Skip to content
Signals
NVD · CVE-2026-64604 · In the Linux kernel, the following vulnerability has been resolved: KVM: VMX: Grab vmcs12 on CR8 interception update iff vCPU is in guest mode When updating CR8NVD · CVE-2026-64603 · In the Linux kernel, the following vulnerability has been resolved: platform/x86: intel-hid: Protect ACPI notify handler against recursion Since commit e2ffcda1NVD · CVE-2026-64602 · In the Linux kernel, the following vulnerability has been resolved: iio: adc: spear: Initialize completion before requesting IRQ In the report from Jaeyoung ChuNVD · CVE-2026-64601 · In the Linux kernel, the following vulnerability has been resolved: ALSA: us144mkii: capture_urb_complete: redundant usb_anchor_urb corrupts anchor list on eachCISA KEV · CVE-2026-63077 · 9.8 · JetBrains TeamCity Deserialization of Untrusted Data Vulnerability · Added 2026-08-05 · Due 2026-08-08CISA KEV · CVE-2026-18556 · 7.4 · N-able N-central Authentication Bypass Using an Alternate Path or Channel Vulnerability · Added 2026-08-04 · Due 2026-08-07NVD · CVE-2026-64604 · In the Linux kernel, the following vulnerability has been resolved: KVM: VMX: Grab vmcs12 on CR8 interception update iff vCPU is in guest mode When updating CR8NVD · CVE-2026-64603 · In the Linux kernel, the following vulnerability has been resolved: platform/x86: intel-hid: Protect ACPI notify handler against recursion Since commit e2ffcda1NVD · CVE-2026-64602 · In the Linux kernel, the following vulnerability has been resolved: iio: adc: spear: Initialize completion before requesting IRQ In the report from Jaeyoung ChuNVD · CVE-2026-64601 · In the Linux kernel, the following vulnerability has been resolved: ALSA: us144mkii: capture_urb_complete: redundant usb_anchor_urb corrupts anchor list on eachCISA KEV · CVE-2026-63077 · 9.8 · JetBrains TeamCity Deserialization of Untrusted Data Vulnerability · Added 2026-08-05 · Due 2026-08-08CISA KEV · CVE-2026-18556 · 7.4 · N-able N-central Authentication Bypass Using an Alternate Path or Channel Vulnerability · Added 2026-08-04 · Due 2026-08-07

Vendors · ge

ge

· 25 Critical

Total CVEs

128

Critical

25

Products

227

Search All CVEs →

128

Products (227)

