Solution sectors / ics-ot-iot
ICS, OT & IoT
Industrial control systems, operational technology and IoT devices bridge the physical and digital worlds, where a vulnerability can have real-world consequences. This hub tracks CVEs across ICS, OT and connected devices.
plc-scada-hmi · 30ip-camera-nvr · 27industrial-network · 27smart-home · 3building-automation · 1medical-device · 1
Cumulative CVEs
12,459
across 233 monthly snapshots
Latest month
220 · proj
+66.7% MoM · +27.9% YoY
Peak month
310
Dec 25
KEV this month
0
29 vendors affected
CVEs per month
Newest period on the right. Click a point to open that monthly report.
Deployment mix
How this sector's software is typically delivered (month in progress) — whether you patch it yourself or a vendor does. AI-assisted vendor classification.
- On-prem88%
- Embedded6%
- Mixed5%
Latest CVEs in this sector
The 15 most recently published vulnerabilities tagged to ICS, OT & IoT.
- CVE-2026-90809HKUDS nanobot ExecTool shell.py ExecTool._spawn argument injection7.3
- CVE-2026-59178ESPHome Device Builder: Renamed auth env vars silently disable dashboard authentication on upgrade9.8
- CVE-2026-90808HKUDS nanobot ExecTool shell.py ExecTool._spawn incomplete blacklist6.3
- CVE-2026-82796SolarView Compact contains a cross-site scripting vulnerability in Image Management. If this vulnerability is exploited, an arbitrary OS command may be executed by an attacker who can log in to the...5.4
- CVE-2026-82795SolarView Compact contains a cross-site scripting vulnerability in Schedule Settings and Mail Send Setting. If this vulnerability is exploited, an arbitrary OS command may be executed by an attacke...5.4
- CVE-2026-82794SolarView Compact contains an OS command Injection vulnerability in in Schedule Settings. If this vulnerability is exploited, an arbitrary OS command may be executed by an attacker who can log in t...8.8
- CVE-2026-82793Unrestricted upload of file with dangerous type issue exists in Contec CAN 2.0B Communication Wireless LAN / USB Converter Unit. If a specially crafted file is uploaded by a remote authenticated at...7.2
- CVE-2026-82765Path traversal vulnerability exists in Contec FX5000 series, FX4000 series, and FX3000 series. If this vulnerability is exploited, arbitrary files on the server may be viewed and/or altered by an a...8.1
- CVE-2026-82792Cross-site scripting vulnerability exists in Contec CAN 2.0B Communication Wireless LAN / USB Converter Unit. If this vulnerability is exploited, an arbitrary script may be executed on a logged-in ...5.2
- CVE-2026-82791Improper neutralization of special elements used in an OS command ('OS Command Injection') issue exists in Contec CAN 2.0B Communication Wireless LAN / USB Converter Unit. If this vulnerability is ...8.8
- CVE-2026-82790Cross-site scripting vulnerability exists in PC-HELPER Wireless I/O DIO-0404RY-LWF and PC-HELPER Wireless I/O DIO-0404RY-LWF-US. If this vulnerability is exploited, an arbitrary script may be execu...5.4
- CVE-2026-82789An improper neutralization of directives in dynamically evaluated code ('Eval Injection') issue exists in CONPROSYS HMI System(CHS). If exploited, arbitrary code may be executed by an attacker who ...8.8
- CVE-2026-82763Cross-site scripting vulnerability exists in Contec FX5000 series, FX4000 series, and FX3000 series. If this vulnerability is exploited, an arbitrary script may be executed on a logged-in user's we...5.4
- CVE-2026-82787Missing authentication for critical function vulnerability exists in CPSL-08P1EN. If this vulnerability is exploited, an affected product may be operated by a remote attacker without authentication.9.8
- CVE-2026-82788Cross-site scripting vulnerability exists in CPSL-08P1EN. If this vulnerability is exploited, an arbitrary script may be executed on a logged-in user's web browser.6.1
Weakness fingerprint
Top CWE classes in this sector, latest monthly snapshot (month in progress).
Top vendors
Most CVEs in this sector, latest monthly snapshot (month in progress).
| Vendor | CVEs | Crit | KEV |
|---|---|---|---|
| geovision inc. | 23 | 2 | · |
| rockwell automation | 18 | · | · |
| cisa | 15 | · | · |
| schneider electric | 9 | · | · |
| px4 | 5 | · | · |
| aveva software, llc | 4 | · | · |
| hitachi energy | 4 | · | · |
Subsectors
Breakdown for the latest monthly snapshot (month in progress).
| Subsector | CVEs | Crit | KEV | Vendors | MoM | Top products |
|---|---|---|---|---|---|---|
| plc-scada-hmi | 30 | 26 | · | 8 | — | pipeline integrity monitor (4) · rslinx classic® (4) · factorytalk® historian machine edition (2) |
| industrial-network | 27 | 1 | · | 7 | — | malcolm (15) · px4-autopilot (5) · fast-dds (2) |
| ip-camera-nvr | 27 | 2 | · | 3 | — | gv-lpc2011/lpc2211 (17) · gv-lpclpc2011/2211 (5) · ds-kd8003 (1) |
| — | 21 | 3 | · | 7 | — | cosminexus component container (4) · microscada sys600 (3) · microscada x sys600 (3) |
| smart-home | 3 | 1 | · | 2 | — | ai-trader (1) · autoagent (1) · openremote (1) |
| building-automation | 1 | · | · | 1 | — | ecos504 (1) · ecos505 (1) · modu612-lc (1) |
| medical-device | 1 | · | · | 1 | — | dicom server (1) |
Sector classification is AI-assisted with human review. How tagging works · Report a misclassification