot Data Link Communications) | Medium 5.3 |
| 07.08.2026 | CVE-2025-71412 | False Emergency or Status Messages Accepted as Legitimate | ATN-B1 / CPDLC (Controller-Pilot Data Link Communications) | High 7.1 |
| 24.07.2026 | CVE-2026-55731 | Unchecked Input for Loop Condition in the SNMP Agent | Loytec / L-INX, L-GATE, L-ROC, L-IOB, L-DALI, L-VIS, L-PAD, LIP-ME20xC | Medium 6.6 |
| 24.07.2026 | CVE-2026-12496 | Unauthenticated Stored Cross-Site Scripting in the OPC XML-DA Server | Loytec / L-INX, L-GATE, L-ROC, L-IOB, L-DALI, L-VIS, L-PAD, LIP-ME20xC | High 8.7 |
| 24.07.2026 | CVE-2026-55728 | Stack-based Buffer Overflow in cmd_ipaddr_conflict | Loytec / L-INX, L-GATE, L-ROC, L-IOB, L-DALI, L-VIS, L-PAD, LIP-ME20xC | Low 3.8 |
| 24.07.2026 | CVE-2026-55730 | Reflected Cross-Site Scripting | Loytec / LWEB-802 | High 8.7 |
| 24.07.2026 | CVE-2026-55732 | Out-of-bounds Read in BACnet Packet Parsing | Loytec / L-INX, L-GATE, L-ROC, L-IOB, L-DALI, L-VIS, L-PAD, LIP-ME20xC | High 8.7 |
| 24.07.2026 | CVE-2026-12502 | Improper Privilege Management in /usr/bin/ltsudo | Loytec / L-INX, L-GATE, L-ROC, L-IOB, L-DALI, L-VIS, L-PAD, LIP-ME20xC | High 8.4 |
| 24.07.2026 | CVE-2026-12503 | Improper Link Resolution in /usr/bin/larm_starter | Loytec / L-INX, L-GATE, L-ROC, L-IOB, L-DALI, L-VIS, L-PAD, LIP-ME20xC | Critical 9.2 |
| 24.07.2026 | CVE-2026-12504 | Improper Authentication in PAM Configuration | Loytec / L-INX, L-GATE, L-ROC, L-IOB, L-DALI, L-VIS, L-PAD, LIP-ME20xC | High 8.4 |
| 24.07.2026 | CVE-2026-55729 | Exposure of Sensitive Information in Browser localStorage | Loytec / LWEB-802 | High 7.7 |
| 03.06.2026 | CVE-2026-35075 | Use of Default Password for Service Account | MBS / UGW Universal Gateway (A-Series, X-Series) | Critical 9.8 |
| 03.06.2026 | CVE-2026-35085 | Stack-based Buffer Overflow in the gdv-serverconfig Method | MBS / UGW Universal Gateway (A-Series, X-Series) | High 8.8 |
| 03.06.2026 | CVE-2026-35084 | Stack-based Buffer Overflow in the dali-devconfig Method | MBS / UGW Universal Gateway (A-Series, X-Series) | High 8.8 |
| 03.06.2026 | CVE-2026-35083 | Stack-based Buffer Overflow in the bac-deviceobject Method | MBS / UGW Universal Gateway (A-Series, X-Series) | High 8.8 |
| 03.06.2026 | CVE-2026-35082 | Path Traversal in the ugw-logread Method | MBS / UGW Universal Gateway (A-Series, X-Series) | High 8.8 |
| 03.06.2026 | CVE-2026-35081 | Arbitrary Process Termination in the ugw-logstop Method | MBS / UGW Universal Gateway (A-Series, X-Series) | High 8.1 |
| 03.06.2026 | CVE-2026-35080 | Arbitrary File Deletion in the ugw-restoreinfo Method | MBS / UGW Universal Gateway (A-Series, X-Series) | High 8.1 |
| 03.06.2026 | CVE-2026-35079 | Arbitrary File Deletion in the ugw-restore Method | MBS / UGW Universal Gateway (A-Series, X-Series) | High 8.1 |
| 03.06.2026 | CVE-2026-35078 | Arbitrary File Deletion in the ugw-logstop Method | MBS / UGW Universal Gateway (A-Series, X-Series) | High 8.1 |
| 03.06.2026 | CVE-2026-35077 | Arbitrary File Deletion in the ugw-delete-file Method | MBS / UGW Universal Gateway (A-Series, X-Series) | High 8.1 |
| 03.06.2026 | CVE-2026-35076 | Arbitrary File Deletion in the bac-scanresult Method | MBS / UGW Universal Gateway (A-Series, X-Series) | High 8.1 |
