PTC
- Products in analyzed data
- 17
- Catalog vulnerabilities
- 44
Severity across 31 analyzed records
Verify to analyze this security profile
A short verification protects source data and prevents automated AI requests.
en
Severity across 31 analyzed records
A short verification protects source data and prevents automated AI requests.
The GCVE catalog currently lists 44 vulnerability records associated with PTC.
Among the 31 records analyzed by CyStack, 21 are High or Critical and 1 appear in the CISA KEV catalog for priority remediation.
The list below is based on vulnerabilities that have been viewed and analyzed; it does not represent the complete global vulnerability corpus. Use the product filter to narrow the scope.
| CVE | Exploitation status | Fix | Affected product | Published | Severity |
|---|---|---|---|---|---|
CVE-2026-77646Server Side Request Forgery (SSRF) vulnerability reported in Windchill | Exploitation statusNot known exploited | FixNot confirmed | Affected productWindchill PDMLink | Published08/20/2026 | SeverityHigh |
CVE-2026-77645Critical Remote Code Execution (RCE) vulnerability reported in Windchill | Exploitation statusNot known exploited | FixNot confirmed | Affected productWindchill PDMLink | Published08/20/2026 | SeverityCritical |
CVE-2026-77644Critical Bypass Access Control Vulnerability Reported for Windchill Risk and Reliability (WRR) Enterprise Edition | Exploitation statusNot known exploited | FixYes | Affected productWindchill Risk and Reliability Enterprise Edition (Formerly Relex) | Published08/20/2026 | SeverityCritical |
CVE-2026-12569Remote Code Execution (RCE) vulnerability in Windchill PDMlink | Exploitation statusKEV | FixYes | Affected productWindchill PDMLink | Published06/18/2026 | SeverityCritical |
CVE-2026-4681Critical Remote Code Execution vulnerability reported in Windchill | Exploitation statusNot known exploited | FixNot confirmed | Affected productWindchill PDMLink | Published03/23/2026 | SeverityCritical |
CVE-2024-40395CVE-2024-40395 | Exploitation statusNot known exploited | FixNot confirmed | Affected productNot confirmed | Published08/27/2024 | SeverityMedium |
CVE-2024-6098PTC Kepware ThingWorx Kepware Server Allocation of Resources Without Limits or Throttling | Exploitation statusNot known exploited | FixNot confirmed | Affected productKepware ThingWorx Kepware Server | Published08/16/2024 | SeverityMedium |
CVE-2024-6071PTC Creo Elements/Direct License Server Missing Authorization | Exploitation statusNot known exploited | FixYes | Affected productCreo Elements/Direct License | Published06/27/2024 | SeverityCritical |
CVE-2024-3951Cross-site Scripting in PTC Codebeamer | Exploitation statusNot known exploited | FixYes | Affected productCodebeamer | Published05/08/2024 | SeverityHigh |
CVE-2023-29447Insufficiently Protected Credentials in PTC's Kepware KEPServerEX | Exploitation statusNot known exploited | FixYes | Affected productKepware KEPServerEX | Published01/10/2024 | SeverityMedium |
CVE-2023-29446Improper Input Validation in PTC's Kepware KEPServerEX | Exploitation statusNot known exploited | FixYes | Affected productKepware KEPServerEX | Published01/10/2024 | SeverityMedium |
CVE-2023-29445Uncontrolled Search Path Element in PTC's Kepware KEPServerEX | Exploitation statusNot known exploited | FixYes | Affected productKepware KEPServerEX | Published01/10/2024 | SeverityHigh |
CVE-2023-29444Uncontrolled Search Path Element in PTC's Kepware KEPServerEX | Exploitation statusNot known exploited | FixYes | Affected productKepware KEPServerEX | Published01/10/2024 | SeverityMedium |
CVE-2023-5909Improper Validation of Certificate with Host Mismatch in PTC KEPServerEx | Exploitation statusNot known exploited | FixYes | Affected productKEPServerEX | Published11/30/2023 | SeverityHigh |
CVE-2023-5908Heap Based Buffer Overflow in PTC KEPServerEx | Exploitation statusNot confirmed | FixYes | Affected productKEPServerEX | Published11/30/2023 | SeverityCritical |
CVE-2023-4296PTC Codebeamer Cross site scripting | Exploitation statusNot known exploited | FixYes | Affected productCodebeamer | Published08/29/2023 | SeverityHigh |
CVE-2023-3825CVE-2023-3825 | Exploitation statusNot known exploited | FixYes | Affected productKEPServerEX | Published07/31/2023 | SeverityHigh |
CVE-2023-31200PTC Vuforia Studio Cross-Site Request Forgery | Exploitation statusNot known exploited | FixYes | Affected productVuforia Studio | Published06/07/2023 | SeverityMedium |
CVE-2023-29502PTC Vuforia Studio Path Traversal | Exploitation statusNot known exploited | FixYes | Affected productVuforia Studio | Published06/07/2023 | SeverityMedium |
