Skip to content
Signals
NVD · CVE-2026-64604 · In the Linux kernel, the following vulnerability has been resolved: KVM: VMX: Grab vmcs12 on CR8 interception update iff vCPU is in guest mode When updating CR8NVD · CVE-2026-64603 · In the Linux kernel, the following vulnerability has been resolved: platform/x86: intel-hid: Protect ACPI notify handler against recursion Since commit e2ffcda1NVD · CVE-2026-64602 · In the Linux kernel, the following vulnerability has been resolved: iio: adc: spear: Initialize completion before requesting IRQ In the report from Jaeyoung ChuNVD · CVE-2026-64601 · In the Linux kernel, the following vulnerability has been resolved: ALSA: us144mkii: capture_urb_complete: redundant usb_anchor_urb corrupts anchor list on eachCISA KEV · CVE-2026-63077 · 9.8 · JetBrains TeamCity Deserialization of Untrusted Data Vulnerability · Added 2026-08-05 · Due 2026-08-08CISA KEV · CVE-2026-18556 · 7.4 · N-able N-central Authentication Bypass Using an Alternate Path or Channel Vulnerability · Added 2026-08-04 · Due 2026-08-07NVD · CVE-2026-64604 · In the Linux kernel, the following vulnerability has been resolved: KVM: VMX: Grab vmcs12 on CR8 interception update iff vCPU is in guest mode When updating CR8NVD · CVE-2026-64603 · In the Linux kernel, the following vulnerability has been resolved: platform/x86: intel-hid: Protect ACPI notify handler against recursion Since commit e2ffcda1NVD · CVE-2026-64602 · In the Linux kernel, the following vulnerability has been resolved: iio: adc: spear: Initialize completion before requesting IRQ In the report from Jaeyoung ChuNVD · CVE-2026-64601 · In the Linux kernel, the following vulnerability has been resolved: ALSA: us144mkii: capture_urb_complete: redundant usb_anchor_urb corrupts anchor list on eachCISA KEV · CVE-2026-63077 · 9.8 · JetBrains TeamCity Deserialization of Untrusted Data Vulnerability · Added 2026-08-05 · Due 2026-08-08CISA KEV · CVE-2026-18556 · 7.4 · N-able N-central Authentication Bypass Using an Alternate Path or Channel Vulnerability · Added 2026-08-04 · Due 2026-08-07

Vendors · wago

wago

· 32 Critical

Total CVEs

114

Critical

32

Products

347

Search All CVEs →

114

Products (347)