| 10.12.2025 | CVE-2025-41732 | Stack-based Buffer Overflow | Wago / Industrial-Managed-Switches | Critical 9.8 |
| 10.12.2025 | CVE-2025-41730 | Remote stack buffer overflow | Wago / Managed Switch - Web Server | Critical 9.8 |
| 22.10.2025 | CVE-2025-41722 | Use of Hard-coded Credentials | Sauter / modulo 6 devices modu680-AS | High 7.5 |
| 22.10.2025 | CVE-2025-41720 | Reliance on File Name or Extension of Externally-Supplied File | Sauter / modulo 6 devices modu680-AS | Medium 4.3 |
| 22.10.2025 | CVE-2025-41723 | Path Traversal: '.../...//' | Sauter / modulo 6 devices modu680-AS | Critical 9.8 |
| 22.10.2025 | CVE-2025-41719 | Improper Validation of Syntactic Correctness of Input | Sauter / modulo 6 devices modu680-AS | High 8.8 |
| 22.10.2025 | CVE-2025-41721 | Improper Neutralization of Special Elements used in a Command ('Command Injection') | Sauter / modulo 6 devices modu680-AS | Low 2.8 |
| 22.10.2025 | CVE-2025-41724 | Failure to Handle Incomplete Element | Sauter / modulo 6 devices modu680-AS | High 7.5 |
| 24.06.2025 | CVE-2025-1718 | Reboot Vulnerability | HITACHI / Energy Monitoring | Medium 6.5 |
| 17.01.2025 | CVE-2024-13502 | Improper Neutralization of Special Elements | Newtec/iDirect / VSAT Modems | Critical 9.3 |
| 17.01.2025 | CVE-2024-13503 | Buffer Copy without Checking Size of Input | iDirect / VSAT Modems | Critical 9.5 |
| 01.01.2025 | | Traffic Alert and Collision Avoidance System (TCAS) II | Multiple Companies / TCAS II - Collision Avoidance Systems | High 8.2 |
| 01.01.2025 | | Stack buffer overflow | ATOP / Industrial-Managed-Switches | High 8.0 |
| 01.09.2024 | | UBR-01 Mk2 | MBS Systems | Medium 5.3 |
| 01.09.2024 | | UBR-01 Mk2 | MBS Systems | Medium 6.6 |
| 01.09.2024 | | UBR-01 Mk2 | MBS Systems | Medium 6.5 |
| 01.09.2024 | | UBR-01 Mk2 | MBS Systems | High 7.2 |
| 01.09.2024 | | UBR-01 Mk2 | MBS Systems | Critical 9.4 |
| 06.08.2024 | CVE-2024-6203 | HaloITSM | Halo Service Solutions | High 8.3 |
| 06.08.2024 | CVE-2024-6202 | HaloITSM | Halo Service Solutions | Critical 9.8 |
| 06.08.2024 | CVE-2024-6201 | HaloITSM | Halo Service Solutions | Medium 5.3 |
| 06.08.2024 | CVE-2024-6200 | HaloITSM | Halo Service Solutions | High 8.0 |
| 01.08.2024 | | DNS Unbound, PowerDNS, Bind | | Medium 5.9 |
| 01.08.2024 | | ActaNova | Rubicon | High 7.4 |
| 10.05.2024 | CVE-2024-27460 | Plantronics Hub | Plantronics | High 7.8 |
| 01.11.2023 | CVE-2023-41840 | FortiClient (Windows) | | High 7.4 |
| 01.10.2023 | CVE-2022-40681 | FortiClient (Windows) | | High 7.1 |
| 01.10.2023 | CVE-2023-47113 | Bleachbit | | High 7.8 |
| 01.09.2023 | CVE-2023-36659 | OPSWAT MetaDefender Kiosk | | Medium 6.2 |
| 01.09.2023 | CVE-2023-36657 | OPSWAT MetaDefender Kiosk | | Medium 5.9 |
| 01.04.2023 | | Sharekey (19 vulnerabilities) | | Critical 10.0 |
| 01.04.2023 | CVE-2022-40682 | Fortiguard | | High 7.1 |
| 01.12.2022 | CVE-2022-4779 | Elvexys StreamX | | High 7.5 |
| 01.12.2022 | CVE-2022-4778 | Elvexys StreamX | | Medium 6.5 |
| 01.12.2022 | CVE-2022-4780 | Elvexys ISOS | | Medium 4.5 |
| 01.09.2022 | | Plantronics Hub | | High 7.8 |
| 01.09.2022 | | e*** | | Critical 10.0 |
| 01.05.2022 | CVE-2022-43996 | CSAF Provider | | Medium 6.2 |
| 01.03.2022 | CVE-2022-27193 | CVRF-CSAF-Converter | | Medium 5.7 |
| 01.02.2022 | CVE-2022-0878 | Combined Charging System (CCS) | | Medium 6.5 |