Skip to content
Signals
NVD · CVE-2026-64604 · In the Linux kernel, the following vulnerability has been resolved: KVM: VMX: Grab vmcs12 on CR8 interception update iff vCPU is in guest mode When updating CR8NVD · CVE-2026-64603 · In the Linux kernel, the following vulnerability has been resolved: platform/x86: intel-hid: Protect ACPI notify handler against recursion Since commit e2ffcda1NVD · CVE-2026-64602 · In the Linux kernel, the following vulnerability has been resolved: iio: adc: spear: Initialize completion before requesting IRQ In the report from Jaeyoung ChuNVD · CVE-2026-64601 · In the Linux kernel, the following vulnerability has been resolved: ALSA: us144mkii: capture_urb_complete: redundant usb_anchor_urb corrupts anchor list on eachCISA KEV · CVE-2026-63077 · 9.8 · JetBrains TeamCity Deserialization of Untrusted Data Vulnerability · Added 2026-08-05 · Due 2026-08-08CISA KEV · CVE-2026-18556 · 7.4 · N-able N-central Authentication Bypass Using an Alternate Path or Channel Vulnerability · Added 2026-08-04 · Due 2026-08-07NVD · CVE-2026-64604 · In the Linux kernel, the following vulnerability has been resolved: KVM: VMX: Grab vmcs12 on CR8 interception update iff vCPU is in guest mode When updating CR8NVD · CVE-2026-64603 · In the Linux kernel, the following vulnerability has been resolved: platform/x86: intel-hid: Protect ACPI notify handler against recursion Since commit e2ffcda1NVD · CVE-2026-64602 · In the Linux kernel, the following vulnerability has been resolved: iio: adc: spear: Initialize completion before requesting IRQ In the report from Jaeyoung ChuNVD · CVE-2026-64601 · In the Linux kernel, the following vulnerability has been resolved: ALSA: us144mkii: capture_urb_complete: redundant usb_anchor_urb corrupts anchor list on eachCISA KEV · CVE-2026-63077 · 9.8 · JetBrains TeamCity Deserialization of Untrusted Data Vulnerability · Added 2026-08-05 · Due 2026-08-08CISA KEV · CVE-2026-18556 · 7.4 · N-able N-central Authentication Bypass Using an Alternate Path or Channel Vulnerability · Added 2026-08-04 · Due 2026-08-07

Vendors · honeywell

honeywell

· 23 Critical

Total CVEs

102

Critical

23

Products

377

Search All CVEs →

102

Products (377)