pfc20041 CVEspfc200 firmware40 CVEs750-820229 CVEs750-88128 CVEs750-8202 firmware27 CVEs750-881 firmware27 CVEs750-831 firmware26 CVEs750-880 firmware26 CVEs750-88026 CVEs750-889 firmware26 CVEs750-88926 CVEs750-83126 CVEs750-85225 CVEs750-852 firmware25 CVEs750-820724 CVEs750-820624 CVEs750-86224 CVEs750-82324 CVEs750-88524 CVEs750-891 firmware24 CVEs750-885 firmware24 CVEs750-88224 CVEs750-882 firmware24 CVEs750-823 firmware24 CVEs750-83224 CVEs750-89124 CVEs750-832 firmware24 CVEs750-862 firmware24 CVEs750-8210 firmware23 CVEs750-821123 CVEs750-8206 firmware23 CVEs750-821623 CVEs750-89023 CVEs750-821223 CVEs750-8211 firmware23 CVEs750-82923 CVEs750-890 firmware23 CVEs750-8216 firmware23 CVEs750-820323 CVEs750-8207 firmware23 CVEs750-820823 CVEs750-821423 CVEs750-820423 CVEs750-8213 firmware23 CVEs750-8214 firmware23 CVEs750-821723 CVEs750-821023 CVEs750-821323 CVEs750-829 firmware23 CVEs750-8212 firmware23 CVEs750-8217 firmware23 CVEs750-8204 firmware22 CVEs750-8208 firmware22 CVEs750-893 firmware22 CVEs750-89322 CVEs750-8203 firmware22 CVEspfc10015 CVEspfc100 firmware13 CVEs752-8303\/8000-002 firmware10 CVEs752-8303\/8000-00210 CVEspfc 200 firmware9 CVEs750-8202\/000-0229 CVEstouch panel 600 marine firmware9 CVEstouch panel 600 advanced firmware9 CVEs750-8202\/000-0129 CVEspfc 2009 CVEstouch panel 600 standard firmware9 CVEspfc 100 firmware9 CVEs750-8202\/040-0018 CVEstouch panel 600 marine8 CVEstouch panel 600 standard8 CVEs750-8202\/000-022 firmware8 CVEs750-8202\/000-012 firmware8 CVEspfc 1008 CVEs750-8202\/025-0018 CVEstouch panel 600 advanced8 CVEs750-8202\/040-0008 CVEs750-8202\/025-0008 CVEs762-6202\/8000-0017 CVEs762-6304\/8000-002 firmware7 CVEs762-6304\/8000-0027 CVEs762-6303\/8000-002 firmware7 CVEs762-6303\/8000-0027 CVEs762-6302\/8000-002 firmware7 CVEs762-6302\/8000-0027 CVEs762-6301\/8000-002 firmware7 CVEs762-6301\/8000-0027 CVEs762-6204\/8000-0017 CVEs762-6203\/8000-0017 CVEs750-81007 CVEs750-8100 firmware7 CVEs750-81017 CVEs750-8101 firmware7 CVEs750-81027 CVEs750-8102\/025-0007 CVEs750-8102 firmware7 CVEs750-8202\/000-0117 CVEs750-8202\/000-011 firmware7 CVEs750-8202\/025-000 firmware7 CVEs750-8202\/025-001 firmware7 CVEs750-8202\/025-0027 CVEs750-8202\/040-000 firmware7 CVEs762-6201\/8000-0017 CVEs762-5306\/8000-002 firmware7 CVEs762-5306\/8000-0027 CVEs762-5305\/8000-002 firmware7 CVEs762-5305\/8000-0027 CVEs762-5304\/8000-0027 CVEs762-5303\/8000-0027 CVEs762-5206\/8000-001 firmware7 CVEs762-5206\/8000-0017 CVEs762-5205\/8000-001 firmware7 CVEs762-5205\/8000-0017 CVEs762-4304\/8000-0027 CVEs762-4303\/8000-0027 CVEs762-4302\/8000-0027 CVEs762-4301\/8000-0027 CVEs762-6202\/8000-001 firmware6 CVEs762-5204\/8000-0016 CVEs762-4305\/8000-0026 CVEs0852-1305 firmware6 CVEs762-4304\/8000-002 firmware6 CVEs762-5204\/8000-001 firmware6 CVEs762-6203\/8000-001 firmware6 CVEs762-6204\/8000-001 firmware6 CVEs0852-0303 firmware6 CVEs762-4202\/8000-001 firmware6 CVEs762-4202\/8000-0016 CVEs751-93016 CVEs751-9301 firmware6 CVEs762-4201\/8000-001 firmware6 CVEs762-4201\/8000-0016 CVEs762-5203\/8000-0016 CVEs762-4306\/8000-002 firmware6 CVEs762-4306\/8000-0026 CVEs762-5203\/8000-001 firmware6 CVEs762-4303\/8000-002 firmware6 CVEs0852-15056 CVEs762-4302\/8000-002 firmware6 CVEs0852-1305\/000-001 firmware6 CVEs0852-1305\/000-0016 CVEs0852-1505\/000-0016 CVEs0852-13056 CVEs0852-1505\/000-001 firmware6 CVEs0852-1505 firmware6 CVEs762-5303\/8000-002 firmware6 CVEs762-4301\/8000-002 firmware6 CVEs0852-03036 CVEs762-4206\/8000-002 firmware6 CVEs762-4206\/8000-0026 CVEs762-5304\/8000-002 firmware6 CVEs762-4206\/8000-001 firmware6 CVEs762-4206\/8000-0016 CVEs762-4205\/8000-002 firmware6 CVEs762-4205\/8000-0026 CVEs762-4205\/8000-001 firmware6 CVEs750-8202\/040-001 firmware6 CVEs750-8202\/025-002 firmware6 CVEs762-6201\/8000-001 firmware6 CVEs750-8102\/025-000 firmware6 CVEs750-8101\/025-000 firmware6 CVEs762-4205\/8000-0016 CVEs762-4204\/8000-001 firmware6 CVEs762-4204\/8000-0016 CVEs750-8101\/025-0006 CVEs762-4203\/8000-001 firmware6 CVEs762-4203\/8000-0016 CVEs762-4305\/8000-002 firmware6 CVEs762-41045 CVEs762-41015 CVEs762-4103 firmware5 CVEs750-8207\/025-0005 CVEs750-8206\/025-0015 CVEs750-8206\/025-0005 