AVEVA records
71 published records for vendor aveva.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 4
- With a fix record
- 0%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')7
- CWE-427 Uncontrolled Search Path Element6
- CWE-200 Exposure of Sensitive Information to an Unauthorized Actor5
- CWE-121 Stack-based Buffer Overflow4
- CWE-476 NULL Pointer Dereference4
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')3
The weakness classes this vendor ships most often: where to look.
CWEAll records
71 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
44Plan | CVE-2022-23854Proof of concept | AVEVA InTouch Access Anywhere versions 2020 R2 and older are vulnerable to a path traversal exploit that could allow an unauthenticated useraveva · intouch access anywhere · CWE-23 | High7.5 | — | 46.0% | Dec 23, 2022 |
44Plan | CVE-2019-6543Proof of concept | AVEVA Software, LLC InduSoft Web Studio prior to Version 8.1 SP3 and InTouch Edge HMI (formerly InTouch Machine Edition) prior to Version 20aveva · indusoft web studio · CWE-306 | Critical9.8 | — | 17.3% | Feb 12, 2019 |
42Plan | CVE-2011-3143No exploit | Use-after-free vulnerability in Control Microsystems ClearSCADA 2005, 2007, and 2009 before R2.3 and R1.4, as used in SCX before 67 R4.5 andaveva · clearscada · CWE-399 | Critical10.0 | — | 7.5% | Aug 16, 2011 |
41Plan | CVE-2018-10628No exploit | AVEVA InTouch 2014 R2 SP1 and prior, InTouch 2017, InTouch 2017 Update 1, and InTouch 2017 Update 2 allow an unauthenticated user to send a aveva · intouch 2014 · CWE-121 | Critical9.8 | — | 5.4% | Jul 24, 2018 |
40Plan | CVE-2018-17914No exploit | InduSoft Web Studio versions prior to 8.1 SP2, and InTouch Edge HMI (formerly InTouch Machine Edition) versions prior to 2017 SP2.aveva · indusoft web studio · CWE-258 | Critical9.8 | — | 4.6% | Nov 2, 2018 |
40Plan | CVE-2018-10620No exploit | AVEVA InduSoft Web Studio v8.1 and v8.1SP1, and InTouch Machine Edition v2017 8.1 and v2017 8.1 SP1 a remote user could send a carefully craaveva · indusoft web studio · CWE-121 | Critical9.8 | — | 4.2% | Jul 19, 2018 |
40Plan | CVE-2018-17916No exploit | InduSoft Web Studio versions prior to 8.1 SP2, and InTouch Edge HMI (formerly InTouch Machine Edition) versions prior to 2017 SP2.aveva · indusoft web studio · CWE-121 | Critical9.8 | — | 3.7% | Nov 2, 2018 |
40Plan | CVE-2020-13501No exploit | An SQL injection vulnerability exists in the CHaD.asmx web service functionality of eDNA Enterprise Data Historian 3.0.1.2/7.5.4989.33053.aveva · edna enterprise data historian · CWE-89 | Critical9.8 | — | 2.9% | Sep 24, 2020 |
40Plan | CVE-2020-13500No exploit | SQL injection vulnerability exists in the CHaD.asmx web service functionality of eDNA Enterprise Data Historian 3.0.1.2/7.5.4989.33053.aveva · edna enterprise data historian · CWE-89 | Critical9.8 | — | 2.9% | Sep 24, 2020 |
40Plan | CVE-2020-13499No exploit | An SQL injection vulnerability exists in the CHaD.asmx web service functionality of eDNA Enterprise Data Historian 3.0.1.2/7.5.4989.33053.aveva · edna enterprise data historian · CWE-89 | Critical9.8 | — | 2.9% | Sep 24, 2020 |
40Plan | CVE-2017-5158No exploit | An Information Exposure issue was discovered in Schneider Electric Wonderware InTouch Access Anywhere, version 11.5.2 and prior.aveva · wonderware intouch access anywhere · CWE-200 | Critical9.8 | — | 2.4% | Apr 20, 2017 |
40Plan | CVE-2025-61937No exploit | AVEVA Process Optimization Code Injectionaveva · process optimization · CWE-94 | Critical10.0 | — | 1.5% | Jan 15, 2026 |
39Monitor | CVE-2020-13504No exploit | Parameter AttFilterValue in ednareporting.asmx is vulnerable to unauthenticated SQL injection attacks.aveva · edna enterprise data historian · CWE-89 | Critical9.8 | — | 1.2% | Sep 24, 2020 |
39Monitor | CVE-2020-13505No exploit | Parameter psClass in ednareporting.asmx is vulnerable to unauthenticated SQL injection attacks.aveva · edna enterprise data historian · CWE-89 | Critical9.8 | — | 1.2% | Sep 24, 2020 |
