VYPR

Vendor CVEs

Codesys

All CVEs

154 total · sorted by risk
  • CVE-2022-22508MedMay 15, 2023
    risk 0.28cvss 4.3epss 0.01

    Improper Input Validation vulnerability in multiple CODESYS V3 products allows an authenticated remote attacker to block consecutive logins of a specific type.

  • CVE-2023-3669LowAug 3, 2023
    risk 0.21cvss 3.3epss 0.00

    A missing Brute-Force protection in CODESYS Development System prior to 3.5.19.20 allows a local attacker to have unlimited attempts of guessing the password within an import dialog.

  • CVE-2026-35226MedJul 29, 2026
    risk 0.00cvss 6.5epss 0.00

    An out‑of‑bounds write vulnerability in the CODESYS PROFINET Controller allows an unauthenticated attacker on the same network segment to send malformed PROFINET communication data that triggers an exception in the affected PLC application. The exception is handled by the…

  • CVE-2015-6460Sep 18, 2015
    risk 0.00cvss epss 0.06

    Multiple heap-based buffer overflows in 3S-Smart CODESYS Gateway Server before 2.3.9.34 allow remote attackers to execute arbitrary code via opcode (1) 0x3ef or (2) 0x3f0.

Page 4 of 4