saia pg5 controls suite9 CVEsc300 firmware7 CVEsc3007 CVEsexperion process knowledge system6 CVEshdzp252di5 CVEshdzp252di firmware5 CVEsxl web ii controller5 CVEsexperion station5 CVEsdirect station5 CVEsengineering station5 CVEshbw2per15 CVEsexperion server5 CVEshbw2per1 firmware5 CVEshpw2p1 firmware4 CVEshpw2p14 CVEsopc ua tunneller4 CVEssafety manager4 CVEssafety manager firmware4 CVEsmaxpro nvr pe firmware3 CVEsmaxpro nvr se3 CVEsmaxpro nvr se firmware3 CVEsmaxpro nvr xe3 CVEsmaxpro nvr xe firmware3 CVEsh4w8pr23 CVEshdzp304di3 CVEsh4w8pr2 firmware3 CVEshdzp304di firmware3 CVEsh4w2per23 CVEsh4w2per2 firmware3 CVEsh4w2per33 CVEsonewireless network wireless device manager3 CVEsonewireless network wireless device manager firmware3 CVEspm433 CVEspm43 firmware3 CVEsapplication control environment3 CVEshbw2per23 CVEshbw8pr23 CVEsh2w2gr13 CVEsh2w2gr1 firmware3 CVEsh2w2pc1m3 CVEsh2w2pc1m firmware3 CVEsh2w2per33 CVEshew2per3 firmware3 CVEsh2w4per33 CVEsh2w4per3 firmware3 CVEshbw8pr2 firmware3 CVEshew2per23 CVEshew2per2 firmware3 CVEshew2per33 CVEswin-pak3 CVEsh2w2per3 firmware3 CVEshbw2per2 firmware3 CVEshew4per2b3 CVEshew4per2b firmware3 CVEsh4w2per3 firmware3 CVEscontroledge rtu3 CVEshew4per3b3 CVEshew4per3b firmware3 CVEscontroledge rtu firmware3 CVEslenels2 netbox3 CVEsc200 firmware3 CVEsc200e3 CVEsc200e firmware3 CVEsapplication control environment firmware3 CVEsc2003 CVEscontroledge plc3 CVEscontroledge plc firmware3 CVEsmaxpro nvr pe3 CVEshcd8g2 CVEshcd8g firmware2 CVEshcl2g2 CVEshcl2g firmware2 CVEshcl2gv2 CVEsh3w2gr1v firmware2 CVEshcw2g2 CVEshcw2g firmware2 CVEshcw2gv2 CVEshcw2gv firmware2 CVEshcw4g2 CVEshcw4g firmware2 CVEshdz302d2 CVEshdz302d firmware2 CVEshdz302de2 CVEshdz302de firmware2 CVEshdz302din-c12 CVEshdz302din-c1 firmware2 CVEshdz302din-s12 CVEshdz302din-s1 firmware2 CVEsfalcon xlweb linux controller2 CVEshdz302lik2 CVEshdz302lik firmware2 CVEshdz302liw2 CVEshdz302liw firmware2 CVEsmidas black firmware2 CVEsmidas firmware2 CVEshed2per32 CVEsmpnvrswxx2 CVEsmpnvrswxx firmware2 CVEshed2per3 firmware2 CVEsnotifier webserver2 CVEsfalcon xlweb xlwebexe2 CVEsalerton ascent control module2 CVEssoftmaster2 CVEssymmetre2 CVEsh3w2gr12 CVEsh3w2gr1 firmware2 CVEstuxedo touch2 CVEsh3w2gr1v2 CVEshcl2gv firmware2 CVEsh3w2gr22 CVEsh3w2gr2 firmware2 CVEsh3w4gr12 CVEsh3w4gr1 firmware2 CVEsh3w4gr1v2 CVEsh3w4gr1v firmware2 CVEsh4d8gr12 CVEsh4d8gr1 firmware2 CVEsh4l2gr12 CVEsh4l2gr1 firmware2 CVEsh4l2gr1v2 CVEsh4l2gr1v firmware2 CVEsh4l6gr22 CVEsh4l6gr2 firmware2 CVEsh4w2gr12 CVEsh4w2gr1 firmware2 CVEsh4w2gr1v2 CVEsh4w2gr1v firmware2 CVEsh4w2gr22 