PTC records
36 published records for vendor ptc.
Researcher profile
- Entered KEV
- 1 · 2.8%
- Weaponized
- 1 · 2.8%
- Pre-auth RCE
- 8
- With a fix record
- 0%
- Median publish → KEV
- 8 days
Recurring classes
- CWE-122 Heap-based Buffer Overflow3
- CWE-306 Missing Authentication for Critical Function3
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')3
- CWE-200 Exposure of Sensitive Information to an Unauthorized Actor2
- CWE-119 Improper Restriction of Operations within the Bounds of a Memory Buffer2
- CWE-121 Stack-based Buffer Overflow2
The weakness classes this vendor ships most often: where to look.
CWEAll records
36 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
81Now | CVE-2026-12569Weaponized | Remote Code Execution (RCE) vulnerability in Windchill PDMlinkptc · flexplm · CWE-20 | Critical9.3 | KEV | 46.0% | Jun 17, 2026 |
43Plan | CVE-2023-0755No exploit | The affected products are vulnerable to an improper validation of array index, which could allow an attacker to crash the server and remotege · digital industrial gateway server · CWE-129 | Critical9.8 | — | 11.8% | Feb 23, 2023 |
42Plan | CVE-2020-27265No exploit | KEPServerEX: v6.0 to v6.9, ThingWorx Kepware Server: v6.8 and v6.9, ThingWorx Industrial Connectivity: All versions, OPC-Aggregator: All verge · industrial gateway server · CWE-121 | Critical9.8 | — | 10.1% | Jan 13, 2021 |
40Plan | CVE-2022-25247No exploit | PTC Axeda agent and Axeda Desktop Server Missing Authentication For Critical Functionptc · axeda agent · CWE-306 | Critical9.8 | — | 4.1% | Mar 16, 2022 |
40Plan | CVE-2022-2825No exploit | This vulnerability allows remote attackers to execute arbitrary code on affected installations of Kepware KEPServerEX 6.11.718.0.ge · industrial gateway server · CWE-121 | Critical9.8 | — | 3.4% | Mar 29, 2023 |
40Plan | CVE-2023-0754No exploit | The affected products are vulnerable to an integer overflow or wraparound, which could allow an attacker to crash the server and remotely ge · digital industrial gateway server · CWE-190 | Critical9.8 | — | 2.9% | Feb 23, 2023 |
40Plan | CVE-2022-25251No exploit | PTC Axeda agent and Axeda Desktop Server Missing Authentication For Critical Functionptc · axeda agent · CWE-306 | Critical9.8 | — | 1.9% | Mar 16, 2022 |
39Monitor | CVE-2023-27881No exploit | PTC Vuforia Studio Unrestricted Upload of File with Dangerous Typeptc · vuforia studio · CWE-434 | Critical9.9 | — | 0.7% | Jun 7, 2023 |
37Monitor | CVE-2020-27263No exploit | KEPServerEX: v6.0 to v6.9, ThingWorx Kepware Server: v6.8 and v6.9, ThingWorx Industrial Connectivity: All versions, OPC-Aggregator: All verge · industrial gateway server · CWE-122 | Critical9.1 | — | 4.9% | Jan 13, 2021 |
37Monitor | CVE-2020-27267No exploit | KEPServerEX v6.0 to v6.9, ThingWorx Kepware Server v6.8 and v6.9, ThingWorx Industrial Connectivity (all versions), OPC-Aggregator (all versge · industrial gateway server · CWE-416 | Critical9.1 | — | 4.9% | Jan 13, 2021 |
37Monitor | CVE-2022-2848No exploit | This vulnerability allows remote attackers to execute arbitrary code on affected installations of Kepware KEPServerEX 6.11.718.0.ge · industrial gateway server · CWE-122 | Critical9.1 | — | 3.4% | Mar 29, 2023 |
36Monitor | CVE-2022-25246No exploit | PTC Axeda agent and Axeda Desktop Server Use of Hard-Coded Credentialsptc · axeda agent · CWE-798 | High8.8 | — | 1.8% | Mar 16, 2022 |
