VYPR
Vendor

Ptc

Products
29
CVEs
41
Across products
115
Status
Private

Products

29

Recent CVEs

41
View all 41 CVEs →
  • CVE-2026-12569CriKEVJun 18, 2026
    risk 0.84cvss 9.8epss 0.30

    A critical remote code execution (RCE) vulnerability has been reported in PTC Windchill PDMlink and PTC FlexPLM. The vulnerability may be exploited through the deserialization of untrusted data.  * This advisory also applies to all CPS versions * The identified…

  • CVE-2024-6071CriJun 27, 2024
    risk 0.65cvss 10.0epss 0.01

    PTC Creo Elements/Direct License Server exposes a web interface which can be used by unauthenticated remote attackers to execute arbitrary OS commands on the server.

  • CVE-2023-0755CriFeb 23, 2023
    risk 0.65cvss 9.8epss 0.12

    The affected products are vulnerable to an improper validation of array index, which could allow an attacker to crash the server and remotely execute arbitrary code.

  • CVE-2020-27265CriJan 14, 2021
    risk 0.65cvss 9.8epss 0.10

    KEPServerEX: v6.0 to v6.9, ThingWorx Kepware Server: v6.8 and v6.9, ThingWorx Industrial Connectivity: All versions, OPC-Aggregator: All versions, Rockwell Automation KEPServer Enterprise, GE Digital Industrial Gateway Server: v7.68.804 and v7.66, Software Toolbox TOP Server:…

  • CVE-2022-2825CriMar 29, 2023
    risk 0.64cvss 9.8epss 0.03

    This vulnerability allows remote attackers to execute arbitrary code on affected installations of Kepware KEPServerEX 6.11.718.0. Authentication is not required to exploit this vulnerability. The specific flaw exists within the handling of text encoding conversions. The issue…

  • CVE-2023-0754CriFeb 23, 2023
    risk 0.64cvss 9.8epss 0.03

    The affected products are vulnerable to an integer overflow or wraparound, which could  allow an attacker to crash the server and remotely execute arbitrary code.

  • CVE-2022-25251CriMar 16, 2022
    risk 0.64cvss 9.8epss 0.02

    When connecting to a certain port Axeda agent (All versions) and Axeda Desktop Server for Windows (All versions) may allow an attacker to send certain XML messages to a specific port without proper authentication. Successful exploitation of this vulnerability could allow a…

  • CVE-2022-25247CriMar 16, 2022
    risk 0.64cvss 9.8epss 0.04

    Axeda agent (All versions) and Axeda Desktop Server for Windows (All versions) may allow an attacker to send certain commands to a specific port without authentication. Successful exploitation of this vulnerability could allow a remote unauthenticated attacker to obtain full…

  • CVE-2022-25246CriMar 16, 2022
    risk 0.64cvss 9.8epss 0.02

    Axeda agent (All versions) and Axeda Desktop Server for Windows (All versions) uses hard-coded credentials for its UltraVNC installation. Successful exploitation of this vulnerability could allow a remote authenticated attacker to take full remote control of the host operating…

  • CVE-2026-4681CriMar 23, 2026
    risk 0.61cvss epss 0.01

    A critical remote code execution (RCE) vulnerability has been reported in PTC Windchill and PTC FlexPLM. The vulnerability may be exploited through the deserialization of untrusted data. This issue affects Windchill PDMLink: 11.0 M030, 11.1 M020, 11.2.1.0, 12.0.2.0, 12.1.2.0,…

  • CVE-2020-27267CriJan 14, 2021
    risk 0.60cvss 9.1epss 0.05

    KEPServerEX v6.0 to v6.9, ThingWorx Kepware Server v6.8 and v6.9, ThingWorx Industrial Connectivity (all versions), OPC-Aggregator (all versions), Rockwell Automation KEPServer Enterprise, GE Digital Industrial Gateway Server v7.68.804 and v7.66, and Software Toolbox TOP Server…

  • CVE-2020-27263CriJan 14, 2021
    risk 0.60cvss 9.1epss 0.05

    KEPServerEX: v6.0 to v6.9, ThingWorx Kepware Server: v6.8 and v6.9, ThingWorx Industrial Connectivity: All versions, OPC-Aggregator: All versions, Rockwell Automation KEPServer Enterprise, GE Digital Industrial Gateway Server: v7.68.804 and v7.66, Software Toolbox TOP Server:…

  • CVE-2023-5908CriNov 30, 2023
    risk 0.59cvss 9.1epss 0.01

    KEPServerEX is vulnerable to a buffer overflow which may allow an attacker to crash the product being accessed or leak information.

  • CVE-2022-2848CriMar 29, 2023
    risk 0.59cvss 9.1epss 0.03

    This vulnerability allows remote attackers to execute arbitrary code on affected installations of Kepware KEPServerEX 6.11.718.0. Authentication is not required to exploit this vulnerability. The specific flaw exists within the handling of text encoding conversions. The issue…

  • CVE-2023-4296HigAug 29, 2023
    risk 0.57cvss 8.8epss 0.01

    ​If an attacker tricks an admin user of PTC Codebeamer into clicking on a malicious link, it may allow the attacker to inject arbitrary code to be executed in the browser on the target device.

  • CVE-2023-27881HigJun 7, 2023
    risk 0.52cvss 8.0epss 0.01

    A user could use the “Upload Resource” functionality to upload files to any location on the disk.

  • CVE-2023-29445HigJan 10, 2024
    risk 0.51cvss 7.8epss 0.00

    An uncontrolled search path element vulnerability (DLL hijacking) has been discovered that could allow a locally authenticated adversary to escalate privileges to SYSTEM.

  • CVE-2023-5909HigNov 30, 2023
    risk 0.49cvss 7.5epss 0.00

    KEPServerEX does not properly validate certificates from clients which may allow unauthenticated users to connect.

  • CVE-2023-3825HigJul 31, 2023
    risk 0.49cvss 7.5epss 0.01

    PTC’s KEPServerEX Versions 6.0 to 6.14.263 are vulnerable to being made to read a recursively defined object that leads to uncontrolled resource consumption. KEPServerEX uses OPC UA, a protocol which defines various object types that can be nested to create complex arrays. It…

  • CVE-2022-25252HigMar 16, 2022
    risk 0.49cvss 7.5epss 0.02

    When connecting to a certain port Axeda agent (All versions) and Axeda Desktop Server for Windows (All versions) when receiving certain input throws an exception. Services using said function do not handle the exception. Successful exploitation of this vulnerability could allow…