CVEs762-4102 firmware5 CVEs762-41025 CVEs762-41035 CVEs762-4101 firmware5 CVEs750-8208\/025-0005 CVEs750-8207\/025-0015 CVEs762-4104 firmware5 CVEs750-8206\/040-0014 CVEs750-3624 CVEs750-362 firmware4 CVEs750-3634 CVEs750-363 firmware4 CVEs750-8206\/040-0004 CVEs750-8208\/025-0014 CVEs750-8210\/025-0004 CVEs750-8210\/040-0004 CVEs750-8211\/040-0004 CVEs750-8212\/025-0004 CVEs750-8212\/025-0014 CVEs750-8212\/025-0024 CVEs750-8212\/040-0004 CVEs750-8212\/040-0104 CVEs750-8213\/040-0104 CVEs750-82154 CVEs750-8215 firmware4 CVEs750-8216\/025-0004 CVEs750-8216\/025-0014 CVEs750-8217\/025-0004 CVEs750-832\/000-0024 CVEs750-832\/000-002 firmware4 CVEs750-890\/025-0004 CVEs750-890\/025-000 firmware4 CVEs750-890\/025-0014 CVEs750-890\/025-001 firmware4 CVEs750-890\/025-0024 CVEs750-890\/025-002 firmware4 CVEs750-890\/040-0004 CVEs750-890\/040-000 firmware4 CVEse\!cockpit4 CVEsedge controller4 CVEsedge controller firmware4 CVEs750-831\/000-002 firmware3 CVEs750-880\/040-000 firmware3 CVEs750-880\/040-0003 CVEs750-880\/025-002 firmware3 CVEs750-880\/025-0023 CVEs762-30003 CVEs762-3000 firmware3 CVEs762-30013 CVEs762-3001 firmware3 CVEs762-30023 CVEs762-3002 firmware3 CVEs762-30033 CVEs762-3003 firmware3 CVEs750-880\/025-001 firmware3 CVEs750-880\/025-0013 CVEs750-880\/025-000 firmware3 CVEs750-880\/025-0003 CVEs750-849 firmware3 CVEs750-8493 CVEs750-831\/000-0023 CVEs750-8217\/625-000 firmware3 CVEs750-8217\/625-0003 CVEs750-8217\/600-000 firmware3 CVEs750-8217\/600-0003 CVEs750-8217\/025-000 firmware3 CVEs750-8216\/040-000 firmware3 CVEs750-8216\/040-0003 CVEs750-8216\/025-001 firmware3 CVEs750-8216\/025-000 firmware3 CVEs750-8213\/040-010 firmware3 CVEs750-8212\/040-010 firmware3 CVEs750-8212\/040-001 firmware3 CVEs750-8212\/040-0013 CVEs750-8212\/040-000 firmware3 CVEs750-8212\/025-002 firmware3 CVEs750-8212\/025-001 firmware3 CVEs750-8212\/025-000 firmware3 CVEs750-8212\/000-100 firmware3 CVEs750-8212\/000-1003 CVEs750-8211\/040-0013 CVEs750-8211\/040-000 firmware3 CVEs750-8210\/040-000 firmware3 CVEs750-8210\/025-000 firmware3 CVEs750-8208\/025-001 firmware3 CVEs750-8208\/025-000 firmware3 CVEs750-8207\/025-001 firmware3 CVEs750-8207\/025-000 firmware3 CVEs750-8206\/040-001 firmware3 CVEs750-8206\/040-000 firmware3 CVEs750-8206\/025-001 firmware3 CVEs750-8206\/025-000 firmware3 CVEs750-8204\/025-0003 CVEs750-8203\/025-0003 CVEs750-352 firmware3 CVEs750-3523 CVEscompact controller 1003 CVEscompact controller 100 firmware3 CVEs750-331 firmware3 CVEs750-3313 CVEs0852-1328 firmware2 CVEs758-8702 CVEs758-870 firmware2 CVEs0852-1322 firmware2 CVEs0852-13222 CVEs750-885\/025-000 firmware2 CVEs852-13052 CVEs852-1305 firmware2 CVEswago i\/o system 758 industrial pc device2 CVEs750-8204\/025-000 firmware2 CVEs852-15052 CVEs0852-13282 CVEs750-8203\/025-000 firmware2 CVEspfc firmware2 CVEs852-1505 firmware2 CVEs852-3032 CVEs750-8211\/040-001 firmware2 CVEs750-885\/025-0002 CVEs852-303 firmware2 CVEs750-363\/040-000 firmware1 CVEs750-363\/040-0001 CVEs750-362\/040-000 firmware1 CVEs750-362\/040-0001 CVEs750-362\/000-001 firmware1 CVEs750-362\/000-0011 CVEs0852-0602 firmware1 CVEs0852-06021 CVEs852-111\/000-0011 CVEs852-111\/000-001 firmware1 CVEs750-873 firmware1 CVEs750-8731 CVEs750-872 firmware1 CVEs750-8721 CVEs750-871 firmware1 CVEs750-8711 CVEs750-8841 CVEs750-830 firmware1 CVEs750-8301 CVEs750-82 firmware1 CVEsbacnet\/ip1 CVEsbacnet\/ip firmware1 CVEscc1001 CVEscc100 firmware1 CVEswago 750-881 ethernet controller devices1 CVEsdtminspector 31 CVEswago 750-881 ethernet controller devices firmware1 CVEswagoapprtu1 CVEsethernet1 CVEsethernet firmware1 CVEsfdtcontainer application1 CVEsfdtcontainer component1 CVEsknx ip1 CVEsknx ip firmware1 CVEs750-330 firmware1 CVEs750-884 firmware1 CVEs750-3301 CVEs0852-1605 firmware1 CVEs0852-16051 CVEstelecontrol configurator1 CVEs0852-0603 firmware1 CVEs0852-06031 CVEs750-821 CVEs750-xxxx series firmware1 CVEs750-8101\/000-010 firmware1 CVEs750-8101\/000-0101 CVEs752-8303\/8000-00021 CVEs752-8303\/8000-0002 firmware1 CVEs750-365\/040-010 firmware1 CVEs750-365\/040-0101 CVEs758-874-0000-01111 CVEs758-xxxx series firmware1 CVEs750-364\/040-010 firmware1 CVEs750-364\/040-0101 CVEs