CVE-2023-27881PTC Vuforia Studio Unrestricted Upload of File with Dangerous Type | Exploitation statusNot known exploited | FixYes | Affected productVuforia Studio | Published06/07/2023 | SeverityHigh |
CVE-2023-29152PTC Vuforia Studio Improper Authorization | Exploitation statusNot known exploited | FixYes | Affected productVuforia Studio | Published06/07/2023 | SeverityMedium |
CVE-2023-24476PTC Vuforia Studio Improper Authorization | Exploitation statusNot known exploited | FixYes | Affected productVuforia Studio | Published06/07/2023 | SeverityLow |
CVE-2023-29168PTC Vuforia Studio Insufficiently Protected Credentials | Exploitation statusNot known exploited | FixYes | Affected productVuforia Studio | Published06/07/2023 | SeverityLow |
CVE-2022-2825CVE-2022-2825 | Exploitation statusNot known exploited | FixNot confirmed | Affected productKEPServerEX | Published03/29/2023 | SeverityCritical |
CVE-2022-2848CVE-2022-2848 | Exploitation statusNot known exploited | FixNot confirmed | Affected productKEPServerEX | Published03/29/2023 | SeverityCritical |
CVE-2023-0754CVE-2023-0754 | Exploitation statusNot known exploited | FixYes | Affected productThingWorx Edge C-SDK | Published02/23/2023 | SeverityCritical |
CVE-2023-0755CVE-2023-0755 | Exploitation statusNot known exploited | FixYes | Affected productThingWorx Edge C-SDK | Published02/23/2023 | SeverityCritical |
CVE-2022-25251PTC Axeda agent and Axeda Desktop Server Missing Authentication For Critical Function | Exploitation statusNot known exploited | FixYes | Affected productAxeda agent | Published03/16/2022 | SeverityCritical |
CVE-2022-25252PTC Axeda agent and Axeda Desktop Server Improper Check or Handling Of Exceptional Conditions | Exploitation statusNot known exploited | FixYes | Affected productAxeda agent | Published03/16/2022 | SeverityHigh |
CVE-2022-25250PTC Axeda agent and Axeda Desktop Server Missing Authentication For Critical Function | Exploitation statusNot known exploited | FixYes | Affected productAxeda agent | Published03/16/2022 | SeverityHigh |
CVE-2022-25249PTC Axeda agent and Axeda Desktop Server Path Traversal | Exploitation statusNot known exploited | FixYes | Affected productAxeda agent | Published03/16/2022 | SeverityHigh |
CVE-2022-25248PTC Axeda agent and Axeda Desktop Server Information Exposure | Exploitation statusNot known exploited | FixYes | Affected productAxeda agent | Published03/16/2022 | SeverityMedium |
CVE-2022-25246PTC Axeda agent and Axeda Desktop Server Use of Hard-Coded Credentials | Exploitation statusNot known exploited | FixYes | Affected productAxeda agent | Published03/16/2022 | SeverityCritical |
CVE-2022-25247PTC Axeda agent and Axeda Desktop Server Missing Authentication For Critical Function | Exploitation statusNot known exploited | FixYes | Affected productAxeda agent | Published03/16/2022 | SeverityCritical |
CVE-2020-27265CVE-2020-27265 | Exploitation statusNot confirmed | FixNot confirmed | Affected productPTC Kepware KEPServerEX; ThingWorx Industrial Connectivity; OPC-Aggregator; Rockwell Automation KEPServer Enterprise; GE Digital Industrial Gateway Server; Software Toolbox TOP Server | Published01/13/2021 | SeverityUnknown |
CVE-2020-27263CVE-2020-27263 | Exploitation statusNot confirmed | FixNot confirmed | Affected productPTC Kepware KEPServerEX | Published01/13/2021 | SeverityUnknown |
CVE-2020-27267CVE-2020-27267 | Exploitation statusNot confirmed | FixNot confirmed | Affected productPTC Kepware KEPServerEX | Published01/13/2021 | SeverityUnknown |
CVE-2018-20092CVE-2018-20092 | Exploitation statusNot confirmed | FixNot confirmed | Affected productNot confirmed | Published12/17/2018 | SeverityUnknown |
CVE-2018-17216CVE-2018-17216 | Exploitation statusNot confirmed | FixNot confirmed | Affected productNot confirmed | Published10/01/2018 | SeverityUnknown |
CVE-2018-17218CVE-2018-17218 | Exploitation statusNot confirmed | FixNot confirmed | Affected productNot confirmed | Published10/01/2018 | SeverityUnknown |
CVE-2018-17217CVE-2018-17217 | Exploitation statusNot confirmed | FixNot confirmed | Affected productNot confirmed | Published10/01/2018 | SeverityUnknown |
CVE-2015-2061CVE-2015-2061 | Exploitation statusNot confirmed | FixNot confirmed | Affected productNot confirmed | Published03/09/2015 | SeverityUnknown |
CVE-2014-9267CVE-2014-9267 | Exploitation statusNot confirmed | FixNot confirmed | Affected productNot confirmed | Published12/08/2014 | SeverityUnknown |
CVE-2007-4600CVE-2007-4600 | Exploitation statusNot confirmed | FixNot confirmed | Affected productNot confirmed | Published10/18/2007 | SeverityUnknown |
CyStack VulnScan continuously discovers assets, validates vulnerabilities, and helps security teams prioritize remediation across the organization.
Explore CyStack VulnScan