Vulnerabilities in Dassault Systèmes

102 results
Vexday analysis

O portfólio da Dassault Systèmes acumula 98 CVEs catalogadas, com 3 confirmadas em exploração ativa no catálogo KEV da CISA — uma taxa que está 6,8 vezes acima da média geral do catálogo, sinalizando risco operacional elevado para ambientes que utilizam essas soluções. A CVE mais crítica no momento, CVE-2025-5086, apresenta EPSS de 0,89, indicando probabilidade muito alta de exploração iminente e demandando atenção prioritária de equipes de resposta. O tipo de falha mais recorrente é CWE-79 (Cross-Site Scripting), o que sugere lacunas persistentes em validação de entrada e saída nas aplicações do vendor. Com 8 CVEs de severidade crítica e 6 surgidas nos últimos 90 dias, a superfície de ataque permanece ativa e requer monitoramento contínuo.

CVE-2026-1283HIGHHeap-based Buffer Overflow vulnerability affecting the EPRT file reading procedure in SOLIDWORKS eDrawings from Release SOLIDWORKS Desktop 2025 through Release SOLIDWORKS Desktop 2026EPSS 0.2%CVE-2026-14165HIGHAuthorization Bypass Through User-Controlled Key vulnerability affecting Tuleap Enterprise Edition from 17.0 through 17.5EPSS 0.2%CVE-2024-6379HIGHReflected Cross-site Scripting (XSS) vulnerability affecting 3DSwymer from Release 3DEXPERIENCE R2022x through Release 3DEXPERIENCE R2024xEPSS 0.2%CVE-2025-10555HIGHStored Cross-site Scripting (XSS) vulnerability affecting Service Items Management in DELMIA Service Process Engineer on Release 3DEXPERIENCE R2025xEPSS 0.2%CVE-2025-0599HIGHStored Cross-site Scripting (XSS) vulnerability affecting Document Management in ENOVIA Collaborative Industry Innovator on Release 3DEXPERIENCE R2024xEPSS 0.2%CVE-2025-0600HIGHStored Cross-site Scripting (XSS) vulnerability affecting Product Explorer in ENOVIA Collaborative Industry Innovator on Release 3DEXPERIENCE R2024xEPSS 0.2%CVE-2025-0830HIGHStored Cross-site Scripting (XSS) vulnerability affecting Meeting Management in ENOVIA Change Manager from Release 3DEXPERIENCE R2022x through Release 3DEXPERIENCE R2024xEPSS 0.2%CVE-2025-0832HIGHStored Cross-site Scripting (XSS) vulnerability affecting Project Gantt in ENOVIA Collaborative Industry Innovator from Release 3DEXPERIENCE R2022x through Release 3DEXPERIENCE R2024xEPSS 0.2%CVE-2025-0833HIGHStored Cross-site Scripting (XSS) vulnerability affecting Route Management in ENOVIA Collaborative Industry Innovator from Release 3DEXPERIENCE R2023x through Release 3DEXPERIENCE R2024xEPSS 0.2%CVE-2025-0598HIGHStored Cross-site Scripting (XSS) vulnerability affecting Relations in ENOVIA Collaborative Industry Innovator from Release 3DEXPERIENCE R2023x through Release 3DEXPERIENCE R2024xEPSS 0.2%CVE-2025-0596HIGHStored Cross-site Scripting (XSS) vulnerability affecting Bookmark Editor in ENOVIA Collaborative Industry Innovator on Release 3DEXPERIENCE R2024xEPSS 0.2%CVE-2025-0828HIGHStored Cross-site Scripting (XSS) vulnerability affecting Engineering Release in ENOVIA Product Engineering Specialist from Release 3DEXPERIENCE R2022x through Release 3DEXPERIENCE R2024xEPSS 0.2%CVE-2025-0829HIGHStored Cross-site Scripting (XSS) vulnerability affecting 3D Markup in ENOVIA Collaborative Industry Innovator from Release 3DEXPERIENCE R2022x through Release 3DEXPERIENCE R2024xEPSS 0.2%CVE-2025-0601HIGHStored Cross-site Scripting (XSS) vulnerability affecting Issue Management in ENOVIA Collaborative Industry Innovator from Release 3DEXPERIENCE R2022x through Release 3DEXPERIENCE R2024xEPSS 0.2%CVE-2025-0826HIGHStored Cross-site Scripting (XSS) vulnerability affecting 3D Navigate in ENOVIA Collaborative Industry Innovator from Release 3DEXPERIENCE R2022x through Release 3DEXPERIENCE R2024xEPSS 0.2%CVE-2024-10204HIGHHeap-based Buffer Overflow and Uninitialized Variable vulnerabilities exist in eDrawings from Release SOLIDWORKS 2024 through Release SOLIDWORKS 2025EPSS 0.2%CVE-2025-1884HIGHUse-After-Free vulnerability exists in SOLIDWORKS eDrawings on Release SOLIDWORKS Desktop 2025EPSS 0.2%CVE-2023-3589MEDIUMCross-Site Request Forgery (CSRF) vulnerability affecting Teamwork Cloud from No Magic Release 2021x through No Magic Release 2022xEPSS 0.2%CVE-2025-1883HIGHOut-Of-Bounds Write vulnerability exists in SOLIDWORKS eDrawings on Release SOLIDWORKS Desktop 2025EPSS 0.2%CVE-2026-1335HIGHOut-Of-Bounds Write vulnerability affecting the EPRT file reading procedure in SOLIDWORKS eDrawings from Release SOLIDWORKS Desktop 2025 through Release SOLIDWORKS Desktop 2026EPSS 0.2%