39Monitor | CVE-2021-33008No exploit | AVEVA System Platform Missing Authentication for Critical Functionaveva · system platform · CWE-306 | Critical9.8 | — | 1.2% | Apr 4, 2022 |
39Monitor | CVE-2021-42796No exploit | An issue was discovered in ExecuteCommand() in AVEVA Edge (formerly InduSoft Web Studio) versions R2020 and prior that allows unauthenticateaveva · edge · CWE-78 | Critical9.8 | — | 1.1% | Dec 15, 2023 |
39Monitor | CVE-2022-1467No exploit | AVEVA InTouch Access Anywhere Exposure of Resource to Wrong Sphereaveva · intouch access anywhere · CWE-668 | Critical9.9 | — | 1.0% | May 23, 2022 |
39Monitor | CVE-2021-32959No exploit | AVEVA SuiteLink Server Buffer Overflowaveva · suitelink · CWE-122 | Critical9.8 | — | 0.9% | Sep 23, 2021 |
39Monitor | CVE-2023-1256No exploit | The listed versions of AVEVA Plant SCADA and AVEVA Telemetry Server are vulnerable to an improper authorization exploit which could allow anaveva · aveva plant scada · CWE-285 | Critical9.8 | — | 0.7% | Mar 16, 2023 |
37Monitor | CVE-2025-61943No exploit | AVEVA Process Optimization SQL Injectionaveva · process optimization · CWE-89 | Critical9.3 | — | 0.3% | Jan 15, 2026 |
37Monitor | CVE-2025-64691No exploit | AVEVA Process Optimization Code Injectionaveva · process optimization · CWE-94 | Critical9.3 | — | 0.3% | Jan 15, 2026 |
37Monitor | CVE-2025-65118No exploit | AVEVA Process Optimization Uncontrolled Search Path Elementaveva · process optimization · CWE-427 | Critical9.3 | — | 0.3% | Jan 15, 2026 |
36Monitor | CVE-2022-28685No exploit | This vulnerability allows remote attackers to execute arbitrary code on affected installations of AVEVA Edge 2020 SP2 Patch 0(4201.2111.1802aveva · aveva edge · CWE-502 | High7.8 | — | 17.2% | Mar 29, 2023 |
35Monitor | CVE-2019-6525No exploit | AVEVA Wonderware System Platform 2017 Update 2 and prior uses an ArchestrA network user account for authentication of system processes and iaveva · wonderware system platform · CWE-522 | High8.8 | — | 1.3% | Apr 11, 2019 |
35Monitor | CVE-2017-5156No exploit | A Cross-Site Request Forgery issue was discovered in Schneider Electric Wonderware InTouch Access Anywhere, version 11.5.2 and prior.aveva · wonderware intouch access anywhere · CWE-352 | High8.8 | — | 1.0% | Apr 20, 2017 |
- CVE-2022-2385444Plan
AVEVA InTouch Access Anywhere versions 2020 R2 and older are vulnerable to a path traversal exploit that could allow an unauthenticated user
HighCVSS 7.5Proof of conceptEPSS 46%aveva · intouch access anywhereDec 23, 2022
- CVE-2019-654344Plan
AVEVA Software, LLC InduSoft Web Studio prior to Version 8.1 SP3 and InTouch Edge HMI (formerly InTouch Machine Edition) prior to Version 20
CriticalCVSS 9.8Proof of conceptEPSS 17%aveva · indusoft web studioFeb 12, 2019
- CVE-2011-314342Plan
Use-after-free vulnerability in Control Microsystems ClearSCADA 2005, 2007, and 2009 before R2.3 and R1.4, as used in SCX before 67 R4.5 and
CriticalCVSS 10.0No exploitEPSS 8%aveva · clearscadaAug 16, 2011
- CVE-2018-1062841Plan
AVEVA InTouch 2014 R2 SP1 and prior, InTouch 2017, InTouch 2017 Update 1, and InTouch 2017 Update 2 allow an unauthenticated user to send a
CriticalCVSS 9.8No exploitEPSS 5%aveva · intouch 2014Jul 24, 2018
- CVE-2018-1791440Plan
InduSoft Web Studio versions prior to 8.1 SP2, and InTouch Edge HMI (formerly InTouch Machine Edition) versions prior to 2017 SP2.
CriticalCVSS 9.8No exploitEPSS 5%aveva · indusoft web studioNov 2, 2018
- CVE-2018-1062040Plan
AVEVA InduSoft Web Studio v8.1 and v8.1SP1, and InTouch Machine Edition v2017 8.1 and v2017 8.1 SP1 a remote user could send a carefully cra
CriticalCVSS 9.8No exploitEPSS 4%aveva · indusoft web studioJul 19, 2018
- CVE-2018-1791640Plan
InduSoft Web Studio versions prior to 8.1 SP2, and InTouch Edge HMI (formerly InTouch Machine Edition) versions prior to 2017 SP2.
