advantech

385 tracked vulnerabilities.

CVE-2026-6888 HIGH
Advantech SaaS Composer < 3.4.17 - Authenticated SQL Injection via Specific Interface
May 13, 2026
CVSS 7.2
EPSS 0.00
CVE-2026-2670 HIGH
Advantech WISE-6610 1.2.1 - Command Injection
Feb 18, 2026
CVSS 7.2
EPSS 0.00
CVE-2025-52694 CRITICAL NUCLEI
Advantech IoT Edge Linux Docker < 2.0.2 - Unauthenticated SQL Injection
Jan 12, 2026
CVSS 10.0
EPSS 0.13
CVE-2025-67653 MEDIUM
Advantech WebAccess/SCADA - Path Traversal
Dec 18, 2025
CVSS 4.3
EPSS 0.00
CVE-2025-46268 MEDIUM
Advantech WebAccess/SCADA - SQL Injection
Dec 18, 2025
CVSS 6.3
EPSS 0.00
CVE-2025-14850 HIGH
Advantech WebAccess/SCADA - Path Traversal and Arbitrary File Deletion
Dec 18, 2025
CVSS 8.1
EPSS 0.00
CVE-2025-14849 HIGH
Advantech WebAccess/SCADA - Unrestricted File Upload and Remote Code Execution
Dec 18, 2025
CVSS 8.8
EPSS 0.00
CVE-2025-14848 MEDIUM
Advantech WebAccess/SCADA - Absolute Path Traversal
Dec 18, 2025
CVSS 4.3
EPSS 0.00
CVE-2025-14252 HIGH
Advantech SUSI <5.0.24335 - Privilege Escalation
Dec 16, 2025
CVSS 7.8
EPSS 0.00
CVE-2025-34266 MEDIUM
Advantech WISE-DeviceOn Server < 5.4 - Authenticated Stored Cross-Site Scripting via PluginConfig AddIns Menus
Dec 05, 2025
CVSS 5.4
EPSS 0.00
CVE-2025-34265 MEDIUM
Advantech WISE-DeviceOn Server < 5.4 - Authenticated Stored Cross-Site Scripting via Rule Engine Fields
Dec 05, 2025
CVSS 5.4
EPSS 0.00
CVE-2025-34264 MEDIUM
Advantech WISE-DeviceOn Server < 5.4 - Authenticated Stored Cross-Site Scripting via Software Watchdog Process Name
Dec 05, 2025
CVSS 5.4
EPSS 0.00
CVE-2025-34263 MEDIUM
Advantech WISE-DeviceOn Server < 5.4 - Authenticated Stored Cross-Site Scripting via Dashboard Menu Configuration
Dec 05, 2025
CVSS 5.4
EPSS 0.00
CVE-2025-34262 MEDIUM
Advantech WISE-DeviceOn Server < 5.4 - Authenticated Stored Cross-Site Scripting via Device Name Parameter
Dec 05, 2025
CVSS 5.4
EPSS 0.00
CVE-2025-34261 MEDIUM
Advantech WISE-DeviceOn Server < 5.4 - Authenticated Stored Cross-Site Scripting via Device Groups Endpoint
Dec 05, 2025
CVSS 5.4
EPSS 0.00
CVE-2025-34260 MEDIUM
Advantech WISE-DeviceOn Server < 5.4 - Authenticated Stored Cross-Site Scripting via Action Schedule Endpoint
Dec 05, 2025
CVSS 5.4
EPSS 0.00
CVE-2025-34259 MEDIUM
Advantech WISE-DeviceOn Server < 5.4 - Authenticated Stored Cross-Site Scripting via DeviceMap Building Name Parameter
Dec 05, 2025
CVSS 5.4
EPSS 0.00
CVE-2025-34258 MEDIUM
Advantech WISE-DeviceOn Server < 5.4 - Authenticated Stored Cross-Site Scripting via DeviceMap Plan Name Parameter
Dec 05, 2025
CVSS 5.4
EPSS 0.00
CVE-2025-34257 MEDIUM
Advantech WISE-DeviceOn Server < 5.4 - Authenticated Stored Cross-Site Scripting via Action Defined Endpoint
Dec 05, 2025
CVSS 5.4
EPSS 0.00
CVE-2025-34256 CRITICAL
Advantech WISE-DeviceOn Server <5.4 - Auth Bypass
Dec 05, 2025
CVSS 9.8
EPSS 0.00
CVE-2025-13373 HIGH
Advantech iView <5.7.05.7057 - SQL Injection
Dec 04, 2025
CVSS 7.5
EPSS 0.00
CVE-2025-63701 MEDIUM
Advantech TP-3250 - Memory Corruption
Nov 14, 2025
CVSS 6.8
EPSS 0.00
CVE-2025-64302 MEDIUM
Advantech DeviceOn iEdge < 2.0.2 - Cross-Site Scripting via Dashboard Label or Path
Nov 06, 2025
CVSS 6.4
EPSS 0.00
CVE-2025-62630 HIGH
Advantech DeviceOn iEdge < 2.0.2 - Path Traversal and Remote Code Execution via Configuration File Upload
Nov 06, 2025
CVSS 8.8
EPSS 0.00
CVE-2025-59171 HIGH
Advantech DeviceOn iEdge < 2.0.2 - Path Traversal and Remote Code Execution via Configuration File Upload
Nov 06, 2025
CVSS 7.5
EPSS 0.00