3ds records
67 published records for vendor 3ds.
Researcher profile
- Entered KEV
- 3 · 4.5%
- Weaponized
- 3 · 4.5%
- Pre-auth RCE
- 12
- With a fix record
- 0%
- Median publish → KEV
- 85 days
Recurring classes
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')34
- CWE-502 Deserialization of Untrusted Data4
- CWE-787 Out-of-bounds Write4
- CWE-78 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')3
- CWE-122 Heap-based Buffer Overflow3
- CWE-416 Use After Free2
The weakness classes this vendor ships most often: where to look.
CWEAll records
67 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
95Now | CVE-2025-5086Weaponized | Deserialization of Untrusted Data vulnerability affecting DELMIA Apriso from Release 2020 through Release 20253ds · delmia apriso · CWE-502 | Critical9.0 | KEV | 96.9% | Jun 2, 2025 |
88Now | CVE-2025-6205Weaponized | Missing authorization vulnerability affecting DELMIA Apriso from Release 2020 through Release 20253ds · delmia apriso · CWE-862 | Critical9.1 | KEV | 73.3% | Aug 4, 2025 |
85Now | CVE-2025-6204Weaponized | Improper Control of Generation of Code (Code Injection) vulnerability affecting DELMIA Apriso from Release 2020 through Release 20253ds · delmia apriso · CWE-94 | High8.0 | KEV | 78.0% | Aug 4, 2025 |
41Plan | CVE-2014-2072Proof of concept | Dassault Systemes Catia V5-6R2013: Stack Buffer Overflow due to inadequate boundary checks3ds · catia · CWE-787 | Critical9.8 | — | 7.4% | Jan 8, 2020 |
40Plan | CVE-2014-2073No exploit | Stack-based buffer overflow in Dassault Systemes CATIA V5-6R2013 allows remote attackers to execute arbitrary code via a crafted packet, rel3ds · catia · CWE-787 | Critical9.8 | — | 5.0% | Apr 10, 2018 |
39Monitor | CVE-2023-6078No exploit | OS Command Injection vulnerability affecting BIOVIA Materials Studio products from Release BIOVIA 2021 through Release BIOVIA 20233ds · biovia materials studio · CWE-78 | Critical9.8 | — | 1.6% | Feb 1, 2024 |
39Monitor | CVE-2023-1287No exploit | ENOVIA Live Collaboration V6R2013xE is affected by an XSL template injection vulnerability3ds · enovia live collaboration · CWE-74 | Critical9.8 | — | 1.0% | Mar 9, 2023 |
38Monitor | CVE-2024-1624No exploit | OS Command Injection vulnerability affecting documentation server on certain Releases of 3DEXPERIENCE, SIMULIA Abaqus, SIMULIA Isight and CATIA Composerdassault systèmes · documentation server · CWE-78 | Critical9.4 | — | 2.1% | Mar 1, 2024 |
37Monitor | CVE-2024-3300Proof of concept | Pre-authentication Unsafe .NET object deserialization vulnerability affecting DELMIA Apriso Release 2019 through Release 2024dassault systèmes · delmia apriso · CWE-502 | Critical9.0 | — | 2.8% | May 30, 2024 |
36Monitor | CVE-2023-1997No exploit | OS Command Injection vulnerability affecting SIMULIA 3DOrchestrate from Release 3DEXPERIENCE R2021x through Release 3DEXPERIENCE R2023x3ds · 3dexperience · CWE-78 | High8.8 | — | 1.9% | Aug 28, 2023 |
36Monitor | CVE-2025-10559No exploit | Path Traversal vulnerability affecting Factory Resource Management in DELMIA Factory Resource Manager from Release 3DEXPERIENCE R2023x through Release 3DEXPERIE3ds · 3dexperience · CWE-22 | Critical9.1 | — | 0.3% | Mar 31, 2026 |