CriticalCVSS 9.8No exploitEPSS 4%aveva · indusoft web studioNov 2, 2018
- CVE-2020-1350140Plan
An SQL injection vulnerability exists in the CHaD.asmx web service functionality of eDNA Enterprise Data Historian 3.0.1.2/7.5.4989.33053.
CriticalCVSS 9.8No exploitEPSS 3%aveva · edna enterprise data historianSep 24, 2020
- CVE-2020-1350040Plan
SQL injection vulnerability exists in the CHaD.asmx web service functionality of eDNA Enterprise Data Historian 3.0.1.2/7.5.4989.33053.
CriticalCVSS 9.8No exploitEPSS 3%aveva · edna enterprise data historianSep 24, 2020
- CVE-2020-1349940Plan
An SQL injection vulnerability exists in the CHaD.asmx web service functionality of eDNA Enterprise Data Historian 3.0.1.2/7.5.4989.33053.
CriticalCVSS 9.8No exploitEPSS 3%aveva · edna enterprise data historianSep 24, 2020
- CVE-2017-515840Plan
An Information Exposure issue was discovered in Schneider Electric Wonderware InTouch Access Anywhere, version 11.5.2 and prior.
CriticalCVSS 9.8No exploitEPSS 2%aveva · wonderware intouch access anywhereApr 20, 2017
- CVE-2025-6193740Plan
AVEVA Process Optimization Code Injection
CriticalCVSS 10.0No exploitEPSS 2%aveva · process optimizationJan 15, 2026
- CVE-2020-1350439Monitor
Parameter AttFilterValue in ednareporting.asmx is vulnerable to unauthenticated SQL injection attacks.
CriticalCVSS 9.8No exploitEPSS 1%aveva · edna enterprise data historianSep 24, 2020
- CVE-2020-1350539Monitor
Parameter psClass in ednareporting.asmx is vulnerable to unauthenticated SQL injection attacks.
CriticalCVSS 9.8No exploitEPSS 1%aveva · edna enterprise data historianSep 24, 2020
- CVE-2021-3300839Monitor
AVEVA System Platform Missing Authentication for Critical Function
CriticalCVSS 9.8No exploitEPSS 1%aveva · system platformApr 4, 2022
- CVE-2021-4279639Monitor
An issue was discovered in ExecuteCommand() in AVEVA Edge (formerly InduSoft Web Studio) versions R2020 and prior that allows unauthenticate
CriticalCVSS 9.8No exploitEPSS 1%aveva · edgeDec 15, 2023
- CVE-2022-146739Monitor
AVEVA InTouch Access Anywhere Exposure of Resource to Wrong Sphere
CriticalCVSS 9.9No exploitEPSS 1%aveva · intouch access anywhereMay 23, 2022
- CVE-2021-3295939Monitor
AVEVA SuiteLink Server Buffer Overflow
CriticalCVSS 9.8No exploitEPSS 1%aveva · suitelinkSep 23, 2021
- CVE-2023-125639Monitor
The listed versions of AVEVA Plant SCADA and AVEVA Telemetry Server are vulnerable to an improper authorization exploit which could allow an
CriticalCVSS 9.8No exploitEPSS 1%aveva · aveva plant scadaMar 16, 2023
- CVE-2025-6194337Monitor
AVEVA Process Optimization SQL Injection
CriticalCVSS 9.3No exploitEPSS 0%aveva · process optimizationJan 15, 2026
- CVE-2025-6469137Monitor
AVEVA Process Optimization Code Injection
CriticalCVSS 9.3No exploitEPSS 0%aveva · process optimizationJan 15, 2026
- CVE-2025-6511837Monitor
AVEVA Process Optimization Uncontrolled Search Path Element
CriticalCVSS 9.3No exploitEPSS 0%aveva · process optimizationJan 15, 2026
- CVE-2022-2868536Monitor
This vulnerability allows remote attackers to execute arbitrary code on affected installations of AVEVA Edge 2020 SP2 Patch 0(4201.2111.1802
HighCVSS 7.8No exploitEPSS 17%aveva · aveva edgeMar 29, 2023
- CVE-2019-652535Monitor
AVEVA Wonderware System Platform 2017 Update 2 and prior uses an ArchestrA network user account for authentication of system processes and i
HighCVSS 8.8No exploitEPSS 1%aveva · wonderware system platformApr 11, 2019
- CVE-2017-515635Monitor
A Cross-Site Request Forgery issue was discovered in Schneider Electric Wonderware InTouch Access Anywhere, version 11.5.2 and prior.
HighCVSS 8.8No exploitEPSS 1%aveva · wonderware intouch access anywhereApr 20, 2017