Vendor CVEs
Contec Co., Ltd.
All CVEs
84 total · sorted by risk| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2026-82784 | Med | 0.42 | 6.5 | 0.00 | Sep 14, 2026 | Missing authentication for critical function vulnerability exists in Remote I/O Coupler Unit (Server Type) CPSN-MCB271-*. An attacker may execute a REST API without authentication, which could allow the attacker to retrieve I/O values and/or control the output. | ||
| CVE-2023-22324 | Med | 0.42 | 6.5 | 0.01 | Jan 30, 2023 | SQL injection vulnerability in the CONPROSYS HMI System (CHS) Ver.3.5.0 and earlier allows a remote authenticated attacker to execute an arbitrary SQL command. As a result, information stored in the database may be obtained. | ||
| CVE-2026-82786 | Med | 0.41 | 6.3 | 0.00 | Sep 14, 2026 | Insufficiently protected credentials issue exists in Remote I/O Coupler Unit (Server Type) CPSN-MCB271-*. If this vulnerability is exploited, sensitive information may be restored from a backup file. | ||
| CVE-2026-82788 | Med | 0.40 | 6.1 | 0.00 | Sep 14, 2026 | Cross-site scripting vulnerability exists in CPSL-08P1EN. If this vulnerability is exploited, an arbitrary script may be executed on a logged-in user's web browser. | ||
| CVE-2026-82776 | Med | 0.40 | 6.1 | 0.00 | Sep 14, 2026 | Cross-site scripting vulnerability exists in CONPROSYS PAC Series. If this vulnerability is exploited, an arbitrary script may be executed on a logged-in user's web browser. | ||
| CVE-2026-82773 | Med | 0.40 | 6.1 | 0.00 | Sep 14, 2026 | Cross-site scripting vulnerability exists in CONPROSYS M2M Gateway Series and CONPROSYS M2M Controller Series. If this vulnerability is exploited, an arbitrary script may be executed on a logged-in user's web browser. | ||
| CVE-2025-34080 | Med | 0.40 | 6.1 | 0.01 | Jul 1, 2025 | The Contec Co.,Ltd. CONPROSYS HMI System (CHS) is vulnerable to Cross-Site Scripting (XSS) in the getqsetting.php functionality that could allow reflected execution of scripts in the browser on interaction.This issue affects CONPROSYS HMI System (CHS): before 3.7.7. | ||
| CVE-2022-44355 | Med | 0.40 | 6.1 | 0.02 | Nov 29, 2022 | SolarView Compact 7.0 is vulnerable to Cross-site Scripting (XSS) via /network_test.php. | ||
| CVE-2022-31373 | Med | 0.40 | 6.1 | 0.06 | Jun 21, 2022 | SolarView Compact v6.0 was discovered to contain a cross-site scripting (XSS) vulnerability via the component Solar_AiConf.php. | ||
| CVE-2025-0683 | Med | 0.38 | 5.9 | 0.01 | Jan 30, 2025 | In its default configuration, Contec Health CMS8000 Patient Monitor transmits plain-text patient data to a hard-coded public IP address when a patient is hooked up to the monitor. This could lead to a leakage of confidential patient data to any device with that IP address or… | ||
| CVE-2023-28651 | Med | 0.36 | 4.8 | 0.62 | Jun 1, 2023 | Cross-site scripting vulnerability exists in CONPROSYS HMI System (CHS) versions prior to 3.5.3. If a user who can access the affected product with an administrative privilege configures specially crafted settings, an arbitrary script may be executed on the web browser of the… | ||
| CVE-2022-29302 | Med | 0.36 | 5.5 | 0.00 | May 12, 2022 | SolarView Compact ver.6.00 was discovered to contain a local file disclosure via /html/Solar_Ftp.php. | ||
| CVE-2026-82796 | Med | 0.35 | 5.4 | 0.00 | Sep 14, 2026 | SolarView Compact contains a cross-site scripting vulnerability in Image Management. If this vulnerability is exploited, an arbitrary OS command may be executed by an attacker who can log in to the product. | ||
| CVE-2026-82795 | Med | 0.35 | 5.4 | 0.00 | Sep 14, 2026 | SolarView Compact contains a cross-site scripting vulnerability in Schedule Settings and Mail Send Setting. If this vulnerability is exploited, an arbitrary OS command may be executed by an attacker who can log in to the product. | ||
| CVE-2026-82781 | Med | 0.35 | 5.4 | 0.00 | Sep 14, 2026 | Cross-site scripting vulnerability exists in CONPROSYS nano Series. If this vulnerability is exploited, an arbitrary script may be executed on a logged-in user's web browser. | ||
| CVE-2026-82771 | Med | 0.35 | 5.4 | 0.00 | Sep 14, 2026 | Cross-site scripting vulnerability exists in Contec EC1000 series. If this vulnerability is exploited, an arbitrary script may be executed on a logged-in user's web browser. | ||
| CVE-2026-82769 | Med | 0.35 | 5.4 | 0.00 | Sep 14, 2026 | Cross-site scripting vulnerability exists in Contec RP-WAH-SR Series. If this vulnerability is exploited, an arbitrary script may be executed on a logged-in user's web browser. | ||
| CVE-2026-82763 | Med | 0.35 | 5.4 | 0.00 | Sep 14, 2026 | Cross-site scripting vulnerability exists in Contec FX5000 series, FX4000 series, and FX3000 series. If this vulnerability is exploited, an arbitrary script may be executed on a logged-in user's web browser. | ||