Recent Vulnerabilities

View all 114
CVE-2025-41732CRITICAL 9.8

An unauthenticated remote attacker can abuse unsafe sscanf calls within the check_cookie() function to write arbitrary data into fixed-size stack buffers which leads to full device compromise.

CVE-2025-41730CRITICAL 9.8

An unauthenticated remote attacker can abuse unsafe sscanf calls within the check_account() function to write arbitrary data into fixed-size stack buffers which leads to full device compromise.

CVE-2023-5188HIGH 7.5

The MMS Interpreter of WagoAppRTU in versions below 1.4.6.0 which is used by the WAGO Telecontrol Configurator is vulnerable to malformed packets. An remote unauthenticated attacker could send specifically crafted packets that lead to a denial-of-service condition until restart of the affected device.

CVE-2023-4149CRITICAL 9.8

A vulnerability in the web-based management allows an unauthenticated remote attacker to inject arbitrary system commands and gain full system control. Those commands are executed with root privileges. The vulnerability is located in the user request handling of the web-based management.

CVE-2023-3379MEDIUM 5.3

Wago web-based management of multiple products has a vulnerability which allows an local authenticated attacker to change the passwords of other non-admin users and thus to escalate non-root privileges.

CVE-2023-4089LOW 2.7

On affected Wago products an remote attacker with administrative privileges can access files to which he has already access to through an undocumented local file inclusion. This access is logged in a different log file than expected.

CVE-2023-1620MEDIUM 4.9

Multiple WAGO devices in multiple versions may allow an authenticated remote attacker with high privileges to DoS the device by sending a specifically crafted packet to the CODESYS V2 runtime.

CVE-2023-1619MEDIUM 4.9

Multiple WAGO devices in multiple versions may allow an authenticated remote attacker with high privileges to DoS the device by sending a malformed packet.