35Monitor | CVE-2023-2141No exploit | Unsafe .NET object deserialization affecting DELMIA Apriso Release 2017 through Release 20223ds · delmia apriso · CWE-502 | High8.8 | — | 1.0% | Apr 21, 2023 |
34Monitor | CVE-2024-3301No exploit | Post-authentication Unsafe .NET object deserialization vulnerability affecting DELMIA Apriso Release 2019 through Release 2024dassault systèmes · delmia apriso · CWE-502 | High8.5 | — | 0.7% | May 30, 2024 |
31Monitor | CVE-2020-25507No exploit | An incorrect permission assignment during the installation script of TeamworkCloud 18.0 thru 19.0 allows a local unprivileged attacker to ex3ds · teamwork cloud · CWE-732 | High7.8 | — | 0.5% | Dec 28, 2020 |
31Monitor | CVE-2023-2762No exploit | Use-After-Free vulnerability in SLDPRT file reading procedure affecting SOLIDWORKS Desktop from Release SOLIDWORKS 2021 through Release SOLIDWORKS 20233ds · 3dexperience solidworks · CWE-416 | High7.8 | — | 0.4% | Jul 12, 2023 |
31Monitor | CVE-2024-3299No exploit | Out-Of-Bounds Write, Use of Uninitialized Resource and Use-After-Free vulnerabilities exist in the SLDDRW and SLDPRT file reading procedure in eDrawings from Redassault systèmes · edrawings · CWE-416 | High7.8 | — | 0.4% | Apr 4, 2024 |
31Monitor | CVE-2023-2763No exploit | Use-After-Free, Out-of-bounds Write and Heap-based Buffer Overflow vulnerabilities exist in the DWG and DXF file reading procedure in SOLIDWORKS Desktop from Re3ds · 3dexperience solidworks · CWE-122 | High7.8 | — | 0.4% | Jul 12, 2023 |
31Monitor | CVE-2024-1847No exploit | Multiple vulnerabilities exist in file reading procedure in eDrawings from Release SOLIDWORKS 2023 through Release SOLIDWORKS 20243ds · solidworks · CWE-122 | High7.8 | — | 0.3% | Feb 28, 2024 |
31Monitor | CVE-2024-3298No exploit | Out-Of-Bounds Write and Type Confusion vulnerabilities exist in the DWG and DXF file reading procedure in eDrawings from Release SOLIDWORKS 2023 through Releasedassault systèmes · edrawings · CWE-787 | High7.8 | — | 0.3% | Apr 4, 2024 |
31Monitor | CVE-2024-1848No exploit | Multiple vulnerabilities exist in file reading procedure in SOLIDWORKS Desktop on Release SOLIDWORKS 2024dassault systèmes · solidworks desktop · CWE-122 | High7.8 | — | 0.3% | Mar 22, 2024 |
31Monitor | CVE-2026-3476No exploit | Code Injection vulnerability affecting SOLIDWORKS Desktop from Release 2025 through Release 20263ds · solidworks · CWE-94 | High7.8 | — | 0.2% | Mar 16, 2026 |
31Monitor | CVE-2026-1335No exploit | Out-Of-Bounds Write vulnerability affecting the EPRT file reading procedure in SOLIDWORKS eDrawings from Release SOLIDWORKS Desktop 2025 through Release SOLIDWO3ds · solidworks edrawings · CWE-787 | High7.8 | — | 0.2% | Feb 16, 2026 |
31Monitor | CVE-2026-1333No exploit | Use of Uninitialized Variable vulnerability affecting the EPRT file reading procedure in SOLIDWORKS eDrawings from Release SOLIDWORKS Desktop 2025 through Relea3ds · solidworks edrawings · CWE-457 | High7.8 | — | 0.2% | Feb 16, 2026 |