CVEsh4w2gr2 firmware2 CVEsh4w4gr12 CVEsh4w4gr1 firmware2 CVEsh4w4gr1v2 CVEsh4w4gr1v firmware2 CVEsh4w4per22 CVEsh4w4per2 firmware2 CVEsh4w4per32 CVEsh4w4per3 firmware2 CVEshbd2per12 CVEshbd2per1 firmware2 CVEscontroledge unit operations controller2 CVEscontroledge unit operations controller firmware2 CVEscontroledge virtual unit operations controller2 CVEscontroledge virtual unit operations controller firmware2 CVEshbd8gr12 CVEshbd8gr1 firmware2 CVEshbl2gr1v2 CVEshbl2gr1v firmware2 CVEshbl6gr22 CVEshbl6gr2 firmware2 CVEshbw2gr1v2 CVEshbw2gr1v firmware2 CVEsalerton ascent control module firmware2 CVEshbw2gr3v2 CVEshbw2gr3v firmware2 CVEshew4per32 CVEshew4per3 firmware2 CVEshbw4gr1v2 CVEshfd6gr12 CVEshfd6gr1 firmware2 CVEshfd8gr12 CVEshfd8gr1 firmware2 CVEshm4l8gr12 CVEshm4l8gr1 firmware2 CVEshmbl8gr12 CVEshmbl8gr1 firmware2 CVEshnmswvms2 CVEshnmswvms firmware2 CVEshnmswvmslt2 CVEshnmswvmslt firmware2 CVEshbw4gr1v firmware2 CVEshbw4per12 CVEshbw4per1 firmware2 CVEshbw4per22 CVEshbw4per2 firmware2 CVEshbw4pgr12 CVEshbw4pgr1 firmware2 CVEsmaxpro nvr hybrid xe1 CVEsademco atnbaseloader100 module1 CVEsmb-secure1 CVEsmb-secure firmware1 CVEsmb-secure pro1 CVEsmb-secure pro firmware1 CVEsmidas1 CVEsmidas black1 CVEsmpa21 CVEsmpa2 firmware1 CVEsniagara framework1 CVEsopos suite1 CVEsprowatch1 CVEsscanserver activex control1 CVEstrend iq4111 CVEstrend iq411 firmware1 CVEstrend iq4121 CVEstrend iq412 firmware1 CVEstrend iq4221 CVEstrend iq422 firmware1 CVEstrend iq4e1 CVEstrend iq4e firmware1 CVEstrend iq4nc1 CVEstrend iq4nc firmware1 CVEsuniformance process history database1 CVEsmaxpro nvr hybrid xe firmware1 CVEsalerton bcm-web1 CVEsalerton bcm-web firmware1 CVEsalerton compass1 CVEsalterton visual logic1 CVEsalterton visual logic firmware1 CVEsck751 CVEscn511 CVEscn751 CVEscn75e1 CVEscn801 CVEscomfortpoint open manager station1 CVEsct401 CVEsct501 CVEsct601 CVEsd75e1 CVEseda501 CVEseda50k1 CVEseda511 CVEseda60k1 CVEseda701 CVEsenterprise building manager1 CVEsenterprise buildings integrator1 CVEsenterprise dvr1 CVEsenterprise dvr firmware1 CVEsexcel web xl 1000c1000 600 i\/o1 CVEsexcel web xl 1000c1000 600 i\/o uukl1 CVEsexcel web xl 1000c100 104 i\/o1 CVEsexcel web xl 1000c100u 104 i\/o uukl1 CVEsexcel web xl 1000c500 300 i\/o1 CVEsexcel web xl 1000c500 300 i\/o uukl1 CVEsexcel web xl 1000c50 52 i\/o1 CVEsexcel web xl 1000c50u 52 i\/o uukl1 CVEsexperion1 CVEsexperion lx1 CVEsexperion lx firmware1 CVEsfusion iv rev c1 CVEsfusion iv rev c firmware1 CVEsh4d3prv21 CVEsh4d3prv2 firmware1 CVEsh4d3prv31 CVEsh4d3prv3 firmware1 CVEsh4d8pr11 CVEsh4d8pr1 firmware1 