| CVE-2023-22373 | Med | 0.35 | 5.4 | 0.02 | Jan 20, 2023 | Cross-site scripting vulnerability in CONPROSYS HMI System (CHS) Ver.3.4.5 and earlier allows a remote authenticated attacker to inject an arbitrary script and obtain the sensitive information. | ||
| CVE-2023-22334 | Med | 0.35 | 5.3 | 0.01 | Jan 20, 2023 | Use of password hash instead of password for authentication vulnerability in CONPROSYS HMI System (CHS) Ver.3.4.5 and earlier allows a remote authenticated attacker to obtain user credentials information via a man-in-the-middle attack. | ||
| CVE-2021-20657 | Med | 0.35 | 5.4 | 0.03 | Feb 24, 2021 | Improper access control vulnerability in SolarView Compact SV-CPT-MC310 prior to Ver.6.5 allows an authenticated attacker to obtain and/or alter the setting information without the access privilege via unspecified vectors. | ||
| CVE-2026-82792 | Med | 0.34 | 5.2 | 0.00 | Sep 14, 2026 | Cross-site scripting vulnerability exists in Contec CAN 2.0B Communication Wireless LAN / USB Converter Unit. If this vulnerability is exploited, an arbitrary script may be executed on a logged-in user's web browser. | ||
| CVE-2026-82767 | Med | 0.34 | 5.2 | 0.00 | Sep 14, 2026 | Cross-site scripting vulnerability exists in SGA1000. If this vulnerability is exploited, an arbitrary script may be executed on a logged-in user's web browser. | ||
| CVE-2023-28824 | Med | 0.32 | 4.9 | 0.01 | Jun 1, 2023 | Server-side request forgery vulnerability exists in CONPROSYS HMI System (CHS) versions prior to 3.5.3. A user who can access the affected product with an administrative privilege may bypass the database restriction set on the query setting page, and connect to a user unintended… | ||
| CVE-2026-82785 | Med | 0.28 | 4.3 | 0.00 | Sep 14, 2026 | Stack-based buffer overflow vulnerability exists in Remote I/O Coupler Unit (Server Type) CPSN-MCB271-*. Receiving a specially crafted request created and sent by a remote attacker may cause a denial-of-service (DoS) condition. | ||
| CVE-2026-82778 | Med | 0.28 | 4.3 | 0.00 | Sep 14, 2026 | An exposure of information through directory listing issue exists in CONPROSYS PAC Series. Accessing a specific URL on this product may allow a remote unauthenticated attacker to obtain the directory list without authentication. | ||
| CVE-2026-82775 | Med | 0.28 | 4.3 | 0.00 | Sep 14, 2026 | An exposure of information through directory listing issue exists in CONPROSYS M2M Gateway Series and CONPROSYS M2M Controller Series. Accessing a specific URL on this product may allow a remote unauthenticated attacker to obtain the directory list without authentication. | ||
| CVE-2026-82764 | Med | 0.28 | 4.3 | 0.00 | Sep 14, 2026 | Cross-site request forgery vulnerability exists in multiple Contec products. If a user views a specially crafted page while logged in to the affected product, unintended operations may be performed. | ||
| CVE-2023-27920 | Med | 0.28 | 4.3 | 0.02 | May 23, 2023 | Improper access control vulnerability in the system date/time setting page of SolarView Compact SV-CPT-MC310 versions prior to Ver.8.10 and SV-CPT-MC310F versions prior to Ver.8.10 allows a remote authenticated attacker to alter system date/time of the affected product. | ||
| CVE-2023-23575 | Med | 0.28 | 4.3 | 0.01 | Apr 11, 2023 | Improper access control vulnerability in CONPROSYS IoT Gateway products allows a remote authenticated attacker to bypass access restriction and access Network Maintenance page, which may result in obtaining the network information of the product. The affected products and… | ||
| CVE-2021-20656 | Med | 0.28 | 4.3 | 0.01 | Feb 24, 2021 | Exposure of information through directory listing in SolarView Compact SV-CPT-MC310 prior to Ver.6.5 allows an authenticated attacker to obtain the information inside the system, such as directories and/or file configurations via unspecified vectors. | ||
| CVE-2026-82783 | Med | 0.27 | 4.2 | 0.00 | Sep 14, 2026 | Plaintext storage of a password issue exists in CONPROSYS nano Series . If this vulnerability is exploited, an attacker with physical access to the product may obtain credentials. | ||
| CVE-2023-2758 | Low | 0.24 | 3.7 | 0.01 | May 31, 2023 | A denial of service vulnerability exists in Contec CONPROSYS HMI System versions 3.5.2 and prior. When there is a time-zone mismatch in certain configuration files, a remote, unauthenticated attacker may deny logins for an extended period of time. | ||
| CVE-2014-2324 | 0.02 | — | 0.29 | Mar 14, 2014 | Multiple directory traversal vulnerabilities in (1) mod_evhost and (2) mod_simple_vhost in lighttpd before 1.4.35 allow remote attackers to read arbitrary files via a .. (dot dot) in the host name, related to request_check_hostname. |
- risk 0.42cvss 6.5epss 0.00
Missing authentication for critical function vulnerability exists in Remote I/O Coupler Unit (Server Type) CPSN-MCB271-*. An attacker may execute a REST API without authentication, which could allow the attacker to retrieve I/O values and/or control the output.
