Contec / Conprosys Hmi System
15 CVEs
| CVE ID | Description | Severity | CVSS | Published |
|---|---|---|---|---|
| CVE-2025-34081 | CONPROSYS HMI System (CHS) < 3.7.7 Exposed PHP Debug Info | MEDIUM | 6.9 | Jul 1, 2025 |
| CVE-2025-34080 | CONPROSYS HMI System (CHS) < 3.7.7 Reflected Cross-Site Scripting | MEDIUM | 5.1 | Jul 1, 2025 |
| CVE-2023-29154 | SQL injection vulnerability exists in the CONPROSYS HMI System (CHS) versions prior to 3.5.3. A user who can access the affected product with an administrative… | HIGH | 7.2 | Jun 1, 2023 |
| CVE-2023-28824 | Server-side request forgery vulnerability exists in CONPROSYS HMI System (CHS) versions prior to 3.5.3. A user who can access the affected product with an admi… | MEDIUM | 4.9 | Jun 1, 2023 |
| CVE-2023-28713 | Plaintext storage of a password exists in CONPROSYS HMI System (CHS) versions prior to 3.5.3. Because account information of the database is saved in a local f… | HIGH | 8.1 | Jun 1, 2023 |
| CVE-2023-28657 | Improper access control vulnerability exists in CONPROSYS HMI System (CHS) versions prior to 3.5.3. A user of the PC where the affected product is installed ma… | HIGH | 8.8 | Jun 1, 2023 |
| CVE-2023-28651 | Cross-site scripting vulnerability exists in CONPROSYS HMI System (CHS) versions prior to 3.5.3. If a user who can access the affected product with an administ… | MEDIUM | 4.8 | Jun 1, 2023 |
| CVE-2023-28399 | Incorrect permission assignment for critical resource exists in CONPROSYS HMI System (CHS) versions prior to 3.5.3. ACL (Access Control List) is not appropriat… | HIGH | 7.8 | Jun 1, 2023 |
| CVE-2023-2758 | Contec CONPROSYS HMI System (CHS) v3.5.2 Denial of Service | MEDIUM | 5.3 | May 31, 2023 |
| CVE-2023-22324 | SQL injection vulnerability in the CONPROSYS HMI System (CHS) Ver.3.5.0 and earlier allows a remote authenticated attacker to execute an arbitrary SQL command.… | MEDIUM | 6.5 | Jan 30, 2023 |
| CVE-2023-22373 | Cross-site scripting vulnerability in CONPROSYS HMI System (CHS) Ver.3.4.5 and earlier allows a remote authenticated attacker to inject an arbitrary script and… | MEDIUM | 5.4 | Jan 20, 2023 |
| CVE-2023-22339 | Improper access control vulnerability in CONPROSYS HMI System (CHS) Ver.3.4.5 and earlier allows a remote unauthenticated attacker to bypass access restriction… | HIGH | 7.5 | Jan 20, 2023 |
| CVE-2023-22334 | Use of password hash instead of password for authentication vulnerability in CONPROSYS HMI System (CHS) Ver.3.4.5 and earlier allows a remote authenticated att… | MEDIUM | 5.3 | Jan 20, 2023 |
| CVE-2023-22331 | Use of default credentials vulnerability in CONPROSYS HMI System (CHS) Ver.3.4.5 and earlier allows a remote unauthenticated attacker to alter user credentials… | HIGH | 7.5 | Jan 20, 2023 |
| CVE-2022-44456 | CONPROSYS HMI System (CHS) Ver.3.4.4?and earlier allows a remote unauthenticated attacker to execute an arbitrary OS command on the server where the product is… | CRITICAL | 9.8 | Dec 19, 2022 |
Showing 1 to 15 of 15 CVEs