CVEsh4lggr21 CVEsh4lggr2 firmware1 CVEshbd3pr11 CVEshbd3pr1 firmware1 CVEshbd3pr21 CVEshbd3pr2 firmware1 CVEshbl2gr11 CVEshbl2gr1 firmware1 CVEshbw2gr11 CVEshbw2gr1 firmware1 CVEshbw2gr31 CVEshbw2gr3 firmware1 CVEshbw4gr11 CVEshbw4gr1 firmware1 CVEshdz302din1 CVEshdz302din firmware1 CVEshed3pr31 CVEshed3pr3 firmware1 CVEshen041031 CVEshen04103 firmware1 CVEshen04103l1 CVEshen04103l firmware1 CVEshen041131 CVEshen04113 firmware1 CVEshen041231 CVEshen04123 firmware1 CVEshen081031 CVEshen08103 firmware1 CVEshen08103l1 CVEshen08103l firmware1 CVEshen081041 CVEshen08104 firmware1 CVEshen0811241 CVEshen081124 firmware1 CVEshen081131 CVEshen08113 firmware1 CVEshen081231 CVEshen08123 firmware1 CVEshen081431 CVEshen08143 firmware1 CVEshen081441 CVEshen08144 firmware1 CVEshen161031 CVEshen16103 firmware1 CVEshen16103l1 CVEshen16103l firmware1 CVEshen161041 CVEshen16104 firmware1 CVEshen161231 CVEshen16123 firmware1 CVEshen161431 CVEshen16143 firmware1 CVEshen161441 CVEshen16144 firmware1 CVEshen161631 CVEshen16163 firmware1 CVEshen161841 CVEshen16184 firmware1 CVEshen162041 CVEshen16204 firmware1 CVEshen1622441 CVEshen162244 firmware1 CVEshen162841 CVEshen16284 firmware1 CVEshen163041 CVEshen16304 firmware1 CVEshen163841 CVEshen16384 firmware1 CVEshen32103l1 CVEshen32103l firmware1 CVEshen321041 CVEshen32104 firmware1 CVEshen3211241 CVEshen321124 firmware1 CVEshen322041 CVEshen32204 firmware1 CVEshen3221641 CVEshen322164 firmware1 CVEshen322841 CVEshen32284 firmware1 CVEshen323041 CVEshen32304 firmware1 CVEshen3231641 CVEshen323164 firmware1 CVEshen323841 CVEshen32384 firmware1 CVEshen642041 CVEshen64204 firmware1 CVEshen643041 CVEshen64304 firmware1 CVEshen6431641 CVEshen643164 firmware1 CVEshen6433241 CVEshen643324 firmware1 CVEshen6434841 CVEshen643484 firmware1 CVEshepz302w01 CVEshepz302w0 firmware1 CVEshew4per21 CVEshew4per2 firmware1 CVEshfd5pr11 CVEshfd5pr1 firmware1 CVEshsw2g11 CVEshsw2g1 firmware1 CVEshswb2g11 CVEshswb2g1 firmware1 CVEsinncom inncontrol1 CVEsinncom inncontrol firmware1 CVEsintermec pc231 CVEsintermec pc23 firmware1 CVEsintermec pc421 CVEsintermec pc42 firmware1 CVEsintermec pc431 CVEsintermec pc43 firmware1 CVEsintermec pd431 CVEsintermec pd43 firmware1 CVEsintermec pm231 CVEsintermec pm23 firmware1 CVEsintermec pm421 CVEsintermec pm42 firmware1 CVEsintermec pm431 CVEsintermec pm43 firmware1 CVEsip-ak21 CVEsip-ak2 firmware1 CVEsiq3xcite1 CVEsiq3xcite firmware1 CVEsmasmobile asp.net services1 CVEsmasmobile classic1 CVEsmatrikon opc server1 CVEsmatrikonopc explorer1 CVEsmaxpro nvr hybrid se1 CVEsmaxpro nvr hybrid se firmware1 CVEs

