vciy

CVEs we hold for Phoenix

Records whose assigning authority named Phoenix as the affected vendor. Newest identifiers first, capped at 200.

CVE-2026-7849Command Injection in SCM (idledisconnect parameter)Phoenix Contact CHARX SEC-3000
CVE-2026-64941Open redirect in Phoenix.LiveView.validate_local_url!/2 via ASCII tab, LF and CRphoenixframework phoenix_live_view
CVE-2026-58228Scheme validation bypass in Phoenix.LiveView.Utils leads to XSS via <.link>phoenixframework phoenix_live_view
CVE-2026-56812Phoenix JavaScript presence client crashes on presence keys colliding with Object.prototype members in…phoenixframework phoenix
CVE-2026-56811Phoenix transports do not limit channel joins per connection, enabling process-exhaustion denial of servicephoenixframework phoenix
CVE-2026-44108Firewall bypass during shutdownPhoenix Contact CHARX SEC-3000
CVE-2026-44107Exposed Reboot via ModbusPhoenix Contact CHARX SEC-3000
CVE-2026-44106Local Privilege Escalation vulnerability in /etc/init.d/user-applications via customer website filePhoenix Contact CHARX SEC-3000
CVE-2026-44105Cleartext password in logsPhoenix Contact CHARX SEC-3000
CVE-2026-44104ControllerAgent does not perform validation of firmwarePhoenix Contact CHARX SEC-3000
CVE-2026-44103JupiCore does not perform validation of firmwarePhoenix Contact CHARX SEC-3000
CVE-2026-44102OCPP Firmware download is not properly lockedPhoenix Contact CHARX SEC-3000
CVE-2026-44101OCPP reconfiguration vulnerabilityPhoenix Contact CHARX SEC-3000
CVE-2026-44100JupiCore charging point reconfiguration without authPhoenix Contact CHARX SEC-3000
CVE-2026-44099Local Privilege Escalation via pppd password injectionPhoenix Contact CHARX SEC-3000
CVE-2026-44098OS Command Injection in OCPP Agent via charge_box_idPhoenix Contact CHARX SEC-3000
CVE-2026-44097File Upload vulnerabilityPhoenix Contact CHARX SEC-3000
CVE-2026-44096udhcpc Privilege EscalationPhoenix Contact CHARX SEC-3000
CVE-2026-44095Local Privilege Escalation via Network scriptsPhoenix Contact CHARX SEC-3000
CVE-2026-44094Fallback to second RAUC slot with default credentialsPhoenix Contact CHARX SEC-3000
CVE-2026-44093Local Privilege Escalation vulnerability in /etc/init.d/user-applications via user-application start scriptPhoenix Contact CHARX SEC-3000
CVE-2026-44092Missing input validation / stripping of CRLF characters in SystemConfigManagerPhoenix Contact CHARX SEC-3000
CVE-2026-44091Creation of a new configuration by posting a malicious ID to MQTTPhoenix Contact CHARX SEC-3000
CVE-2026-44090Missing authentication for MQTT BrokerPhoenix Contact CHARX SEC-3000
CVE-2026-41032Phoenix Contact: Unauthenticated log download vulnerability in the firmware of CHARX SEC-3xxx charging controllersPhoenix Contact CHARX SEC-3000
CVE-2026-32689Long-poll NDJSON body splitting causes unbounded memory allocation in Phoenixphoenixframework phoenix
CVE-2026-22323Cross‑Site Request Forgery in Link Aggregation ConfigurationPhoenix Contact FL SWITCH 5916SFP-8GC-4SFP+
CVE-2026-22322Stored Cross‑Site Scripting in Link Aggregation Name HandlingPhoenix Contact FL SWITCH 5916SFP-8GC-4SFP+
CVE-2026-22321Stack-Based Buffer Overflow in CLI Login Username Handling over CLIPhoenix Contact FL SWITCH 5916SFP-8GC-4SFP+
CVE-2026-22320Stack-Based Buffer Overflow in TFTP File-Transfer Command Handling over CLIPhoenix Contact FL SWITCH 5916SFP-8GC-4SFP+