cimplicity12 CVEsintelligent platforms proficy hmi\/scada cimplicity10 CVEsindustrial gateway server7 CVEsmultilin b906 CVEsmultilin f60 firmware6 CVEsmultilin b306 CVEsmultilin b30 firmware6 CVEsintelligent platforms proficy historian6 CVEsmultilin l60 firmware6 CVEsmultilin l606 CVEsintelligent platforms proficy process systems with cimplicity6 CVEsmultilin l30 firmware6 CVEsintelligent platforms proficy real-time information portal6 CVEsmultilin l306 CVEsmultilin g60 firmware6 CVEsmultilin g606 CVEsmultilin g30 firmware6 CVEsmultilin g306 CVEsmultilin f606 CVEsmultilin f35 firmware6 CVEsmultilin f356 CVEsmultilin d60 firmware6 CVEsmultilin d606 CVEsmultilin d30 firmware6 CVEsmultilin d306 CVEsmultilin c95 firmware6 CVEsmultilin c956 CVEsmultilin c70 firmware6 CVEsmultilin c706 CVEsmultilin c60 firmware6 CVEsmultilin c606 CVEsmultilin c30 firmware6 CVEsmultilin c306 CVEsmultilin b90 firmware6 CVEsmultilin t60 firmware6 CVEsmultilin t606 CVEsmultilin t35 firmware6 CVEsge communicator6 CVEsmultilin t356 CVEsmultilin n60 firmware6 CVEsmultilin n606 CVEsmultilin m60 firmware6 CVEsmultilin m606 CVEsmultilin l90 firmware6 CVEsmultilin l906 CVEssd4 firmware5 CVEssd45 CVEssd2 firmware5 CVEssd25 CVEssd1 firmware5 CVEssd15 CVEsproficy historian5 CVEstd220x firmware5 CVEstd220x5 CVEsmds pulsenet5 CVEsifix5 CVEssd9 firmware5 CVEsinet 9005 CVEsinet 900 firmware5 CVEsinet ii 9005 CVEssd95 CVEsinet ii 900 firmware5 CVEstd220max5 CVEstd220max firmware5 CVEsmultilink ml8104 CVEsintelligent platforms proficy hmi\/scada ifix4 CVEsmultilink ml8004 CVEsmultilink ml31004 CVEsmultilink ml30004 CVEsmultilink ml24004 CVEsmultilink ml16004 CVEsmultilink ml12004 CVEsrt431 firmware3 CVEsintelligent platforms proficy process systems3 CVEsms 30003 CVEsms 3000 firmware3 CVEsmu320e3 CVEsmu320e firmware3 CVEsmultilink ml1200 firmware3 CVEsmultilink ml1600 firmware3 CVEsmultilink ml2400 firmware3 CVEsmultilink ml3000 firmware3 CVEsmultilink ml3100 firmware3 CVEsmultilink ml800 firmware3 CVEsmultilink ml810 firmware3 CVEsreason dr603 CVEsreason dr60 firmware3 CVEsrt4303 CVEsrt430 firmware3 CVEsrt4313 CVEsrt4343 CVEsrt434 firmware3 CVEss20203 CVEss2020 firmware3 CVEsvoluson s83 CVEsvoluson s8 firmware3 CVEsasset performance management classic2 CVEsintelligent platforms proficy batch execution2 CVEstoolboxst2 CVEsintelligent platforms si7 i\/o driver2 CVEsdigital industrial gateway server2 CVEsworkstationst2 CVEsintelligent platforms proficy pulse2 CVEsintelligent platforms proficy plant applications2 CVEsd60 line distance relay firmware2 CVEss20242 CVEss2024 firmware2 CVEsintelligent platforms proficy hmi\%2fscada cimplicity2 CVEsd60 line distance relay2 CVEsintelligent platforms proficy dnp3 i\/o driver2 CVEsmultilin sr 745 transformer protection relay firmware1 CVEsmultilin sr 750 feeder protection relay1 CVEsmultilin sr 750 feeder protection relay firmware1 CVEsmultilin sr 760 feeder protection relay1 CVEsmultilin sr 760 feeder protection relay firmware1 CVEsgemnet license server1 CVEsex2100e firmware1 CVEsex2100e1 CVEsmultilin universal relay1 CVEsmultilin universal relay firmware1 CVEsmultilin urplus b951 CVEsmultilin urplus b95 firmware1 CVEsmultilin urplus c901 CVEsmultilin urplus c90 firmware1 CVEsmultilin urplus d901 CVEsmultilin urplus d90 firmware1 CVEsmultilink firmware1 CVEsvivid e901 CVEsvivid e90 firmware1 CVEsd20me firmware1 CVEsvivid e951 CVEsd20me1 CVEsvivid e95 firmware1 CVEsd200 firmware1 CVEsvivid iq1 CVEsd2001 CVEsvivid iq firmware1 CVEscentricity pacs ra10001 CVEsvivid s70n1 CVEspacsystems cpu3201 CVEspacsystems cpu320 firmware1 CVEspacsystems cru3201 CVEspacsystems cru320 firmware1 CVEspacsystems rsti-ep cpe 1001 CVEspacsystems rsti-ep cpe 100 firmware1 CVEspacsystems rx3i cpe3051 CVEspacsystems rx3i cpe305 firmware1 CVEspacsystems rx3i cpe3101 CVEspacsystems rx3i cpe310 firmware1 CVEspacsystems rxi1 CVEspacsystems rxi firmware1 CVEsproficy cimplicitiy1 CVEsbently nevada 3500\/22m usb firmware1 CVEsproficy real-time information portal1 CVEsvivid s70n firmware1 CVEsvivid t81 CVEsreason rpv311 firmware1 CVEsrpv3111 CVEsvivid t8 firmware1 CVEsvivid t91 CVEsvivid t9 firmware1 CVEs12400 level transmitter device type manager1 CVEsvoluson1 CVEsvoluson firmware1 CVEsrx3i cpe3301 CVEsrx3i cpe330 firmware1 CVEsrx3i cpe 4001 CVEsrx3i cpe 400 firmware1 CVEsxeleris1 CVEss2020g1 CVEss2020g firmware1 CVEsbently nevada 3500\/22m usb1 CVEsbently nevada 3500\/22m serial firmware1 CVEsbently nevada 3500\/22m serial1 CVEsaestiva 7900 firmware1 CVEsaestiva 79001 CVEsaestiva 7100 firmware1 CVEsaestiva 71001 CVEssnmp\/web adapter 10247461 CVEssnmp\/web adapter 10247471 CVEssnmp\/web adapter 10247481 CVEssnmp\/web adapter 10249211 CVEssnmp\/web adapter firmware1 CVEssvi ii ap positioner device type manager1 CVEsaespire 7900 firmware1 CVEsaespire 79001 CVEsaespire 7100 firmware1 CVEsaespire 71001 CVEsups snmp web adapter firmware1 CVEsur bootloader binary1 CVEsvector device type manager1 CVEsvenue go1 CVEsvenue go firmware1 CVEsversana essential1 CVEsversana essential firmware1 CVEsmicom s1 agile1 CVEsmark vle firmware1 CVEsmark vle1 CVEsmark vie controll system1 CVEsmark vie control system1 CVEsls2100e firmware1 CVEsls2100e1 CVEslogiq s8 firmware1 CVEslogiq s81 CVEslogiq s7 firmware1 CVEslogiq s71 CVEslogiq p9 firmware1 CVEslogiq p91 CVEslogiq e9 with xdclear firmware1 CVEslogiq e9 with xdclear1 CVEslogiq e9 firmware1 CVEslogiq e91 CVEslogiq e101 CVEslogiq e10 firmware1 CVEsinvenia abus scan station firmware1 CVEsinvenia abus scan station1 CVEsinfinia hawkeye 4 firmware1 CVEsinfinia hawkeye 41 CVEshydran m21 CVEshistorian1 CVEsmultilin sr 369 motor protection relay1 CVEsmultilin sr 369 motor protection relay firmware1 CVEsmultilin sr 469 motor protection relay1 CVEsmultilin sr 469 motor protection relay firmware1 CVEsmultilin sr 489 generator protection relay1 CVEsmultilin sr 489 generator protection relay firmware1 CVEsmultilin sr 745 transformer protection relay1 CVEs