Recent Vulnerabilities

View all 102
CVE-2025-2605CRITICAL 9.9

Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in Honeywell MB-Secure allows Privilege Abuse. This issue affects MB-Secure: from V11.04 before V12.53 and MB-Secure PRO from V01.06 before V03.09.Honeywell also recommends updating to the most recent version of this product.

CVE-2024-46453MEDIUM 6.1

A cross-site scripting (XSS) vulnerability in the component /test/ of iq3xcite v2.31 to v3.05 allows attackers to execute arbitrary web scripts or HTML via a crafted payload.

CVE-2024-2422HIGH 8.8

LenelS2 NetBox access control and event monitoring system was discovered to contain an authenticated RCE in versions prior to and including 5.6.1, which allows an attacker to execute malicious commands.

CVE-2024-2421CRITICAL 9.8

LenelS2 NetBox access control and event monitoring system was discovered to contain an unauthenticated RCE in versions prior to and including 5.6.1, which allows an attacker to execute malicious commands with elevated permissions.

CVE-2024-2420CRITICAL 9.8

LenelS2 NetBox access control and event monitoring system was discovered to contain Hardcoded Credentials in versions prior to and including 5.6.1 which allows an attacker to bypass authentication requirements.

CVE-2023-51605MEDIUM 6.5

Honeywell Saia PG5 Controls Suite XML External Entity Processing Information Disclosure Vulnerability. This vulnerability allows remote attackers to disclose sensitive information on affected installations of Honeywell Saia PG5 Controls Suite. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of XML files. Due to the improper restriction of XML External Entity (XXE) references, a crafted document specifying a URI causes the XML parser to access the URI and embed the contents back into the XML document for further processing. An attacker can leverage this vulnerability to disclose information in the context of the current process. . Was ZDI-CAN-18644.

CVE-2023-51604MEDIUM 6.5

Honeywell Saia PG5 Controls Suite XML External Entity Processing Information Disclosure Vulnerability. This vulnerability allows remote attackers to disclose sensitive information on affected installations of Honeywell Saia PG5 Controls Suite. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of XML files. Due to the improper restriction of XML External Entity (XXE) references, a crafted document specifying a URI causes the XML parser to access the URI and embed the contents back into the XML document for further processing. An attacker can leverage this vulnerability to disclose information in the context of the current process. . Was ZDI-CAN-18593.

CVE-2023-51603HIGH 8.8

Honeywell Saia PG5 Controls Suite CAB File Parsing Directory Traversal Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Honeywell Saia PG5 Controls Suite. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of CAB files. The issue results from the lack of proper validation of a user-supplied path prior to using it in file operations. An attacker can leverage this vulnerability to execute code in the context of the current user. . Was ZDI-CAN-18592.

CVE-2023-51602MEDIUM 6.5

Honeywell Saia PG5 Controls Suite XML External Entity Processing Information Disclosure Vulnerability. This vulnerability allows remote attackers to disclose sensitive information on affected installations of Honeywell Saia PG5 Controls Suite. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of XML files. Due to the improper restriction of XML External Entity (XXE) references, a crafted document specifying a URI causes the XML parser to access the URI and embed the contents back into the XML document for further processing. An attacker can leverage this vulnerability to disclose information in the context of the current process. . Was ZDI-CAN-18591.

CVE-2023-51601MEDIUM 6.5

Honeywell Saia PG5 Controls Suite XML External Entity Processing Information Disclosure Vulnerability. This vulnerability allows remote attackers to disclose sensitive information on affected installations of Honeywell Saia PG5 Controls Suite. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of xml files. Due to the improper restriction of XML External Entity (XXE) references, a crafted document specifying a URI causes the XML parser to access the URI and embed the contents back into the XML document for further processing. An attacker can leverage this vulnerability to disclose information in the context of the current process. . Was ZDI-CAN-18563.

CVE-2023-51600MEDIUM 6.5

Honeywell Saia PG5 Controls Suite XML External Entity Processing Information Disclosure Vulnerability. This vulnerability allows remote attackers to disclose sensitive information on affected installations of Honeywell Saia PG5 Controls Suite. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of XML files. Due to the improper restriction of XML External Entity (XXE) references, a crafted document specifying a URI causes the XML parser to access the URI and embed the contents back into the XML document for further processing. An attacker can leverage this vulnerability to disclose information in the context of the current process. . Was ZDI-CAN-18456.

CVE-2023-51599HIGH 8.8

Honeywell Saia PG5 Controls Suite Directory Traversal Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Honeywell Saia PG5 Controls Suite. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of ZIP files. The issue results from the lack of proper validation of a user-supplied path prior to using it in file operations. An attacker can leverage this vulnerability to execute code in the context of the current user. . Was ZDI-CAN-18412.