CVE-2026-22319Stack-Based Buffer Overflow in File Install Parameter HandlingPhoenix Contact FL SWITCH 5916SFP-8GC-4SFP+
CVE-2026-22318Stack-Based Buffer Overflow in File Transfer Parameter HandlingPhoenix Contact FL SWITCH 5916SFP-8GC-4SFP+
CVE-2026-22317Command Injection Vulnerability in Root CA Certificate Transfer WorkflowPhoenix Contact FL SWITCH 5916SFP-8GC-4SFP+
CVE-2026-22316Buffer Overflow using TFTP FilenamePhoenix Contact FL SWITCH 5916SFP-8GC-4SFP+
CVE-2026-1164Easy Voice Mail <= 1.2.5 - Unauthenticated Stored Cross-Site Scripting via 'message'phoenixstudiodz Easy Voice Mail
CVE-2025-62784InventoryGui allows item duplication in GUIs which use GuiStorageElementPhoenix616 InventoryGui
CVE-2025-62783InventoryGui affected by item duplication in GUIs which use GuiStorageElementPhoenix616 InventoryGui
CVE-2025-62782InventoryGUI vulnerable to item duplication via Bundle items when using GuiStorageElementPhoenix616 InventoryGui
CVE-2025-41771SQL injectionPhoenix Contact EPC 1522
CVE-2025-41770Unauthenticated Denial of ServicePhoenix Contact EPC 1522
CVE-2025-41769Unauthenticated Buffer Overflow in PROFINET ServicePhoenix Contact EPC 1522
CVE-2025-41752Reflected XSS vulnerability in pxc_portSfp.phpPhoenix Contact FL SWITCH 2508/K1
CVE-2025-41751Reflected XSS vulnerability in pxc_portCntr.phpPhoenix Contact FL SWITCH 2508/K1
CVE-2025-41750Reflected XSS vulnerability in pxc_PortCfg.phpPhoenix Contact FL SWITCH 2508/K1
CVE-2025-41749Reflected XSS vulnerability in port_util.phpPhoenix Contact FL SWITCH 2508/K1
CVE-2025-41748Reflected XSS vulnerability in pxc_Dot1xCfg.phpPhoenix Contact FL SWITCH 2508/K1
CVE-2025-41747Reflected XSS vulnerability in pxc_vlanIntfCfg.phpPhoenix Contact FL SWITCH 2508/K1
CVE-2025-41746Reflected XSS vulnerability in pxc_portSecCfg.phpPhoenix Contact FL SWITCH 2508/K1
CVE-2025-41745Reflected XSS vulnerability in pxc_portCntr2.phpPhoenix Contact FL SWITCH 2508/K1
CVE-2025-41717Config-Upload Code InjectionPhoenix Contact TC CLOUD CLIENT 1002-TX/TX
CVE-2025-41707Phoenix Contact: WebSocket Handler Denial of ServicePhoenix Contact QUINT4-UPS/24DC/24DC/40/EIP
CVE-2025-41706Phoenix Contact: Webserver Denial of Service through Malformed Content-LengthPhoenix Contact QUINT4-UPS/24DC/24DC/40/EIP
CVE-2025-41705Phoenix Contact: WebSocket Message Interception Leaks Webfrontend CredentialsPhoenix Contact QUINT4-UPS/24DC/24DC/40/EIP
CVE-2025-41704Phoenix Contact: Unauthenticated Modbus Service DoS via Crafted Function CodePhoenix Contact QUINT4-UPS/24DC/24DC/40/EIP
CVE-2025-41703Phoenix Contact: UPS Shutdown via Unauthenticated Modbus CommandPhoenix Contact QUINT4-UPS/24DC/24DC/40/EIP
CVE-2025-41699Phoenix Contact: Security Advisory for CHARX SEC-3xxx charging controllersPhoenix Contact CHARX SEC-3000
CVE-2025-41697Shell access to UART ConsolePhoenix Contact FL SWITCH 2508/K1
CVE-2025-41696Hardcoded User PasswordPhoenix Contact FL SWITCH 2508/K1
CVE-2025-41695Reflected XSS vulnerability in dyn_conn.phpPhoenix Contact FL SWITCH 2508/K1
CVE-2025-41694Authenticated Denial-of-Service via WebshellPhoenix Contact FL SWITCH 2508/K1
CVE-2025-41693Authenticated Denial-of-Service via SSHPhoenix Contact FL SWITCH 2508/K1
CVE-2025-41692Weak/Predictable root PasswordPhoenix Contact FL SWITCH 2508/K1
