Skip to main content

Vendor archive

ptc CVEs

Beta · best-effort

35 CVEs tagged to vendor ptc12 Critical, 9 High, 12 Medium, 2 Low, 0 Unrated.

CVE-2026-12569

Published Jun 18, 2026

A critical remote code execution (RCE) vulnerability has been reported in PTC Windchill PDMlink and PTC FlexPLM. The vulnerability may be exploited through the deserialization of…

CVSS 9.3 · Critical
evidence mentions
9
Buzz score
68.0
KEV listed
Vendor/product tagsBeta · best-effort

CVE-2024-40395

Published Aug 27, 2024

An Insecure Direct Object Reference (IDOR) in PTC ThingWorx v9.5.0 allows attackers to view sensitive information, including PII, regardless of access level.

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-31200

Published Jun 7, 2023

PTC Vuforia Studio does not require a token; this could allow an attacker with local access to perform a cross-site request forgery attack or a replay attack.

CVSS 5.7 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-29502

Published Jun 7, 2023

Before importing a project into Vuforia, a user could modify the “resourceDirectory” attribute in the appConfig.json file to be a different path.

CVSS 6.2 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-29168

Published Jun 7, 2023

The local Vuforia web application does not support HTTPS, and federated credentials are passed via basic authentication.

CVSS 3.7 · Low
Vendor/product tagsBeta · best-effort

CVE-2023-29152

Published Jun 7, 2023

By changing the filename parameter in the request, an attacker could delete any file with the permissions of the Vuforia server account.

CVSS 6.2 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-27881

Published Jun 7, 2023

A user could use the “Upload Resource” functionality to upload files to any location on the disk.

CVSS 8.0 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2023-24476

Published Jun 7, 2023

An attacker with local access to the machine could record the traffic, which could allow them to resend requests without the server authenticating that the user or session are v…

CVSS 1.8 · Low
Vendor/product tagsBeta · best-effort

CVE-2022-2848

Published Mar 29, 2023

This vulnerability allows remote attackers to execute arbitrary code on affected installations of Kepware KEPServerEX 6.11.718.0. Authentication is not required to exploit this vu…

CVSS 9.1 · Critical
evidence mentions
1
Buzz score
11.9

CVE-2022-2825

Published Mar 29, 2023

This vulnerability allows remote attackers to execute arbitrary code on affected installations of Kepware KEPServerEX 6.11.718.0. Authentication is not required to exploit this vu…

CVSS 9.8 · Critical
evidence mentions
1
Buzz score
11.9

CVE-2023-0755

Published Feb 23, 2023

The affected products are vulnerable to an improper validation of array index, which could allow an attacker to crash the server and remotely execute arbitrary code.

CVSS 9.8 · Critical
evidence mentions
1
Buzz score
11.9

CVE-2023-0754

Published Feb 23, 2023

The affected products are vulnerable to an integer overflow or wraparound, which could  allow an attacker to crash the server and remotely execute arbitrary code.

CVSS 9.8 · Critical
evidence mentions
1
Buzz score
11.9

CVE-2022-25252

Published Mar 16, 2022

When connecting to a certain port Axeda agent (All versions) and Axeda Desktop Server for Windows (All versions) when receiving certain input throws an exception. Services using s…

CVSS 7.5 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2022-25251

Published Mar 16, 2022

When connecting to a certain port Axeda agent (All versions) and Axeda Desktop Server for Windows (All versions) may allow an attacker to send certain XML messages to a specific p…

CVSS 9.8 · Critical
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2022-25250

Published Mar 16, 2022

When connecting to a certain port Axeda agent (All versions) and Axeda Desktop Server for Windows (All versions) may allow an attacker to send a certain command to a specific port…

CVSS 7.5 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2022-25249

Published Mar 16, 2022

When connecting to a certain port Axeda agent (All versions) and Axeda Desktop Server for Windows (All versions) (disregarding Axeda agent v6.9.2 and v6.9.3) is vulnerable to dire…

CVSS 7.5 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2022-25248

Published Mar 16, 2022

When connecting to a certain port Axeda agent (All versions) and Axeda Desktop Server for Windows (All versions) supplies the event log of the specific service.

CVSS 5.3 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2022-25247

Published Mar 16, 2022

Axeda agent (All versions) and Axeda Desktop Server for Windows (All versions) may allow an attacker to send certain commands to a specific port without authentication. Successful…

CVSS 9.8 · Critical
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2022-25246

Published Mar 16, 2022

Axeda agent (All versions) and Axeda Desktop Server for Windows (All versions) uses hard-coded credentials for its UltraVNC installation. Successful exploitation of this vulnerabi…

CVSS 9.8 · Critical
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort
Showing 1-25 of 35 CVEsPage 1 of 2