Recent Vulnerabilities

View all 128
CVE-2023-5909HIGH 7.5

KEPServerEX does not properly validate certificates from clients which may allow unauthenticated users to connect.

CVE-2023-5908CRITICAL 9.1

KEPServerEX is vulnerable to a buffer overflow which may allow an attacker to crash the product being accessed or leak information.

CVE-2023-0898MEDIUM 5.3

General Electric MiCOM S1 Agile is vulnerable to an attacker achieving code execution by placing malicious DLL files in the directory of the application.

CVE-2023-4487HIGH 7.8

GE CIMPLICITY 2023 is by a process control vulnerability, which could allow a local attacker to insert malicious configuration files in the expected web server execution path to escalate privileges and gain full control of the HMI software.

CVE-2023-3463MEDIUM 6.6

All versions of GE Digital CIMPLICITY that are not adhering to SDG guidance and accepting documents from untrusted sources are vulnerable to memory corruption issues due to insufficient input validation, including issues such as out-of-bounds reads and writes, use-after-free, stack-based buffer overflows, uninitialized pointers, and a heap-based buffer overflow. Successful exploitation could allow an attacker to execute arbitrary code.

CVE-2023-1552MEDIUM 6.4

ToolboxST prior to version 7.10 is affected by a deserialization vulnerability. An attacker with local access to an HMI or who has conducted a social engineering attack on an authorized operator could execute code in a Toolbox user's context through the deserialization of an untrusted configuration file. Two CVSS scores have been provided to capture the differences between the two aforementioned attack vectors.  Customers are advised to update to ToolboxST 7.10 which can be found in ControlST 7.10. If unable to update at this time customers should ensure they are following the guidance laid out in GE Gas Power's Secure Deployment Guide (GEH-6839). Customers should ensure they are not running ToolboxST as an Administrative user. 