CVE-2025-41686Improper File Permissions Allow Local Privilege EscalationPhoenix Contact DaUM
CVE-2025-41670Untrusted Search PathPhoenix Contact VPLCNEXT CONTROL 500
CVE-2025-41669Insufficient Verification of Data AuthenticityPhoenix Contact VPLCNEXT CONTROL 500
CVE-2025-41668Phoenix Contact: File access due to the replacement of a critical file used by the service security-profilePHOENIX CONTACT RFC 4072S
CVE-2025-41667Phoenix Contact: File access due to the replacement of a critical file used by the arp-preinit scriptPHOENIX CONTACT RFC 4072S
CVE-2025-41666Phoenix Contact: File access due to the replacement of a critical file used by the watchdogPHOENIX CONTACT RFC 4072S
CVE-2025-41665Phoenix Contact: DoS of the PLC due to incorrect default permissions possiblePHOENIX CONTACT RFC 4072S
CVE-2025-40727Reflected Cross-Site Scripting (XSS) in Phoenix CMSPhoenix CMS
CVE-2025-2813HTTP Service DoS VulnerabilityPhoenix Contact IL EIP BK DI8 DO4 2TX-PAC
CVE-2025-25271OCPP Backend Configuration via Insecure DefaultsPhoenix Contact CHARX SEC-3000
CVE-2025-25270Remote Code Execution via Unauthenticated Configuration ManipulationPhoenix Contact CHARX SEC-3000
CVE-2025-25269Local Privilege Escalation via Unauthenticated Command InjectionPhoenix Contact CHARX SEC-3000
CVE-2025-25268Unauthenticated Configuration Access via Exposed API EndpointPhoenix Contact CHARX SEC-3000
CVE-2025-24006Privilege Escalation via Insecure SSH PermissionsPhoenix Contact CHARX SEC-3000
CVE-2025-24005Local Privilege Escalation via Vulnerable SSH ScriptPhoenix Contact CHARX SEC-3000
CVE-2025-24004USB-C Buffer Overflow via Display Interface in EV Charging StationsPhoenix Contact CHARX SEC-3000
CVE-2025-24003MQTT OOB Write Vulnerability in EichrechtAgents of German EV Charging StationsPhoenix Contact CHARX SEC-3000
CVE-2025-24002MQTT DoS Vulnerability in German EV Charging StationsPhoenix Contact CHARX SEC-3000
CVE-2024-7734Phoenix Contact: Multiple mGuard devices are vulnerable to a drain of open file descriptors.PHOENIX CONTACT TC MGUARD RS4000 4G VZW VPN
CVE-2024-7699Phoenix Contact: OS command execution in MGUARD productsPHOENIX CONTACT TC MGUARD RS4000 4G VZW VPN
CVE-2024-7698Phoenix Contact: Access to CSRF tokens of higher privileged users in MGUARD productsPHOENIX CONTACT TC MGUARD RS4000 4G VZW VPN
CVE-2024-6788Phoenix Contact: update feature from CHARX controller can be used to reset a low privilege user passwordPHOENIX CONTACT CHARX SEC-3150
CVE-2024-58296CE Phoenix v3.0.1 Stored Cross-Site Scripting via admin/currencies.phpPhoenixCart CE Phoenix
CVE-2024-52410WordPress Referrer Detector plugin <= 4.2.1.0 - PHP Object Injection vulnerabilityPhoenixheart Referrer Detector
CVE-2024-52409WordPress AJAX Random Posts plugin <= 0.3.3 - PHP Object Injection vulnerabilityPhoenixheart AJAX Random Posts
CVE-2024-43393Phoenix Contact: Configuration changes of the firewall services can lead to DoS in MGUARD devicesPHOENIX CONTACT TC MGUARD RS4000 4G VZW VPN
CVE-2024-43392Phoenix Contact: Firewall reconfiguration through the FW_environment variables in MGUARD devicesPHOENIX CONTACT TC MGUARD RS4000 4G VZW VPN
CVE-2024-43391Phoenix Contact: Firewall reconfiguration through the FW_PORTFORWARDING.SRC_IP in MGUARD devicesPHOENIX CONTACT TC MGUARD RS4000 4G VZW VPN
