Skip to main content

Vendor archive

codesys CVEs

Beta · best-effort

115 CVEs tagged to vendor codesys11 Critical, 69 High, 34 Medium, 1 Low, 0 Unrated.

CVE-2026-44469

Published May 26, 2026

The affected product extracts installation files to a temporary directory with incorrect default permissions during administrative installation. A low-privileged local attacker ca…

CVSS 8.5 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-44468

Published May 26, 2026

The affected product creates a directory with insecure default permissions during administrative installation. This allows a low-privileged local attacker to modify a temporary fi…

CVSS 8.5 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-0393

Published May 21, 2026

The affected product may expose credentials remotely between low privileged visualization users during concurrent login operations due to insufficient isolation of authentication…

CVSS 6.9 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2025-41700

Published Dec 1, 2025

An unauthenticated attacker can trick a local user into executing arbitrary code by opening a deliberately manipulated CODESYS project file with a CODESYS development system. This…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2024-6876

Published Sep 10, 2024

Out-of-Bounds read vulnerability in OSCAT Basic Library allows an local, unprivileged attacker to access limited internal data of the PLC which may lead to a crash of the affected…

CVSS 4.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-3669

Published Aug 3, 2023

A missing Brute-Force protection in CODESYS Development System prior to 3.5.19.20 allows a local attacker to have unlimited attempts of guessing the password within an import dial…

CVSS 3.3 · Low
Vendor/product tagsBeta · best-effort

CVE-2023-3663

Published Aug 3, 2023

In CODESYS Development System versions from 3.5.11.20 and before 3.5.19.20 a missing integrity check might allow an unauthenticated remote attacker to manipulate the content of no…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2023-3662

Published Aug 3, 2023

In CODESYS Development System versions from 3.5.17.0 and prior to 3.5.19.20 a vulnerability allows for execution of binaries from the current working directory in the users contex…

CVSS 7.3 · High
Vendor/product tagsBeta · best-effort
Showing 1-25 of 115 CVEsPage 1 of 5