Vulnerability index

Browse CVEs

22 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Flexplm CRITICAL 9.8
CVE-2026-12569 KEVEPSS 30%

A critical remote code execution (RCE) vulnerability has been reported in PTC Windchill PDMlink and PTC FlexPLM. The vulnerability may be exploited t…

Fix: 11.0m030+
Fix from $2,300 2026-06-18
Thingworx MEDIUM 6.5
CVE-2024-40395

An Insecure Direct Object Reference (IDOR) in PTC ThingWorx v9.5.0 allows attackers to view sensitive information, including PII, regardless of acces…

Mitigation only
Fix from $1,600 2024-08-27
Kepware Kepserverex HIGH 7.8
CVE-2023-29445

An uncontrolled search path element vulnerability (DLL hijacking) has been discovered that could allow a locally authenticated adversary to escalate …

Fix: after 8.5
Fix from $1,950 2024-01-10
Kepware Kepserverex MEDIUM 5.3
CVE-2023-29447

An insufficiently protected credentials vulnerability in KEPServerEX could allow an adversary to capture user credentials as the web server uses basi…

Fix: after 8.5
Fix from $1,600 2024-01-10
Kepware Kepserverex HIGH 7.3
CVE-2023-29444

An uncontrolled search path element vulnerability (DLL hijacking) has been discovered that could allow a locally authenticated adversary to escalate …

Fix: after 8.5
Fix from $1,950 2024-01-10
Vuforia Studio HIGH 8.0
CVE-2023-31200

PTC Vuforia Studio does not require a token; this could allow an attacker with local access to perform a cross-site request forgery attack or a rep…

Fix: 9.9+
Fix from $1,950 2023-06-07
Vuforia Studio CRITICAL 9.9
CVE-2023-27881

A user could use the “Upload Resource” functionality to upload files to any location on the disk.

Fix: 9.9+
Fix from $2,300 2023-06-07
Vuforia Studio HIGH 8.1
CVE-2023-29152

By changing the filename parameter in the request, an attacker could delete any file with the permissions of the Vuforia server account.

Fix: 9.9+
Fix from $1,950 2023-06-07
Vuforia Studio HIGH 7.5
CVE-2023-29168

The local Vuforia web application does not support HTTPS, and federated credentials are passed via basic authentication.

Fix: 9.9+
Fix from $1,950 2023-06-07
Axeda Agent CRITICAL 9.8
CVE-2022-25247

Axeda agent (All versions) and Axeda Desktop Server for Windows (All versions) may allow an attacker to send certain commands to a specific port with…

Fix: 6.9.1 / 6.9.215+
Fix from $2,300 2022-03-16
Axeda Agent CRITICAL 9.8
CVE-2022-25251

When connecting to a certain port Axeda agent (All versions) and Axeda Desktop Server for Windows (All versions) may allow an attacker to send certai…

Fix: 6.9.1 / 6.9.215+
Fix from $2,300 2022-03-16
Axeda Agent HIGH 8.8
CVE-2022-25246

Axeda agent (All versions) and Axeda Desktop Server for Windows (All versions) uses hard-coded credentials for its UltraVNC installation. Successful …

Fix: 6.9.1 / 6.9.215+
Fix from $1,950 2022-03-16
Axeda Agent HIGH 7.5
CVE-2022-25249

When connecting to a certain port Axeda agent (All versions) and Axeda Desktop Server for Windows (All versions) (disregarding Axeda agent v6.9.2 and…

Fix: 6.9.1 / 6.9.215+
Fix from $1,950 2022-03-16
Axeda Agent HIGH 7.5
CVE-2022-25250

When connecting to a certain port Axeda agent (All versions) and Axeda Desktop Server for Windows (All versions) may allow an attacker to send a cert…

Fix: 6.9.1 / 6.9.215+
Fix from $1,950 2022-03-16
Axeda Agent HIGH 7.5
CVE-2022-25252

When connecting to a certain port Axeda agent (All versions) and Axeda Desktop Server for Windows (All versions) when receiving certain input throws …

Fix: 6.9.1 / 6.9.215+
Fix from $1,950 2022-03-16
Axeda Agent MEDIUM 5.3
CVE-2022-25248

When connecting to a certain port Axeda agent (All versions) and Axeda Desktop Server for Windows (All versions) supplies the event log of the specif…

Fix: 6.9.1 / 6.9.215+
Fix from $1,600 2022-03-16
Thingworx Platform HIGH 7.5
CVE-2018-20092

PTC ThingWorx Platform through 8.3.0 is vulnerable to a directory traversal attack on ZIP files via a POST request.

Fix: 7.0.0+
Fix from $1,950 2018-12-17
Thingworx Platform HIGH 7.5
CVE-2018-17217

An issue was discovered in PTC ThingWorx Platform 6.5 through 8.2. There is a hardcoded encryption key.

Fix: after 8.2
Fix from $1,950 2018-10-01
Thingworx Platform MEDIUM 6.5
CVE-2018-17216

An issue was discovered in PTC ThingWorx Platform 6.5 through 8.2. There is password hash exposure to privileged users.

Fix: after 8.2
Fix from $1,600 2018-10-01
Thingworx Platform MEDIUM 5.4
CVE-2018-17218

An issue was discovered in PTC ThingWorx Platform 6.5 through 8.2. There is reflected XSS in the SQUEAL search function.

Fix: after 8.2.0
Fix from $1,600 2018-10-01
Creo View HIGH 7.5
CVE-2015-2061

Heap-based buffer overflow in the browser plugin for PTC Creo View allows remote attackers to execute arbitrary code via vectors involving setting a …

Mitigation only
Fix from $1,950 2015-03-09
Isoview MEDIUM 6.8
CVE-2014-9267

Heap-based buffer overflow in the PTC IsoView ActiveX control allows remote attackers to execute arbitrary code via a crafted ViewPort property value.

Mitigation only
Fix from $1,600 2014-12-08