vciy

CVEs we hold for Control

Records whose assigning authority named Control as the affected vendor. Newest identifiers first, capped at 200.

CVE-2026-92626Control iD iDSecure Unauthenticated Denial of ServiceControl iD iDSecure
CVE-2026-92625Control iD iDSecure Unauthenticated Denial of ServiceControl iD iDSecure
CVE-2026-57517Control Web Panel < 0.9.8.1225 Blind SQL Injection via userRes ParameterControl Web Panel
CVE-2026-4901Insertion of Sesitive Information into Log File in AlanWeb SCADAControl System AlanWeb SCADA
CVE-2026-34185SQL Injection in AlanWeb SCADAControl System AlanWeb SCADA
CVE-2026-34184Missing Authorization inAlanWeb SCADAControl System AlanWeb SCADA
CVE-2026-23990Flux Operator Web UI Impersonation Bypass via Empty OIDC Claimscontrolplaneio-fluxcd flux-operator
CVE-2025-49853Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') in ControlID iDSecure On-premisesControlID iDSecure On-premises
CVE-2025-49852Server-Side Request Forgery (SSRF) in ControlID iDSecure On-premisesControlID iDSecure On-premises
CVE-2025-49851Improper Authentication in ControlID iDSecure On-premisesControlID iDSecure On-premises
CVE-2025-2125Control iD RH iD PDF Document companyId resource injectionControl iD RH iD
CVE-2025-2124Control iD RH iD API change_password cross site scriptingControl iD RH iD
CVE-2023-6333Cross-site Scripting in ControlByWeb RelaysControlByWeb X-301-24I
CVE-2023-6329Control iD iDSecure passwordCustom Authentication BypassControl iD iDSecure
CVE-2023-4392Control iD Gerencia Web Cookie cleartext storageControl iD Gerencia Web
CVE-2023-42123Control Web Panel mysql_manager Command Injection Remote Code Execution VulnerabilityControl Web Panel
CVE-2023-42122Control Web Panel wloggui Command Injection Local Privilege Escalation VulnerabilityControl Web Panel
CVE-2023-42121Control Web Panel Missing Authentication Remote Code Execution VulnerabilityControl Web Panel
CVE-2023-42120Control Web Panel dns_zone_editor Command Injection Remote Code Execution VulnerabilityControl Web Panel
CVE-2023-2524Control iD RHiD direct requestControl iD RHiD
CVE-2023-2421Control iD RHiD department cross site scriptingControl iD RHiD
CVE-2023-23553X-400 Cross-Site ScriptingControl By Web X-400 devices
CVE-2023-23551X-600M Code InjectionControl By Web X-600M devices
CVE-2023-2044Control iD iDSecure Dispositivos Page cross site scriptingControl iD iDSecure
CVE-2023-2043Control iD RHiD Edit a sql injectionControl iD RHiD
CVE-2023-0125Control iD Gerencia Web Web Interface cross site scriptingControl iD Gerencia Web
CVE-2022-4896no title heldControl de Ciber
CVE-2022-48475no title heldControl de Ciber
CVE-2022-48474no title heldControl de Ciber
CVE-2021-24215Controlled Admin Access < 1.5.2 - Improper Access Control & Privilege EscalationUnknown Controlled Admin Access
CVE-2020-28268no title heldn/a controlled-merge
CVE-2020-10628no title heldn/a ControlEdge RTU
CVE-2020-10624no title heldn/a ControlEdge RTU
CVE-2019-14599no title heldn/a Control Center-I

34 records, read from the index as it stood on 20 Sep 2026. Every row opens the record it names, and every value on that record opens its own receipt.

Everything on this page is free. Public data. Withholding it protects nothing.