CVEs we hold for Control
Records whose assigning authority named Control as the affected vendor. Newest identifiers first, capped at 200.
CVE-2026-57517Control Web Panel < 0.9.8.1225 Blind SQL Injection via userRes ParameterControl Web Panel
CVE-2026-4901Insertion of Sesitive Information into Log File in AlanWeb SCADAControl System AlanWeb SCADA
CVE-2026-23990Flux Operator Web UI Impersonation Bypass via Empty OIDC Claimscontrolplaneio-fluxcd flux-operator
CVE-2025-49853Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') in ControlID iDSecure On-premisesControlID iDSecure On-premises
CVE-2025-49852Server-Side Request Forgery (SSRF) in ControlID iDSecure On-premisesControlID iDSecure On-premises
CVE-2025-49851Improper Authentication in ControlID iDSecure On-premisesControlID iDSecure On-premises
CVE-2023-42123Control Web Panel mysql_manager Command Injection Remote Code Execution VulnerabilityControl Web Panel
CVE-2023-42122Control Web Panel wloggui Command Injection Local Privilege Escalation VulnerabilityControl Web Panel
CVE-2023-42121Control Web Panel Missing Authentication Remote Code Execution VulnerabilityControl Web Panel
CVE-2023-42120Control Web Panel dns_zone_editor Command Injection Remote Code Execution VulnerabilityControl Web Panel
CVE-2021-24215Controlled Admin Access < 1.5.2 - Improper Access Control & Privilege EscalationUnknown Controlled Admin Access
34 records, read from the index as it stood on 20 Sep 2026. Every row opens the record it names, and every value on that record opens its own receipt.
Everything on this page is free. Public data. Withholding it protects nothing.