CVE-2024-43390Phoenix Contact: Firewall reconfiguration due to improper input validation in MGUARD devicesPHOENIX CONTACT TC MGUARD RS4000 4G VZW VPN
CVE-2024-43389Phoenix Contact: OSPF reconfiguration due to improper input validation in MGUARD devicesPHOENIX CONTACT TC MGUARD RS4000 4G VZW VPN
CVE-2024-43388Phoenix Contact: SNMP reconfiguration due to improper input validation in MGUARD devicesPHOENIX CONTACT TC MGUARD RS4000 4G VZW VPN
CVE-2024-43387Phoenix Contact: Access files due to improper neutralization of special elements in MGUARD devicesPHOENIX CONTACT TC MGUARD RS4000 4G VZW VPN
CVE-2024-43386Phoenix Contact: OS command execution through EMAIL_NOTIFICATION.TO in mGuard devices.PHOENIX CONTACT TC MGUARD RS4000 4G VZW VPN
CVE-2024-43385Phoenix Contact: OS command execution through PROXY_HTTP_PORT in mGuard devicesPHOENIX CONTACT TC MGUARD RS4000 4G VZW VPN
CVE-2024-43384Phoenix Contact: Improper removal of sensitive information in MGUARD productsPHOENIX CONTACT TC MGUARD RS4000 4G VZW VPN
CVE-2024-3913Phoenix Contact: Start sequence allows attack during the boot processPhoenix Contact CHARX SEC-3150 (1139012)
CVE-2024-29980Unsafe Handling of IHV UEFI VariablesPhoenix SecureCore™ for Intel Ice Lake
CVE-2024-29979Unsafe Handling of Phoenix UEFI VariablesPhoenix SecureCore™ for Intel Ice Lake
CVE-2024-28137PHOENIX CONTACT: privilege escalation due to a TOCTOU vulnerability in the CHARX SeriesPHOENIX CONTACT CHARX SEC-3150
CVE-2024-28136PHOENIX CONTACT: command injection gains root privileges using the OCPP remote servicePHOENIX CONTACT CHARX SEC-3150
CVE-2024-28135PHOENIX CONTACT: command injection vulnerability in the API of the CHARX SeriesPHOENIX CONTACT CHARX SEC-3150
CVE-2024-28134PHOENIX CONTACT: MitM attack gains privileges of the current logged in user in CHARX SeriesPHOENIX CONTACT CHARX SEC-3150
CVE-2024-28133PHOENIX CONTACT: Privilege escalation in CHARX SeriesPHOENIX CONTACT CHARX SEC-3150
CVE-2024-26288PHOENIX CONTACT: Lack of SSL support in CHARX SeriesPHOENIX CONTACT CHARX SEC-3150
CVE-2024-26005PHOENIX CONTACT: Privilege gain through incomplete cleanup in CHARX SeriesPHOENIX CONTACT CHARX SEC-3150
CVE-2024-26004PHOENIX CONTACT: DoS of a control agent due to access of a uninitialized pointer in CHARX SeriesPHOENIX CONTACT CHARX SEC-3150
CVE-2024-26003PHOENIX CONTACT: DoS of the control agent in CHARX SeriesPHOENIX CONTACT CHARX SEC-3150
CVE-2024-26002PHOENIX CONTACT: File ownership manipulation in CHARX SeriesPHOENIX CONTACT CHARX SEC-3150
CVE-2024-26001PHOENIX CONTACT: Out of bounds write only memory accessPHOENIX CONTACT CHARX SEC-3150
CVE-2024-26000PHOENIX CONTACT: Out of bounds read only memory accessPHOENIX CONTACT CHARX SEC-3150
CVE-2024-25999PHOENIX CONTACT: Privilege escalation in the OCPP agent servicePHOENIX CONTACT CHARX SEC-3150
CVE-2024-25998PHOENIX CONTACT: Command injection in the OCPP ServicePHOENIX CONTACT CHARX SEC-3150
CVE-2024-25997PHOENIX CONTACT: Log injection in CHARX SeriesPHOENIX CONTACT CHARX SEC-3150
CVE-2024-25996PHOENIX CONTACT: Remote code execution due to an origin validation error in CHARX SeriesPHOENIX CONTACT CHARX SEC-3150
CVE-2024-25995PHOENIX CONTACT: Remote code execution in CHARX SeriesPHOENIX CONTACT CHARX SEC-3150
CVE-2024-25994PHOENIX CONTACT: Unintended script file upload in CHARX SeriesPHOENIX CONTACT CHARX SEC-3150
