Skip to content
Signals
NVD · CVE-2026-64604 · In the Linux kernel, the following vulnerability has been resolved: KVM: VMX: Grab vmcs12 on CR8 interception update iff vCPU is in guest mode When updating CR8NVD · CVE-2026-64603 · In the Linux kernel, the following vulnerability has been resolved: platform/x86: intel-hid: Protect ACPI notify handler against recursion Since commit e2ffcda1NVD · CVE-2026-64602 · In the Linux kernel, the following vulnerability has been resolved: iio: adc: spear: Initialize completion before requesting IRQ In the report from Jaeyoung ChuNVD · CVE-2026-64601 · In the Linux kernel, the following vulnerability has been resolved: ALSA: us144mkii: capture_urb_complete: redundant usb_anchor_urb corrupts anchor list on eachCISA KEV · CVE-2026-63077 · 9.8 · JetBrains TeamCity Deserialization of Untrusted Data Vulnerability · Added 2026-08-05 · Due 2026-08-08CISA KEV · CVE-2026-18556 · 7.4 · N-able N-central Authentication Bypass Using an Alternate Path or Channel Vulnerability · Added 2026-08-04 · Due 2026-08-07NVD · CVE-2026-64604 · In the Linux kernel, the following vulnerability has been resolved: KVM: VMX: Grab vmcs12 on CR8 interception update iff vCPU is in guest mode When updating CR8NVD · CVE-2026-64603 · In the Linux kernel, the following vulnerability has been resolved: platform/x86: intel-hid: Protect ACPI notify handler against recursion Since commit e2ffcda1NVD · CVE-2026-64602 · In the Linux kernel, the following vulnerability has been resolved: iio: adc: spear: Initialize completion before requesting IRQ In the report from Jaeyoung ChuNVD · CVE-2026-64601 · In the Linux kernel, the following vulnerability has been resolved: ALSA: us144mkii: capture_urb_complete: redundant usb_anchor_urb corrupts anchor list on eachCISA KEV · CVE-2026-63077 · 9.8 · JetBrains TeamCity Deserialization of Untrusted Data Vulnerability · Added 2026-08-05 · Due 2026-08-08CISA KEV · CVE-2026-18556 · 7.4 · N-able N-central Authentication Bypass Using an Alternate Path or Channel Vulnerability · Added 2026-08-04 · Due 2026-08-07

Vendors · eaton

eaton

· 2 Critical

Total CVEs

54

Critical

2

Products

90

Search All CVEs →

54

Products (90)

intelligent power protector12 CVEsintelligent power manager12 CVEsintelligent power manager virtual appliance5 CVEseasysoft4 CVEsups companion4 CVEsforeseer electrical power monitoring system4 CVEs9px ups3 CVEs9px ups firmware3 CVEselcsoft3 CVEsxcomfort ethernet communication interface2 CVEshmisoft vu32 CVEshmisoft vu3 firmware2 CVEsproview2 CVEseasy-box-e4-uc11 CVEseasy-box-e4-uc1 firmware1 CVEseasy-e4-ac-12rc1p1 CVEseasy-e4-ac-12rc1p firmware1 CVEseasy-e4-ac-12rcx1p1 CVEseasy-e4-ac-12rcx1p firmware1 CVEseasy-e4-ac-16re1p1 CVEseasy-e4-ac-16re1p firmware1 CVEseasy-e4-dc-12tc1p1 CVEseasy-e4-dc-12tc1p firmware1 CVEseasy-e4-dc-12tcx1p1 CVEseasy-e4-dc-12tcx1p firmware1 CVEseasy-e4-dc-16te1p1 CVEseasy-e4-dc-16te1p firmware1 CVEseasy-e4-dc-4pe1p1 CVEseasy-e4-dc-4pe1p firmware1 CVEseasy-e4-dc-6ae1p1 CVEseasy-e4-dc-6ae1p firmware1 CVEseasy-e4-dc-8te1p1 CVEseasy-e4-dc-8te1p firmware1 CVEseasy-e4-uc-12rc1p1 CVEseasy-e4-uc-12rc1p firmware1 CVEseasy-e4-uc-12rcx1p1 CVEseasy-e4-uc-12rcx1p firmware1 CVEseasy-e4-uc-16re11 CVEseasy-e4-uc-16re1 firmware1 CVEseasy-e4-uc-16re1p1 CVEseasy-e4-uc-16re1p firmware1 CVEseasy-e4-uc-8re1p1 CVEseasy-e4-uc-8re1p firmware1 CVEseasy e4-ac-8re1p1 CVEseasy e4-ac-8re1p firmware1 CVEsemaaxx series epdu1 CVEsemaaxx series epdu firmware1 CVEsemaxxx series epdu1 CVEsemaxxx series epdu firmware1 CVEseswaxx series epdu1 CVEseswaxx series epdu firmware1 CVEshalo home1 CVEsintelligent power manager infrastructure1 CVEsnetwork shutdown module1 CVEspower xpert meter 40001 CVEspower xpert meter 4000 firmware1 CVEspower xpert meter 60001 CVEspower xpert meter 6000 firmware1 CVEspower xpert meter 80001 CVEspower xpert meter 8000 firmware1 CVEssecureconnect1 CVEssmp 161 CVEssmp 16 firmware1 CVEssmp 4\/dp1 CVEssmp 4\/dp firmware1 CVEssmp sg-42501 CVEssmp sg-4250 firmware1 CVEssmp sg-42601 CVEssmp sg-4260 firmware1 CVEsxv-102-a035tqrb-1e41 CVEsxv-102-a035tqrb-1e4 firmware1 CVEsxv-102-a3-57tvrb-1e41 CVEsxv-102-a3-57tvrb-1e4 firmware1 CVEsxv100-box-e4-dc11 CVEsxv100-box-e4-dc1 firmware1 CVEsxv100-box-e4-uc11 CVEs5p 8501 CVEsxv100-box-e4-uc1 firmware1 CVEs5p 850 firmware1 CVEs9000x1 CVEs9000x firmware1 CVEs9000x programming and configuration software1 CVEseamaxx series epdu1 CVEseamaxx series epdu firmware1 CVEseamxxx series epdu1 CVEseamxxx series epdu firmware1 CVEseasy-box-e4-ac11 CVEseasy-box-e4-ac1 firmware1 CVEseasy-box-e4-dc11 CVEseasy-box-e4-dc1 firmware1 CVEs