- risk 0.42cvss 6.5epss 0.01
SQL injection vulnerability in the CONPROSYS HMI System (CHS) Ver.3.5.0 and earlier allows a remote authenticated attacker to execute an arbitrary SQL command. As a result, information stored in the database may be obtained.
- risk 0.41cvss 6.3epss 0.00
Insufficiently protected credentials issue exists in Remote I/O Coupler Unit (Server Type) CPSN-MCB271-*. If this vulnerability is exploited, sensitive information may be restored from a backup file.
- risk 0.40cvss 6.1epss 0.00
Cross-site scripting vulnerability exists in CPSL-08P1EN. If this vulnerability is exploited, an arbitrary script may be executed on a logged-in user's web browser.
- risk 0.40cvss 6.1epss 0.00
Cross-site scripting vulnerability exists in CONPROSYS PAC Series. If this vulnerability is exploited, an arbitrary script may be executed on a logged-in user's web browser.
- risk 0.40cvss 6.1epss 0.00
Cross-site scripting vulnerability exists in CONPROSYS M2M Gateway Series and CONPROSYS M2M Controller Series. If this vulnerability is exploited, an arbitrary script may be executed on a logged-in user's web browser.
- risk 0.40cvss 6.1epss 0.01
The Contec Co.,Ltd. CONPROSYS HMI System (CHS) is vulnerable to Cross-Site Scripting (XSS) in the getqsetting.php functionality that could allow reflected execution of scripts in the browser on interaction.This issue affects CONPROSYS HMI System (CHS): before 3.7.7.
- risk 0.40cvss 6.1epss 0.02
SolarView Compact 7.0 is vulnerable to Cross-site Scripting (XSS) via /network_test.php.
- risk 0.40cvss 6.1epss 0.06
SolarView Compact v6.0 was discovered to contain a cross-site scripting (XSS) vulnerability via the component Solar_AiConf.php.
- risk 0.38cvss 5.9epss 0.01
In its default configuration, Contec Health CMS8000 Patient Monitor transmits plain-text patient data to a hard-coded public IP address when a patient is hooked up to the monitor. This could lead to a leakage of confidential patient data to any device with that IP address or…
- risk 0.36cvss 4.8epss 0.62
Cross-site scripting vulnerability exists in CONPROSYS HMI System (CHS) versions prior to 3.5.3. If a user who can access the affected product with an administrative privilege configures specially crafted settings, an arbitrary script may be executed on the web browser of the…
- risk 0.36cvss 5.5epss 0.00
SolarView Compact ver.6.00 was discovered to contain a local file disclosure via /html/Solar_Ftp.php.
- risk 0.35cvss 5.4epss 0.00
SolarView Compact contains a cross-site scripting vulnerability in Image Management. If this vulnerability is exploited, an arbitrary OS command may be executed by an attacker who can log in to the product.
- risk 0.35cvss 5.4epss 0.00
SolarView Compact contains a cross-site scripting vulnerability in Schedule Settings and Mail Send Setting. If this vulnerability is exploited, an arbitrary OS command may be executed by an attacker who can log in to the product.
- risk 0.35cvss 5.4epss 0.00
Cross-site scripting vulnerability exists in CONPROSYS nano Series. If this vulnerability is exploited, an arbitrary script may be executed on a logged-in user's web browser.