36Monitor | CVE-2023-5908No exploit | Heap Based Buffer Overflow in PTC KEPServerExge · industrial gateway server · CWE-122 | Critical9.1 | — | 1.0% | Nov 30, 2023 |
32Monitor | CVE-2023-29152No exploit | PTC Vuforia Studio Improper Authorizationptc · vuforia studio · CWE-285 | High8.1 | — | 0.4% | Jun 7, 2023 |
32Monitor | CVE-2023-31200No exploit | PTC Vuforia Studio Cross-Site Request Forgeryptc · vuforia studio · CWE-352 | High8.0 | — | 0.2% | Jun 7, 2023 |
31Monitor | CVE-2015-2061No exploit | Heap-based buffer overflow in the browser plugin for PTC Creo View allows remote attackers to execute arbitrary code via vectors involving sptc · creo view · CWE-119 | High7.5 | — | 3.9% | Mar 9, 2015 |
31Monitor | CVE-2022-25249No exploit | PTC Axeda agent and Axeda Desktop Server Path Traversalptc · axeda agent · CWE-22 | High7.5 | — | 2.5% | Mar 16, 2022 |
31Monitor | CVE-2018-20092No exploit | PTC ThingWorx Platform through 8.3.0 is vulnerable to a directory traversal attack on ZIP files via a POST request.ptc · thingworx platform · CWE-22 | High7.5 | — | 2.2% | Dec 17, 2018 |
31Monitor | CVE-2023-29445No exploit | Uncontrolled Search Path Element in PTC's Kepware KEPServerEXptc · kepware kepserverex · CWE-427 | High7.8 | — | 0.2% | Jan 10, 2024 |
30Monitor | CVE-2022-25250No exploit | PTC Axeda agent and Axeda Desktop Server Missing Authentication For Critical Functionptc · axeda agent · CWE-306 | High7.5 | — | 1.7% | Mar 16, 2022 |
30Monitor | CVE-2022-25252No exploit | PTC Axeda agent and Axeda Desktop Server Improper Check or Handling Of Exceptional Conditionsptc · axeda agent · CWE-703 | High7.5 | — | 1.6% | Mar 16, 2022 |
30Monitor | CVE-2018-17217No exploit | An issue was discovered in PTC ThingWorx Platform 6.5 through 8.2.ptc · thingworx platform · CWE-798 | High7.5 | — | 0.8% | Sep 30, 2018 |
30Monitor | CVE-2023-29168No exploit | PTC Vuforia Studio Insufficiently Protected Credentialsptc · vuforia studio · CWE-522 | High7.5 | — | 0.5% | Jun 7, 2023 |
30Monitor | CVE-2023-5909No exploit | Improper Validation of Certificate with Host Mismatch in PTC KEPServerExge · industrial gateway server · CWE-297 | High7.5 | — | 0.4% | Nov 30, 2023 |
29Monitor | CVE-2023-29444No exploit | Uncontrolled Search Path Element in PTC's Kepware KEPServerEXptc · kepware kepserverex · CWE-427 | High7.3 | — | 0.2% | Jan 10, 2024 |
- CVE-2026-1256981Now
Remote Code Execution (RCE) vulnerability in Windchill PDMlink
CriticalCVSS 9.3KEVWeaponizedEPSS 46%ptc · flexplmJun 17, 2026
- CVE-2023-075543Plan
The affected products are vulnerable to an improper validation of array index, which could allow an attacker to crash the server and remote
CriticalCVSS 9.8No exploitEPSS 12%ge · digital industrial gateway serverFeb 23, 2023
- CVE-2020-2726542Plan
KEPServerEX: v6.0 to v6.9, ThingWorx Kepware Server: v6.8 and v6.9, ThingWorx Industrial Connectivity: All versions, OPC-Aggregator: All ver
CriticalCVSS 9.8No exploitEPSS 10%ge · industrial gateway serverJan 13, 2021
- CVE-2022-2524740Plan
PTC Axeda agent and Axeda Desktop Server Missing Authentication For Critical Function
CriticalCVSS 9.8No exploitEPSS 4%ptc · axeda agentMar 16, 2022
- CVE-2022-282540Plan
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Kepware KEPServerEX 6.11.718.0.