Recent Vulnerabilities

View all 54
CVE-2026-22619HIGH 7.8

Eaton Intelligent Power Protector (IPP) is affected by insecure library loading in its executable, which could lead to arbitrary code execution by an attacker with access to the software package. This security issue has been fixed in the latest version of Eaton IPP software which is available on the Eaton download center.

CVE-2026-22618MEDIUM 5.9

A security misconfiguration was identified in Eaton Intelligent Power Protector (IPP), where an HTTP response header was set with an insecure attribute, potentially exposing users to web‑based attacks. This security issue has been fixed in the latest version of Eaton IPP software which is available on the Eaton download centre.

CVE-2026-22617MEDIUM 5.7

Eaton Intelligent Power Protector (IPP) uses an insecure cookie configuration, which could allow a network‑based attacker to intercept the cookie and exploit it through a man‑in‑the‑middle attack. This security issue has been fixed in the latest version of Eaton IPP software which is available on the Eaton download centre.

CVE-2026-22616MEDIUM 6.5

Eaton Intelligent Power Protector (IPP) software allows repeated authentication attempts against the web interface login page due to insufficient rate‑limiting controls. This security issue has been fixed in the latest version of Eaton IPP which is available on the Eaton download centre.

CVE-2026-22615MEDIUM 6.0

Due to improper input validation in one of the Eaton Intelligent Power Protector (IPP) XML, it is possible for an attacker with admin privileges and access to the local system to inject malicious code resulting in arbitrary command execution. This security issue has been fixed in the latest version of Eaton IPP software which is available on the Eaton download centre.

CVE-2026-22614MEDIUM 6.1

The encryption mechanism used in Eaton's EasySoft project file was insecure and susceptible to brute force attacks, an attacker with access to this file and the local host machine could potentially read the sensitive information stored and tamper with the project file. This security issue has been fixed in the latest version of Eaton EasySoft which is available on the Eaton download centre.

CVE-2025-67450HIGH 7.8

Due to insecure library loading in the Eaton UPS Companion software executable, an attacker with access to the software package could perform arbitrary code execution . This security issue has been fixed in the latest version of EUC which is available on the Eaton download center.

CVE-2025-59888MEDIUM 6.7

Improper quotation in search paths in the Eaton UPS Companion software installer could lead to arbitrary code execution of an attacker with the access to the file system. This security issue has been fixed in the latest version of EUC which is available on the Eaton download center.

CVE-2025-59887HIGH 8.6

Improper authentication of library files in the Eaton UPS Companion software installer could lead to arbitrary code execution of an attacker with the access to the software package. This security issue has been fixed in the latest version of EUC which is available on the Eaton download center.

CVE-2025-59886HIGH 8.8

Improper input validation at one of the endpoints of Eaton xComfort ECI's web interface, could lead into an attacker with network access to the device executing privileged user commands. As cybersecurity standards continue to evolve and to meet our requirements today, Eaton has decided to discontinue the product. Upon retirement or end of support, there will be no new security updates, non-security updates, or paid assisted support options, or online technical content updates.

CVE-2024-31416MEDIUM 5.6

The Eaton Foreseer software provides multiple customizable input fields for the users to configure parameters in the tool like alarms, reports, etc. Some of these input fields were not checking the length and bounds of the entered value. The exploit of this security flaw by a bad actor may result in excessive memory consumption or integer overflow.