- risk 0.35cvss 5.4epss 0.00
Cross-site scripting vulnerability exists in Contec EC1000 series. If this vulnerability is exploited, an arbitrary script may be executed on a logged-in user's web browser.
- risk 0.35cvss 5.4epss 0.00
Cross-site scripting vulnerability exists in Contec RP-WAH-SR Series. If this vulnerability is exploited, an arbitrary script may be executed on a logged-in user's web browser.
- risk 0.35cvss 5.4epss 0.00
Cross-site scripting vulnerability exists in Contec FX5000 series, FX4000 series, and FX3000 series. If this vulnerability is exploited, an arbitrary script may be executed on a logged-in user's web browser.
- risk 0.35cvss 5.4epss 0.02
Cross-site scripting vulnerability in CONPROSYS HMI System (CHS) Ver.3.4.5 and earlier allows a remote authenticated attacker to inject an arbitrary script and obtain the sensitive information.
- risk 0.35cvss 5.3epss 0.01
Use of password hash instead of password for authentication vulnerability in CONPROSYS HMI System (CHS) Ver.3.4.5 and earlier allows a remote authenticated attacker to obtain user credentials information via a man-in-the-middle attack.
- risk 0.35cvss 5.4epss 0.03
Improper access control vulnerability in SolarView Compact SV-CPT-MC310 prior to Ver.6.5 allows an authenticated attacker to obtain and/or alter the setting information without the access privilege via unspecified vectors.
- risk 0.34cvss 5.2epss 0.00
Cross-site scripting vulnerability exists in Contec CAN 2.0B Communication Wireless LAN / USB Converter Unit. If this vulnerability is exploited, an arbitrary script may be executed on a logged-in user's web browser.
- risk 0.34cvss 5.2epss 0.00
Cross-site scripting vulnerability exists in SGA1000. If this vulnerability is exploited, an arbitrary script may be executed on a logged-in user's web browser.
- risk 0.32cvss 4.9epss 0.01
Server-side request forgery vulnerability exists in CONPROSYS HMI System (CHS) versions prior to 3.5.3. A user who can access the affected product with an administrative privilege may bypass the database restriction set on the query setting page, and connect to a user unintended…
- risk 0.28cvss 4.3epss 0.00
Stack-based buffer overflow vulnerability exists in Remote I/O Coupler Unit (Server Type) CPSN-MCB271-*. Receiving a specially crafted request created and sent by a remote attacker may cause a denial-of-service (DoS) condition.
- risk 0.28cvss 4.3epss 0.00
An exposure of information through directory listing issue exists in CONPROSYS PAC Series. Accessing a specific URL on this product may allow a remote unauthenticated attacker to obtain the directory list without authentication.
- risk 0.28cvss 4.3epss 0.00
An exposure of information through directory listing issue exists in CONPROSYS M2M Gateway Series and CONPROSYS M2M Controller Series. Accessing a specific URL on this product may allow a remote unauthenticated attacker to obtain the directory list without authentication.
- risk 0.28cvss 4.3epss 0.00
Cross-site request forgery vulnerability exists in multiple Contec products. If a user views a specially crafted page while logged in to the affected product, unintended operations may be performed.
- risk 0.28cvss 4.3epss 0.02
Improper access control vulnerability in the system date/time setting page of SolarView Compact SV-CPT-MC310 versions prior to Ver.8.10 and SV-CPT-MC310F versions prior to Ver.8.10 allows a remote authenticated attacker to alter system date/time of the affected product.
- risk 0.28cvss 4.3epss 0.01
Improper access control vulnerability in CONPROSYS IoT Gateway products allows a remote authenticated attacker to bypass access restriction and access Network Maintenance page, which may result in obtaining the network information of the product. The affected products and…
- risk 0.28cvss 4.3epss 0.01
Exposure of information through directory listing in SolarView Compact SV-CPT-MC310 prior to Ver.6.5 allows an authenticated attacker to obtain the information inside the system, such as directories and/or file configurations via unspecified vectors.
- risk 0.27cvss 4.2epss 0.00
Plaintext storage of a password issue exists in CONPROSYS nano Series . If this vulnerability is exploited, an attacker with physical access to the product may obtain credentials.
- risk 0.24cvss 3.7epss 0.01
A denial of service vulnerability exists in Contec CONPROSYS HMI System versions 3.5.2 and prior. When there is a time-zone mismatch in certain configuration files, a remote, unauthenticated attacker may deny logins for an extended period of time.
- CVE-2014-2324Mar 14, 2014risk 0.02cvss —epss 0.29
Multiple directory traversal vulnerabilities in (1) mod_evhost and (2) mod_simple_vhost in lighttpd before 1.4.35 allow remote attackers to read arbitrary files via a .. (dot dot) in the host name, related to request_check_hostname.
Page 2 of 2