CVE-2023-1150HIGH 7.5

Uncontrolled resource consumption in Series WAGO 750-3x/-8x products may allow an unauthenticated remote attacker to DoS the MODBUS server with specially crafted packets.

CVE-2023-1698CRITICAL 9.8

In multiple products of WAGO a vulnerability allows an unauthenticated, remote attacker to create new users and change the device configuration which can result in unintended behaviour, Denial of Service and full system compromise.

CVE-2022-45140CRITICAL 9.8

The configuration backend allows an unauthenticated user to write arbitrary data with root privileges to the storage, which could lead to unauthenticated remote code execution and full system compromise.

CVE-2022-45139MEDIUM 5.3

A CORS Misconfiguration in the web-based management allows a malicious third party webserver to misuse all basic information pages on the webserver. In combination with CVE-2022-45138 this could lead to disclosure of device information like CPU diagnostics. As there is just a limited amount of information readable the impact only affects a small subset of confidentiality.

CVE-2022-45138CRITICAL 9.8

The configuration backend of the web-based management can be used by unauthenticated users, although only authenticated users should be able to use the API. The vulnerability allows an unauthenticated attacker to read and set several device parameters that can lead to full compromise of the device.

CVE-2022-45137MEDIUM 6.1

The configuration backend of the web-based management is vulnerable to reflected XSS (Cross-Site Scripting) attacks that targets the users browser. This leads to a limited impact of confidentiality and integrity but no impact of availability.

CVE-2022-3843CRITICAL 9.1

In WAGO Unmanaged Switch (852-111/000-001) in firmware version 01 an undocumented configuration interface without authorization allows an remote attacker to read system information and configure a limited set of parameters.

CVE-2022-3738MEDIUM 5.9

The vulnerability allows a remote unauthenticated attacker to download a backup file, if one exists. That backup file might contain sensitive information like credentials and cryptographic material. A valid user has to create a backup after the last reboot for this attack to be successfull.

CVE-2020-12069HIGH 7.8

In CODESYS V3 products in all versions prior V3.5.16.0 containing the CmpUserMgr, the CODESYS Control runtime system stores the online communication passwords using a weak hashing algorithm. This can be used by a local attacker with low privileges to gain full control of the device.

CVE-2021-34569CRITICAL 9.8

In WAGO I/O-Check Service in multiple products an attacker can send a specially crafted packet containing OS commands to crash the diagnostic tool and write memory.

CVE-2021-34568HIGH 7.5

In WAGO I/O-Check Service in multiple products an unauthenticated remote attacker can send a specially crafted packet containing OS commands to provoke a denial of service.

CVE-2021-34567HIGH 8.2

In WAGO I/O-Check Service in multiple products an unauthenticated remote attacker can send a specially crafted packet containing OS commands to provoke a denial of service and an limited out-of-bounds read.

CVE-2021-34566CRITICAL 9.1

In WAGO I/O-Check Service in multiple products an unauthenticated remote attacker can send a specially crafted packet containing OS commands to crash the iocheck process and write memory resulting in loss of integrity and DoS.

CVE-2022-3281HIGH 7.5

WAGO Series PFC100/PFC200, Series Touch Panel 600, Compact Controller CC100 and Edge Controller in multiple versions are prone to a loss of MAC-Address-Filtering after reboot. This may allow an remote attacker to circumvent the reach the network that should be protected by the MAC address filter.

CVE-2022-22511MEDIUM 5.4

Various configuration pages of the device are vulnerable to reflected XSS (Cross-Site Scripting) attacks. An authorized attacker with user privileges may use this to gain access to confidential information on a PC that connects to the WBM after it has been compromised.

CVE-2021-34596MEDIUM 6.5

A crafted request may cause a read access to an uninitialized pointer in CODESYS V2 Runtime Toolkit 32 Bit full and PLCWinNT prior to versions V2.4.7.56, resulting in a denial-of-service condition.

CVE-2021-34595HIGH 8.1

A crafted request with invalid offsets may cause an out-of-bounds read or write access in CODESYS V2 Runtime Toolkit 32 Bit full and PLCWinNT prior to versions V2.4.7.56, resulting in a denial-of-service condition or local memory overwrite.