CVE-2023-36483MEDIUM 6.5

Authorization bypass can be achieved by session ID prediction in MASmobile Classic Android  version 1.16.18 and earlier and MASmobile Classic iOS version 1.7.24 and earlier which allows remote attackers to retrieve sensitive data  including customer data, security system status, and event history.

CVE-2023-1841HIGH 8.1

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Honeywell MPA2 Access Panel (Web server modules) allows XSS Using Invalid Characters.This issue affects MPA2 Access Panel all version prior to R1.00.08.05.  Honeywell released firmware update package MPA2 firmware R1.00.08.05 which addresses this vulnerability. This version and all later versions correct the reported vulnerability.

CVE-2024-1309MEDIUM 6.5

Uncontrolled Resource Consumption vulnerability in Honeywell Niagara Framework on Windows, Linux, QNX allows Content Spoofing.This issue affects Niagara Framework: before Niagara AX 3.8.1, before Niagara 4.1.

CVE-2023-5390MEDIUM 5.3

An attacker could potentially exploit this vulnerability, leading to files being read from the Honeywell Experion ControlEdge VirtualUOC and ControlEdge UOC. This exploit could be used to read files from the controller that may expose limited information from the device. Honeywell recommends updating to the most recent version of the product. See Honeywell Security Notification for recommendations on upgrading and versioning.

CVE-2023-5389CRITICAL 9.1

An attacker could potentially exploit this vulnerability, leading to the ability to modify files on Honeywell Experion ControlEdge VirtualUOC and ControlEdge UOC . This exploit could be used to write a file that may result in unexpected behavior based on configuration changes or updating of files that could result in subsequent execution of a malicious application if triggered. Honeywell recommends updating to the most recent version of the product. See Honeywell Security Notification for recommendations on upgrading and versioning. 

CVE-2023-6179HIGH 7.8

Honeywell ProWatch, 4.5, including all Service Pack versions, contain a Vulnerability in Application Server's executable folder(s). A(n) attacker could potentially exploit this vulnerability, leading to a standard user to have arbitrary system code execution. Honeywell recommends updating to the most recent version of this product, service or offering (Pro-watch 6.0.2, 6.0, 5.5.2,5.0.5).

CVE-2023-3712MEDIUM 6.6

Files or Directories Accessible to External Parties vulnerability in Honeywell PM43 on 32 bit, ARM (Printer web page modules) allows Privilege Escalation.This issue affects PM43 versions prior to P10.19.050004.  Update to the latest available firmware version of the respective printers to version MR19.5 (e.g. P10.19.050006).

CVE-2023-3711MEDIUM 6.4

Session Fixation vulnerability in Honeywell PM43 on 32 bit, ARM (Printer web page modules) allows Session Credential Falsification through Prediction.This issue affects PM43 versions prior to P10.19.050004. Update to the latest available firmware version of the respective printers to version MR19.5 (e.g. P10.19.050006).

CVE-2023-3710CRITICAL 9.9

Improper Input Validation vulnerability in Honeywell PM43 on 32 bit, ARM (Printer web page modules) allows Command Injection.This issue affects PM43 versions prior to P10.19.050004. Update to the latest available firmware version of the respective printers to version MR19.5 (e.g. P10.19.050006).

CVE-2023-26597HIGH 7.5

Controller DoS due to buffer overflow in the handling of a specially crafted message received by the controller. See Honeywell Security Notification for recommendations on upgrading and versioning. See Honeywell Security Notification for recommendations on upgrading and versioning.

CVE-2023-25948HIGH 7.5

Server information leak of configuration data when an error is generated in response to a specially crafted message. See Honeywell Security Notification for recommendations on upgrading and versioning.

CVE-2023-25770CRITICAL 9.8

Controller DoS may occur due to buffer overflow when an error is generated in response to a specially crafted message. See Honeywell Security Notification for recommendations on upgrading and versioning.

CVE-2023-25178CRITICAL 9.8

Controller may be loaded with malicious firmware which could enable remote code execution. See Honeywell Security Notification for recommendations on upgrading and versioning.