CVE-2024-1598Potential buffer overflow when handling UEFI variablesPhoenix SecureCore™ for Intel Gemini Lake
CVE-2024-12533no title heldPhoenix SecureCore Technology 4
CVE-2024-11497Phoenix Contact: CHARX-SEC3xxx Charge controllers vulnerable to privilege escalationPHOENIX CONTACT CHARX SEC-3150
CVE-2024-0762Potential buffer overflow when handling UEFI variablesPhoenix SecureCore™ for Intel Meteor Lake
CVE-2023-5592Phoenix Contact: ProConOs prone to Download of Code Without Integrity CheckPHOENIX CONTACT ProConOS eCLR (SDK)
CVE-2023-5058no title heldPhoenix SecureCore™ Technology™ 4
CVE-2023-46144PHOENIX CONTACT: PLCnext Control prone to download of code without integrity checkPHOENIX CONTACT RFC 4072S
CVE-2023-46143Phoenix Contact: Classic line industrial controllers prone to inadequate integrity check of PLCPHOENIX CONTACT RFC 480S PN 4TX
CVE-2023-46142PHOENIX CONTACT: Insufficient Read and Write Protection to Logic and Runtime Data in PLCnext ControlPHOENIX CONTACT RFC 4072S
CVE-2023-46141Phoenix Contact: Automation Worx and classic line controllers prone to Incorrect Permission Assignment for Critical…PHOENIX CONTACT RFC 480S PN 4TX
CVE-2023-37864PHOENIX CONTACT: WP 6xxx Web panels prone to download code without integrity checkPHOENIX CONTACT WP 6215-WHPS
CVE-2023-37863PHOENIX CONTACT: OS Command Injection in WP 6xxx Web panelsPHOENIX CONTACT WP 6215-WHPS
CVE-2023-37862PHOENIX CONTACT: Missing Authorization in WP 6xxx Web panelsPHOENIX CONTACT WP 6215-WHPS
CVE-2023-37861PHOENIX CONTACT: OS Command Injection in WP 6xxx Web panelsPHOENIX CONTACT WP 6215-WHPS
CVE-2023-37860PHOENIX CONTACT: Missing Authorization in WP 6xxx Web panelsPHOENIX CONTACT WP 6215-WHPS
CVE-2023-37859PHOENIX CONTACT: Improper Privilege Management in WP 6xxx Web panelsPHOENIX CONTACT WP 6215-WHPS
CVE-2023-37858PHOENIX CONTACT: Use of Hard-coded Credentials in WP 6xxx Web panelsPHOENIX CONTACT WP 6215-WHPS
CVE-2023-37857PHOENIX CONTACT: Use of Hard-coded Credentials in WP 6xxx Web panelsPHOENIX CONTACT WP 6215-WHPS
CVE-2023-37856PHOENIX CONTACT: Unauthorized read-access of root filesystem in WP 6xxx Web panelsPHOENIX CONTACT WP 6215-WHPS
CVE-2023-37855PHOENIX CONTACT: Unauthorized read-access of root filesystem in WP 6xxx Web panelsPHOENIX CONTACT WP 6215-WHPS
CVE-2023-35841WinFlash Driver Permissions IssuePhoenix WinFlash Driver
CVE-2023-3573PHOENIX CONTACT: Command Injection in WP 6xxx Web panelsPHOENIX CONTACT WP 6215-WHPS
CVE-2023-3572PHOENIX CONTACT: OS Command Injection in WP 6xxx Web panelsPHOENIX CONTACT WP 6215-WHPS
CVE-2023-3571PHOENIX CONTACT: OS Command Injection in WP 6xxx Web panelsPHOENIX CONTACT WP 6215-WHPS
CVE-2023-3570PHOENIX CONTACT: OS Command Injection in WP 6xxx Web panelsPHOENIX CONTACT WP 6215-WHPS
CVE-2023-3569PHOENIX CONTACT: Denial-of-Service due to malicious XML files in TC ROUTER, TC CLOUD CLIENT and CLOUD CLIENTPHOENIX CONTACT TC ROUTER 3002T-4G VZW
CVE-2023-3526PHOENIX CONTACT: Cross-site Scripting vulnerability in TC ROUTER, TC CLOUD CLIENT and CLOUD CLIENT devicesPHOENIX CONTACT TC ROUTER 3002T-4G VZW
CVE-2023-31100no title heldPhoenix SecureCore™ Technology™ 4
CVE-2023-2673PHOENIX CONTACT: FL/TC MGUARD prone to Improper Input ValidationPHOENIX CONTACT FL MGUARD SMART2 VPN
CVE-2023-1109PHOENIX CONTACT: Directory Traversal Vulnerability in ENERGY AXC PU Web servicePHOENIX CONTACT Infobox (1169323 )