CVE-2024-31415MEDIUM 6.3

The Eaton Foreseer software provides the feasibility for the user to configure external servers for multiple purposes such as network management, user management, etc. The software uses encryption to store these configurations securely on the host machine. However, the keys used for this encryption were insecurely stored, which could be abused to possibly change or remove the server configuration.

CVE-2024-31414MEDIUM 6.7

The Eaton Foreseer software provides users the capability to customize the dashboard in WebView pages. However, the input fields for this feature in the Eaton Foreseer software lacked proper input sanitization on the server-side, which could lead to injection and execution of malicious scripts when abused by bad actors.

CVE-2023-43777MEDIUM 5.9

Eaton easySoft software is used to program easy controllers and displays for configuring, programming and defining parameters for all the intelligent relays. This software has a password protection functionality to secure the project file from unauthorized access. This password was being stored insecurely and could be retrieved by skilled adversaries. 

CVE-2023-43776MEDIUM 6.8

Eaton easyE4 PLC offers a device password protection functionality to facilitate a secure connection and prevent unauthorized access. It was observed that the device password was stored with a weak encoding algorithm in the easyE4 program file when exported to SD card (*.PRG file ending).

CVE-2023-43775MEDIUM 4.7

Denial-of-service vulnerability in the web server of the Eaton SMP Gateway allows attacker to potentially force an unexpected restart of the automation platform, impacting the availability of the product. In rare situations, the issue could cause the SMP device to restart in Safe Mode or Max Safe Mode. When in Max Safe Mode, the product is not vulnerable anymore.

CVE-2022-33859HIGH 8.1

A security vulnerability was discovered in the Eaton Foreseer EPMS software. Foreseer EPMS connects an operation’s vast array of devices to assist in the reduction of energy consumption and avoid unplanned downtime caused by the failures of critical systems. A threat actor may upload arbitrary files using the file upload feature. This vulnerability is present in versions 4.x, 5.x, 6.x & 7.0 to 7.5. A new version (v7.6) containing the remediation has been made available by Eaton and a mitigation has been provided for the affected versions that are currently supported. Customers are advised to update the software to the latest version (v7.6). Foreseer EPMS versions 4.x, 5.x, 6.x are no longer supported by Eaton. Please refer to the End-of-Support notification https://www.eaton.com/in/en-us/catalog/services/foreseer/foreseer-legacy.html .

CVE-2021-23283MEDIUM 5.2

Eaton Intelligent Power Protector (IPP) prior to version 1.69 is vulnerable to stored Cross Site Scripting. The vulnerability exists due to insufficient validation of user input and improper encoding of the output for certain resources within the IPP software.

CVE-2021-23286MEDIUM 5.7

Eaton Intelligent Power Manager Infrastructure (IPM Infrastructure) version 1.5.0plus205 and all prior versions are vulnerable to CSV Formula Injection. This issue affects: Eaton Intelligent Power Manager Infrastructure (IPM Infrastructure) all version 1.5.0plus205 and prior versions.

CVE-2021-23285LOW 3.1

Eaton Intelligent Power Manager Infrastructure (IPM Infrastructure) version 1.5.0plus205 and all prior versions are vulnerable to reflected Cross-site Scripting vulnerability. This issue affects: Eaton Intelligent Power Manager Infrastructure (IPM Infrastructure) all version 1.5.0plus205 and prior versions.

CVE-2021-23284MEDIUM 5.7

Eaton Intelligent Power Manager Infrastructure (IPM Infrastructure) version 1.5.0plus205 and all prior versions are vulnerable to Stored Cross-site Scripting vulnerability. This issue affects: Eaton Intelligent Power Manager Infrastructure (IPM Infrastructure) all version 1.5.0plus205 and prior versions.

CVE-2021-23288MEDIUM 5.6

The vulnerability exists due to insufficient validation of input from certain resources by the IPP software. The attacker would need access to the local Subnet and an administrator interaction to compromise the system. This issue affects: Intelligent Power Protector versions prior to 1.69.

CVE-2021-23287MEDIUM 5.6

The vulnerability exists due to insufficient validation of input of certain resources within the IPM software. This issue affects: Intelligent Power Manager (IPM 1) versions prior to 1.70.

CVE-2021-23281CRITICAL 10.0

Eaton Intelligent Power Manager (IPM) prior to 1.69 is vulnerable to unauthenticated remote code execution vulnerability. IPM software does not sanitize the date provided via coverterCheckList action in meta_driver_srv.js class. Attackers can send a specially crafted packet to make IPM connect to rouge SNMP server and execute attacker-controlled code.

CVE-2021-23280HIGH 8.0

Eaton Intelligent Power Manager (IPM) prior to 1.69 is vulnerable to authenticated arbitrary file upload vulnerability. IPM’s maps_srv.js allows an attacker to upload a malicious NodeJS file using uploadBackgroud action. An attacker can upload a malicious code or execute any command using a specially crafted packet to exploit the vulnerability.