Vulnerability index

Browse CVEs

22 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

CRITICAL 9.8 CVE-2026-12569 KEVEPSS 30% A critical remote code execution (RCE) vulnerability has been reported in PTC Windchill PDMlink and PTC FlexPLM. The vulnerability may be exploited t… Flexplm 11.0m030+ Fix from $2,3002026-06-18 MEDIUM 6.5 CVE-2024-40395 An Insecure Direct Object Reference (IDOR) in PTC ThingWorx v9.5.0 allows attackers to view sensitive information, including PII, regardless of acces… Thingworx Mitigation only Fix from $1,6002024-08-27 HIGH 7.8 CVE-2023-29445 An uncontrolled search path element vulnerability (DLL hijacking) has been discovered that could allow a locally authenticated adversary to escalate … Kepware Kepserverex after 8.5 Fix from $1,9502024-01-10 MEDIUM 5.3 CVE-2023-29447 An insufficiently protected credentials vulnerability in KEPServerEX could allow an adversary to capture user credentials as the web server uses basi… Kepware Kepserverex after 8.5 Fix from $1,6002024-01-10 HIGH 7.3 CVE-2023-29444 An uncontrolled search path element vulnerability (DLL hijacking) has been discovered that could allow a locally authenticated adversary to escalate … Kepware Kepserverex after 8.5 Fix from $1,9502024-01-10 HIGH 8.0 CVE-2023-31200 PTC Vuforia Studio does not require a token; this could allow an attacker with local access to perform a cross-site request forgery attack or a rep… Vuforia Studio 9.9+ Fix from $1,9502023-06-07 CRITICAL 9.9 CVE-2023-27881 A user could use the “Upload Resource” functionality to upload files to any location on the disk. Vuforia Studio 9.9+ Fix from $2,3002023-06-07 HIGH 8.1 CVE-2023-29152 By changing the filename parameter in the request, an attacker could delete any file with the permissions of the Vuforia server account. Vuforia Studio 9.9+ Fix from $1,9502023-06-07 HIGH 7.5 CVE-2023-29168 The local Vuforia web application does not support HTTPS, and federated credentials are passed via basic authentication. Vuforia Studio 9.9+ Fix from $1,9502023-06-07 CRITICAL 9.8 CVE-2022-25247 Axeda agent (All versions) and Axeda Desktop Server for Windows (All versions) may allow an attacker to send certain commands to a specific port with… Axeda Agent 6.9.1 / 6.9.215+ Fix from $2,3002022-03-16 CRITICAL 9.8 CVE-2022-25251 When connecting to a certain port Axeda agent (All versions) and Axeda Desktop Server for Windows (All versions) may allow an attacker to send certai… Axeda Agent 6.9.1 / 6.9.215+ Fix from $2,3002022-03-16 HIGH 8.8 CVE-2022-25246 Axeda agent (All versions) and Axeda Desktop Server for Windows (All versions) uses hard-coded credentials for its UltraVNC installation. Successful … Axeda Agent 6.9.1 / 6.9.215+ Fix from $1,9502022-03-16 HIGH 7.5 CVE-2022-25249 When connecting to a certain port Axeda agent (All versions) and Axeda Desktop Server for Windows (All versions) (disregarding Axeda agent v6.9.2 and… Axeda Agent 6.9.1 / 6.9.215+ Fix from $1,9502022-03-16 HIGH 7.5 CVE-2022-25250 When connecting to a certain port Axeda agent (All versions) and Axeda Desktop Server for Windows (All versions) may allow an attacker to send a cert… Axeda Agent 6.9.1 / 6.9.215+ Fix from $1,9502022-03-16 HIGH 7.5 CVE-2022-25252 When connecting to a certain port Axeda agent (All versions) and Axeda Desktop Server for Windows (All versions) when receiving certain input throws … Axeda Agent 6.9.1 / 6.9.215+ Fix from $1,9502022-03-16 MEDIUM 5.3 CVE-2022-25248 When connecting to a certain port Axeda agent (All versions) and Axeda Desktop Server for Windows (All versions) supplies the event log of the specif… Axeda Agent 6.9.1 / 6.9.215+ Fix from $1,6002022-03-16 HIGH 7.5 CVE-2018-20092 PTC ThingWorx Platform through 8.3.0 is vulnerable to a directory traversal attack on ZIP files via a POST request. Thingworx Platform 7.0.0+ Fix from $1,9502018-12-17 HIGH 7.5 CVE-2018-17217 An issue was discovered in PTC ThingWorx Platform 6.5 through 8.2. There is a hardcoded encryption key. Thingworx Platform after 8.2 Fix from $1,9502018-10-01 MEDIUM 6.5 CVE-2018-17216 An issue was discovered in PTC ThingWorx Platform 6.5 through 8.2. There is password hash exposure to privileged users. Thingworx Platform after 8.2 Fix from $1,6002018-10-01 MEDIUM 5.4 CVE-2018-17218 An issue was discovered in PTC ThingWorx Platform 6.5 through 8.2. There is reflected XSS in the SQUEAL search function. Thingworx Platform after 8.2.0 Fix from $1,6002018-10-01 HIGH 7.5 CVE-2015-2061 Heap-based buffer overflow in the browser plugin for PTC Creo View allows remote attackers to execute arbitrary code via vectors involving setting a … Creo View Mitigation only Fix from $1,9502015-03-09 MEDIUM 6.8 CVE-2014-9267 Heap-based buffer overflow in the PTC IsoView ActiveX control allows remote attackers to execute arbitrary code via a crafted ViewPort property value. Isoview Mitigation only Fix from $1,6002014-12-08