CVE-2023-0757Phoenix Contact ProConOS prone to Incorrect Permission Assignment for Critical ResourcePHOENIX CONTACT ProConOS eCLR (SDK)
CVE-2022-3737Out-of-bounds Read in PHOENIX CONTACT Automationworx Software SuitePHOENIX CONTACT PC Worx Express
CVE-2022-3480Denial-of-Service vulnerability in PHOENIX CONTACT mGuard product familyPHOENIX CONTACT TC MGUARD RS4000 4G VZW VPN
CVE-2022-3461Buffer Overflow in PHOENIX CONTACT Automationworx Software SuitePHOENIX CONTACT PC Worx Express
CVE-2022-31801Insufficient Verification of Data Vulnerability in ProConOS/ProConOS eCLR SDK and MULTIPROG Engineering toolPHOENIX CONTACT ProConOS eCLR
CVE-2022-31800Insufficient Verification of Data Vulnerability in PHOENIX CONTACT classic line industrial controllersPHOENIX CONTACT FC 350 PCI ETH
CVE-2022-29898Remote Code Execution in all versions of various RAD-ISM-900-EN-* devices by PHOENIX CONTACTPHOENIX CONTACT RAD-ISM-900-EN-BD-BUS
CVE-2022-29897Remote Code Execution in all versions of various RAD-ISM-900-EN-* devices by PHOENIX CONTACTPHOENIX CONTACT RAD-ISM-900-EN-BD-BUS
CVE-2021-34598Phoenix Contact: FL MGUARD lack of memory release in remote logging functionalityPHOENIX CONTACT FL MGUARD
CVE-2021-34597Phoenix Contact: PC Worx/-Express prone to improper input validation vulnerabilityPhoenix Contact PC Worx
CVE-2021-34582Phoenix Contact: FL MGUARD XSS through web-based management and REST APIPHOENIX CONTACT FL MGUARD
CVE-2021-34579PHOENIX CONTACT: FL MGUARD DM version 1.12.0 and 1.13.0 Improper Privilege ManagementPHOENIX CONTACT FL MGUARD DM (2981974)
CVE-2021-34570Phoenix Contact: DoS for PLCnext Control devices in versions prior to 2021.0.5 LTSPhoenix Contact PLCnext
CVE-2021-34565In WirelessHART-Gateway versions 3.0.7 to 3.0.9 hard-coded credentials have been foundPhoenix Contact WHA-GW-F2D2-0-AS- Z2-ETH.EIP
CVE-2021-34564In WirelessHART-Gateway versions 3.0.9 a vulnerability allows to read and write sensitive data in a cookiePhoenix Contact WHA-GW-F2D2-0-AS- Z2-ETH.EIP
CVE-2021-34563In WirelessHART-Gateway versions 3.0.8 and 3.0.9 the HttpOnly flag is missing in a cookie which allows client-side…Phoenix Contact WHA-GW-F2D2-0-AS- Z2-ETH.EIP
CVE-2021-34562A vulnerability in WirelessHART-Gateway 3.0.8 it is possible to inject arbitrary JavaScript into the application's…Phoenix Contact WHA-GW-F2D2-0-AS- Z2-ETH.EIP
CVE-2021-34561A vulnerability in WirelessHART-Gateway <= 3.0.8 allows to bypass any IP or firewall based access restrictions through…Phoenix Contact WHA-GW-F2D2-0-AS- Z2-ETH.EIP
CVE-2021-34560A vulnerability in WirelessHART-Gateway <= 3.0.9 could lead to information exposure of sensitive informationPhoenix Contact WHA-GW-F2D2-0-AS- Z2-ETH.EIP
CVE-2021-34559A vulnerability in WirelessHART-Gateway <= 3.0.8 may allow remote attackers to rewrite links and URLs in cached pages…Phoenix Contact WHA-GW-F2D2-0-AS- Z2-ETH.EIP
CVE-2021-33555A vulnerability may allow remote attackers to read arbitrary files on the server of the WirelessHART-GatewayPhoenix Contact WHA-GW-F2D2-0-AS- Z2-ETH.EIP
CVE-2021-33542Phoenix Contact: Automation Worx Software Suite affected by Remote Code Execution (RCE) vulnerabilityPhoenix Contact Automation Worx Software Suite
CVE-2021-33541Phoenix Contact: ILC1x Industrial controllers affected by Denial-of-Service vulnerabilityPhoenix Contact ILC1x
