Solution sectors / ics-ot-iot
ICS, OT & IoT
Industrial control systems, operational technology and IoT devices bridge the physical and digital worlds, where a vulnerability can have real-world consequences. This hub tracks CVEs across ICS, OT and connected devices.
plc-scada-hmi · 24ip-camera-nvr · 24smart-home · 12industrial-network · 7building-automation · 1medical-device
Cumulative CVEs
12,112
across 231 monthly snapshots
Latest month
104 · proj
-50.2% MoM · -59.8% YoY
Peak month
310
Dec 25
KEV this month
0
29 vendors affected
CVEs per month
Newest period on the right. Click a point to open that monthly report.
Deployment mix
How this sector's software is typically delivered (month in progress) — whether you patch it yourself or a vendor does. AI-assisted vendor classification.
- On-prem91%
- Mixed9%
Latest CVEs in this sector
The 15 most recently published vulnerabilities tagged to ICS, OT & IoT.
- CVE-2026-60134Weintek cMT3092X Reliance on Cookies without Validation and Integrity Checking in a Security Decision8.8
- CVE-2026-61892Weintek cMT3092X Incorrect Permission Assignment for Critical Resource8.8
- CVE-2026-61886Weintek cMT3092X Plaintext Storage of a Password6.5
- CVE-2026-60135Weintek cMT3092X Incorrect User Management6.5
- CVE-2026-16519GeoVision GV-IP Device Utility DLL Search Order Hijacking Vulnerability7.3
- CVE-2026-16002Out-of-bounds Read in MZ Automation lib608708.2
- CVE-2026-50032NULL Pointer Dereference in MZ Automation libIEC618507.5
- CVE-2026-50103Improper Handling of Syntactically Invalid Structure in MZ Automation libIEC618506.5
- CVE-2026-49035Stack-based Buffer Overflow in MZ Automation libIEC618508.1
- CVE-2026-50039Stack-based Buffer Overflow in MZ Automation libIEC618507.5
- CVE-2026-34496victor Web - Priviledge Escalation8.8
- CVE-2026-21653CCure and Victor Application Server - Server Side Request Forgery8.8
- CVE-2026-60122gpsd gpsprof Code Injection via SKY.satellites used Field7.8
- CVE-2026-47752Tugtainer has Server-Side Template Injection in notification templates that leads to Remote Code Execution9.9
- CVE-2026-11804Program Module Vulnerability5.2
Weakness fingerprint
Top CWE classes in this sector, latest monthly snapshot (month in progress).
Top vendors
Most CVEs in this sector, latest monthly snapshot (month in progress).
| Vendor | CVEs | Crit | KEV |
|---|---|---|---|
| rockwell automation | 19 | 1 | · |
| geovision inc. | 18 | · | · |
| automationdirect | 6 | · | · |
| spaceapplications | 6 | 3 | · |
| csa-iot | 5 | · | · |
Subsectors
Breakdown for the latest monthly snapshot (month in progress).
| Subsector | CVEs | Crit | KEV | Vendors | MoM | Top products |
|---|---|---|---|---|---|---|
| plc-scada-hmi | 24 | 13 | · | 9 | — | yamcs (6) · aprol (2) · compactlogix® 5370 compact guardlogix® 5370 controllogix® 5570 guardlogix® 5570 (2) |
| ip-camera-nvr | 24 | 3 | · | 5 | — | geowebplayer (18) · 2k indoor wi-fi security camera (2) · flamingo (2) |
| — | 23 | · | · | 5 | — | productivity suite (6) · arena (4) · cpci85 central processing/communication (4) |
| smart-home | 12 | 5 | · | 5 | — | matter (5) · gardyn cloud api (3) · gardyn home firmware (3) |
| industrial-network | 7 | 1 | · | 4 | — | liman mys (3) · firmware (2) · core flight system (cfs) health & safety (hs) application (1) |
| building-automation | 1 | · | · | 1 | — | hotel broadband operation system (1) |
Sector classification is AI-assisted with human review. How tagging works · Report a misclassification