31Monitor | CVE-2026-1334No exploit | Out-Of-Bounds Read vulnerability affecting the EPRT file reading procedure in SOLIDWORKS eDrawings from Release SOLIDWORKS Desktop 2025 through Release SOLIDWOR3ds · solidworks edrawings · CWE-125 | High7.8 | — | 0.2% | Feb 16, 2026 |
30Monitor | CVE-2013-4721No exploit | SQL injection vulnerability in the RSS feed from records extension 1.0.0 and earlier for TYPO3 allows remote attackers to execute arbitrary typo3 · typo3 · CWE-89 | High7.5 | — | 1.2% | Jun 27, 2013 |
- CVE-2025-508695Now
Deserialization of Untrusted Data vulnerability affecting DELMIA Apriso from Release 2020 through Release 2025
CriticalCVSS 9.0KEVWeaponizedEPSS 97%3ds · delmia aprisoJun 2, 2025
- CVE-2025-620588Now
Missing authorization vulnerability affecting DELMIA Apriso from Release 2020 through Release 2025
CriticalCVSS 9.1KEVWeaponizedEPSS 73%3ds · delmia aprisoAug 4, 2025
- CVE-2025-620485Now
Improper Control of Generation of Code (Code Injection) vulnerability affecting DELMIA Apriso from Release 2020 through Release 2025
HighCVSS 8.0KEVWeaponizedEPSS 78%3ds · delmia aprisoAug 4, 2025
- CVE-2014-207241Plan
Dassault Systemes Catia V5-6R2013: Stack Buffer Overflow due to inadequate boundary checks
CriticalCVSS 9.8Proof of conceptEPSS 7%3ds · catiaJan 8, 2020
- CVE-2014-207340Plan
Stack-based buffer overflow in Dassault Systemes CATIA V5-6R2013 allows remote attackers to execute arbitrary code via a crafted packet, rel
CriticalCVSS 9.8No exploitEPSS 5%3ds · catiaApr 10, 2018
- CVE-2023-607839Monitor
OS Command Injection vulnerability affecting BIOVIA Materials Studio products from Release BIOVIA 2021 through Release BIOVIA 2023
CriticalCVSS 9.8No exploitEPSS 2%3ds · biovia materials studioFeb 1, 2024
- CVE-2023-128739Monitor
ENOVIA Live Collaboration V6R2013xE is affected by an XSL template injection vulnerability
CriticalCVSS 9.8No exploitEPSS 1%3ds · enovia live collaborationMar 9, 2023
- CVE-2024-162438Monitor
OS Command Injection vulnerability affecting documentation server on certain Releases of 3DEXPERIENCE, SIMULIA Abaqus, SIMULIA Isight and CATIA Composer
CriticalCVSS 9.4No exploitEPSS 2%dassault systèmes · documentation serverMar 1, 2024
- CVE-2024-330037Monitor
Pre-authentication Unsafe .NET object deserialization vulnerability affecting DELMIA Apriso Release 2019 through Release 2024
CriticalCVSS 9.0Proof of conceptEPSS 3%dassault systèmes · delmia aprisoMay 30, 2024
- CVE-2023-199736Monitor
OS Command Injection vulnerability affecting SIMULIA 3DOrchestrate from Release 3DEXPERIENCE R2021x through Release 3DEXPERIENCE R2023x
HighCVSS 8.8No exploitEPSS 2%3ds · 3dexperienceAug 28, 2023
- CVE-2025-1055936Monitor
Path Traversal vulnerability affecting Factory Resource Management in DELMIA Factory Resource Manager from Release 3DEXPERIENCE R2023x through Release 3DEXPERIE
CriticalCVSS 9.1No exploitEPSS 0%3ds · 3dexperienceMar 31, 2026
- CVE-2023-214135Monitor
Unsafe .NET object deserialization affecting DELMIA Apriso Release 2017 through Release 2022
HighCVSS 8.8No exploitEPSS 1%3ds · delmia aprisoApr 21, 2023