CriticalCVSS 9.8No exploitEPSS 3%ge · industrial gateway serverMar 29, 2023
- CVE-2023-075440Plan
The affected products are vulnerable to an integer overflow or wraparound, which could allow an attacker to crash the server and remotely
CriticalCVSS 9.8No exploitEPSS 3%ge · digital industrial gateway serverFeb 23, 2023
- CVE-2022-2525140Plan
PTC Axeda agent and Axeda Desktop Server Missing Authentication For Critical Function
CriticalCVSS 9.8No exploitEPSS 2%ptc · axeda agentMar 16, 2022
- CVE-2023-2788139Monitor
PTC Vuforia Studio Unrestricted Upload of File with Dangerous Type
CriticalCVSS 9.9No exploitEPSS 1%ptc · vuforia studioJun 7, 2023
- CVE-2020-2726337Monitor
KEPServerEX: v6.0 to v6.9, ThingWorx Kepware Server: v6.8 and v6.9, ThingWorx Industrial Connectivity: All versions, OPC-Aggregator: All ver
CriticalCVSS 9.1No exploitEPSS 5%ge · industrial gateway serverJan 13, 2021
- CVE-2020-2726737Monitor
KEPServerEX v6.0 to v6.9, ThingWorx Kepware Server v6.8 and v6.9, ThingWorx Industrial Connectivity (all versions), OPC-Aggregator (all vers
CriticalCVSS 9.1No exploitEPSS 5%ge · industrial gateway serverJan 13, 2021
- CVE-2022-284837Monitor
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Kepware KEPServerEX 6.11.718.0.
CriticalCVSS 9.1No exploitEPSS 3%ge · industrial gateway serverMar 29, 2023
- CVE-2022-2524636Monitor
PTC Axeda agent and Axeda Desktop Server Use of Hard-Coded Credentials
HighCVSS 8.8No exploitEPSS 2%ptc · axeda agentMar 16, 2022
- CVE-2023-590836Monitor
Heap Based Buffer Overflow in PTC KEPServerEx
CriticalCVSS 9.1No exploitEPSS 1%ge · industrial gateway serverNov 30, 2023
- CVE-2023-2915232Monitor
PTC Vuforia Studio Improper Authorization
HighCVSS 8.1No exploitEPSS 0%ptc · vuforia studioJun 7, 2023
- CVE-2023-3120032Monitor
PTC Vuforia Studio Cross-Site Request Forgery
HighCVSS 8.0No exploitEPSS 0%ptc · vuforia studioJun 7, 2023
- CVE-2015-206131Monitor
Heap-based buffer overflow in the browser plugin for PTC Creo View allows remote attackers to execute arbitrary code via vectors involving s
HighCVSS 7.5No exploitEPSS 4%ptc · creo viewMar 9, 2015
- CVE-2022-2524931Monitor
PTC Axeda agent and Axeda Desktop Server Path Traversal
HighCVSS 7.5No exploitEPSS 2%ptc · axeda agentMar 16, 2022
- CVE-2018-2009231Monitor
PTC ThingWorx Platform through 8.3.0 is vulnerable to a directory traversal attack on ZIP files via a POST request.
HighCVSS 7.5No exploitEPSS 2%ptc · thingworx platformDec 17, 2018
- CVE-2023-2944531Monitor
Uncontrolled Search Path Element in PTC's Kepware KEPServerEX
HighCVSS 7.8No exploitEPSS 0%ptc · kepware kepserverexJan 10, 2024
- CVE-2022-2525030Monitor
PTC Axeda agent and Axeda Desktop Server Missing Authentication For Critical Function
HighCVSS 7.5No exploitEPSS 2%ptc · axeda agentMar 16, 2022
- CVE-2022-2525230Monitor
PTC Axeda agent and Axeda Desktop Server Improper Check or Handling Of Exceptional Conditions
HighCVSS 7.5No exploitEPSS 2%ptc · axeda agentMar 16, 2022
- CVE-2018-1721730Monitor
An issue was discovered in PTC ThingWorx Platform 6.5 through 8.2.
HighCVSS 7.5No exploitEPSS 1%ptc · thingworx platformSep 30, 2018
- CVE-2023-2916830Monitor
PTC Vuforia Studio Insufficiently Protected Credentials
HighCVSS 7.5No exploitEPSS 0%ptc · vuforia studioJun 7, 2023
- CVE-2023-590930Monitor
Improper Validation of Certificate with Host Mismatch in PTC KEPServerEx
HighCVSS 7.5No exploitEPSS 0%ge · industrial gateway serverNov 30, 2023
- CVE-2023-2944429Monitor
Uncontrolled Search Path Element in PTC's Kepware KEPServerEX
HighCVSS 7.3No exploitEPSS 0%ptc · kepware kepserverexJan 10, 2024