CVE-2021-33540Phoenix Contact: Undocumented FTP acces in certain AXL F BK and IL BK devicesPhoenix Contact IL
CVE-2021-24816Phoenix Media Rename < 3.4.4 - Author Arbitrary Media File RenamingUnknown Phoenix Media Rename
CVE-2021-21005Race Condition Vulnerability in Phoenix Contact FL SWITCH SMCS series productsPhoenix Contact FL NAT
CVE-2021-21004Cross-site Scripting Vulnerability in Phoenix Contact FL SWITCH SMCS series productsPhoenix Contact FL NAT
CVE-2021-21003Denial of Service Vulnerability in Phoenix Contact FL SWITCH SMCS series productsPhoenix Contact FL NAT
CVE-2021-21002Denial of Service in Phoenix Contact FL COMSERVER UNI productsPhoenix Contact FL COMSERVER
CVE-2020-12524Phoenix Contact BTP Touch Panels uncontrolled resource consumptionPhoenix Contact BTP Touch Panel
CVE-2020-12523Phoenix Contact mGuard Devices versions before 8.8.3: LAN ports get functional after reboot even if they are disabled…Phoenix Contact TC MGUARD RS4000 4G VPN (2903586)…
CVE-2020-12521Phoenix Contact PLCnext Control Devices versions before 2021.0 LTS: A specially crafted LLDP packet may lead to a high…Phoenix Contact PLCnext Technology Starterkit (1188165)
CVE-2020-12519Phoenix Contact PLCnext Control Devices versions before 2021.0 LTS: An attacker can use this vulnerability i.e. to open…Phoenix Contact PLCnext Technology Starterkit (1188165)
CVE-2020-12518Phoenix Contact PLCnext Control Devices versions before 2021.0 LTS: An attacker can use the knowledge gained by reading…Phoenix Contact PLCnext Technology Starterkit (1188165)
CVE-2020-12517Phoenix Contact PLCnext Control Devices versions before 2021.0 LTS: An authenticated low privileged user could embed…Phoenix Contact PLCnext Technology Starterkit (1188165)
CVE-2020-12499PHOENIX CONTACT PLCnext Engineer version 2020.3.1 and earlier: Improper path sanitation vulnerability.PHOENIX CONTACT PLCnext Engineer
CVE-2020-12498Phoenix Contact Automation Worx <= 1.87: out-of-bounds read remote code executionPhoenix Contact Automation Worx Express
CVE-2020-12497Phoenix Contact Automation Worx <= 1.87: stack-based overflowPhoenix Contact Automation Worx Express
CVE-2018-5441no title heldn/a PHOENIX CONTACT mGuard
CVE-2018-25112PHOENIX CONTACT: ILC 1x1 ETH Denial of ServicePHOENIX CONTACT ILC 191 ETH
CVE-2017-7937no title heldn/a Phoenix Contact GmbH mGuard
CVE-2017-7935no title heldn/a Phoenix Contact GmbH mGuard
CVE-2017-6039no title heldn/a Phoenix Broadband Technologies LLC PowerAgent SC3 Site…
CVE-2017-5159no title heldn/a Phoenix Contact mGuard 8.4.0
CVE-2017-16743no title heldn/a PHOENIX CONTACT FL SWITCH
CVE-2017-16741no title heldn/a PHOENIX CONTACT FL SWITCH
CVE-2017-16723no title heldn/a PHOENIX CONTACT FL COMSERVER, FL COM SERVER, and…
CVE-2016-8380no title heldPhoenix Contact ILC PLCs
CVE-2016-8371no title heldPhoenix Contact ILC PLCs
CVE-2016-8366no title heldPhoenix Contact ILC PLCs
CVE-2014-9195Phoenix Contact Software ProConOs and MultiProg Missing Authentication for Critical FunctionPhoenix Contact MultiProg
CVE-2014-4860no title heldPhoenix Technologies Ltd. SCT3; American Megatrends…

200 records, read from the index as it stood on 20 Sep 2026. Every row opens the record it names, and every value on that record opens its own receipt.

Everything on this page is free. Public data. Withholding it protects nothing.