- CVE-2024-330134Monitor
Post-authentication Unsafe .NET object deserialization vulnerability affecting DELMIA Apriso Release 2019 through Release 2024
HighCVSS 8.5No exploitEPSS 1%dassault systèmes · delmia aprisoMay 30, 2024
- CVE-2020-2550731Monitor
An incorrect permission assignment during the installation script of TeamworkCloud 18.0 thru 19.0 allows a local unprivileged attacker to ex
HighCVSS 7.8No exploitEPSS 1%3ds · teamwork cloudDec 28, 2020
- CVE-2023-276231Monitor
Use-After-Free vulnerability in SLDPRT file reading procedure affecting SOLIDWORKS Desktop from Release SOLIDWORKS 2021 through Release SOLIDWORKS 2023
HighCVSS 7.8No exploitEPSS 0%3ds · 3dexperience solidworksJul 12, 2023
- CVE-2024-329931Monitor
Out-Of-Bounds Write, Use of Uninitialized Resource and Use-After-Free vulnerabilities exist in the SLDDRW and SLDPRT file reading procedure in eDrawings from Re
HighCVSS 7.8No exploitEPSS 0%dassault systèmes · edrawingsApr 4, 2024
- CVE-2023-276331Monitor
Use-After-Free, Out-of-bounds Write and Heap-based Buffer Overflow vulnerabilities exist in the DWG and DXF file reading procedure in SOLIDWORKS Desktop from Re
HighCVSS 7.8No exploitEPSS 0%3ds · 3dexperience solidworksJul 12, 2023
- CVE-2024-184731Monitor
Multiple vulnerabilities exist in file reading procedure in eDrawings from Release SOLIDWORKS 2023 through Release SOLIDWORKS 2024
HighCVSS 7.8No exploitEPSS 0%3ds · solidworksFeb 28, 2024
- CVE-2024-329831Monitor
Out-Of-Bounds Write and Type Confusion vulnerabilities exist in the DWG and DXF file reading procedure in eDrawings from Release SOLIDWORKS 2023 through Release
HighCVSS 7.8No exploitEPSS 0%dassault systèmes · edrawingsApr 4, 2024
- CVE-2024-184831Monitor
Multiple vulnerabilities exist in file reading procedure in SOLIDWORKS Desktop on Release SOLIDWORKS 2024
HighCVSS 7.8No exploitEPSS 0%dassault systèmes · solidworks desktopMar 22, 2024
- CVE-2026-347631Monitor
Code Injection vulnerability affecting SOLIDWORKS Desktop from Release 2025 through Release 2026
HighCVSS 7.8No exploitEPSS 0%3ds · solidworksMar 16, 2026
- CVE-2026-133531Monitor
Out-Of-Bounds Write vulnerability affecting the EPRT file reading procedure in SOLIDWORKS eDrawings from Release SOLIDWORKS Desktop 2025 through Release SOLIDWO
HighCVSS 7.8No exploitEPSS 0%3ds · solidworks edrawingsFeb 16, 2026
- CVE-2026-133331Monitor
Use of Uninitialized Variable vulnerability affecting the EPRT file reading procedure in SOLIDWORKS eDrawings from Release SOLIDWORKS Desktop 2025 through Relea
HighCVSS 7.8No exploitEPSS 0%3ds · solidworks edrawingsFeb 16, 2026
- CVE-2026-133431Monitor
Out-Of-Bounds Read vulnerability affecting the EPRT file reading procedure in SOLIDWORKS eDrawings from Release SOLIDWORKS Desktop 2025 through Release SOLIDWOR
HighCVSS 7.8No exploitEPSS 0%3ds · solidworks edrawingsFeb 16, 2026
- CVE-2013-472130Monitor
SQL injection vulnerability in the RSS feed from records extension 1.0.0 and earlier for TYPO3 allows remote attackers to execute arbitrary
HighCVSS 7.5No exploitEPSS 1%typo3 · typo3Jun 27, 2013