CVE-2022-2848CRITICAL 9.1

This vulnerability allows remote attackers to execute arbitrary code on affected installations of Kepware KEPServerEX 6.11.718.0. Authentication is not required to exploit this vulnerability. The specific flaw exists within the handling of text encoding conversions. The issue results from the lack of proper validation of the length of user-supplied data prior to copying it to a heap-based buffer. An attacker can leverage this vulnerability to execute code in the context of SYSTEM. Was ZDI-CAN-16486.

CVE-2022-2825CRITICAL 9.8

This vulnerability allows remote attackers to execute arbitrary code on affected installations of Kepware KEPServerEX 6.11.718.0. Authentication is not required to exploit this vulnerability. The specific flaw exists within the handling of text encoding conversions. The issue results from the lack of proper validation of the length of user-supplied data prior to copying it to a stack-based buffer. An attacker can leverage this vulnerability to execute code in the context of SYSTEM. Was ZDI-CAN-18411.

CVE-2023-0598HIGH 7.8

GE Digital Proficy iFIX 2022, GE Digital Proficy iFIX v6.1, and GE Digital Proficy iFIX v6.5 are vulnerable to code injection, which may allow an attacker to insert malicious configuration files in the expected web server execution path and gain full control of the HMI software.

CVE-2023-0755CRITICAL 9.8

The affected products are vulnerable to an improper validation of array index, which could allow an attacker to crash the server and remotely execute arbitrary code.

CVE-2023-0754CRITICAL 9.8

The affected products are vulnerable to an integer overflow or wraparound, which could  allow an attacker to crash the server and remotely execute arbitrary code.

CVE-2022-46732CRITICAL 9.8

Even if the authentication fails for local service authentication, the requested command could still execute regardless of authentication status.

CVE-2022-46660HIGH 7.5

An unauthorized user could alter or write files with full control over the path and content of the file.

CVE-2022-46331HIGH 7.5

An unauthorized user could possibly delete any file on the system.

CVE-2022-43494HIGH 7.5

An unauthorized user could be able to read any file on the system, potentially exposing sensitive information.

CVE-2022-38469HIGH 7.5

An unauthorized user with network access and the decryption key could decrypt sensitive data, such as usernames and passwords.

CVE-2022-43977CRITICAL 9.8

An issue was discovered on GE Grid Solutions MS3000 devices before 3.7.6.25p0_3.2.2.17p0_4.7p0. The debug port accessible via TCP (a qconn service) lacks access control.

CVE-2022-43976CRITICAL 9.8

An issue was discovered in FC46-WebBridge on GE Grid Solutions MS3000 devices before 3.7.6.25p0_3.2.2.17p0_4.7p0. Direct access to the API is possible on TCP port 8888 via programs located in the cgi-bin folder without any authentication.

CVE-2022-43975HIGH 7.5

An issue was discovered in FC46-WebBridge on GE Grid Solutions MS3000 devices before 3.7.6.25p0_3.2.2.17p0_4.7p0. A vulnerability in the web server allows arbitrary files and configurations to be read via directory traversal over TCP port 8888.

CVE-2022-24120MEDIUM 4.6

Certain General Electric Renewable Energy products store cleartext credentials in flash memory. This affects iNET and iNET II before 8.3.0.

CVE-2022-24119CRITICAL 9.8

Certain General Electric Renewable Energy products have a hidden feature for unauthenticated remote access to the device configuration shell. This affects iNET and iNET II before 8.3.0.

CVE-2022-24118CRITICAL 9.1

Certain General Electric Renewable Energy products allow attackers to use a code to trigger a reboot into the factory default configuration. This affects iNET and iNET II before 8.3.0, SD before 6.4.7, TD220X before 2.0.16, and TD220MAX before 1.2.6.

CVE-2022-24117CRITICAL 9.8

Certain General Electric Renewable Energy products download firmware without an integrity check. This affects iNET and iNET II before 8.3.0, SD before 6.4.7, TD220X before 2.0.16, and TD220MAX before 1.2.6.

CVE-2022-24116CRITICAL 9.8

Certain General Electric Renewable Energy products have inadequate encryption strength. This affects iNET and iNET II before 8.3.0.

CVE-2022-3092HIGH 7.8

GE CIMPICITY versions 2022 and prior is vulnerable to an out-of-bounds write, which could allow an attacker to execute arbitrary code.

ge — Vendor | Dragons Community