37 Total CVEs
37 AI Analyzed
3 CISA KEV
7 Critical

Profile

8.1% ended up actively exploited 3 of 37 added to CISA KEV
19% rated critical (CVSS 9.0+) 7 critical, 30 high
0 with a public exploit on record positive-only index; absence is not proof

Last 12 months

25 CVEs in the last 12 months

Products

  • eDrawings3
  • DELMIA Apriso2
  • Tuleap Enterprise Edition2
  • DELMIA Service Process Engineer1
  • Teamwork Cloud / Magic Collaboration Studio1
  • ENOVIAvpm1
  • SIMULIA Execution Engine1
  • 3DEXPERIENCE platform (Station Launcher App)1

8 products in total

Every figure counts the high and critical CVEs CVE Brief has published for this vendor, not every CVE the vendor has ever received. Exploitation means listing in the CISA Known Exploited Vulnerabilities catalog. No patch-availability figure is shown because CVE Brief does not measure it.

All Vendors
Showing 1-37 of 37 CVEs
CVE-2026-9695
Analyzed
9.8
Dassault Systèmes DELMIA Apriso

An improper authentication vulnerability in Dassault Systèmes DELMIA Apriso (2020-2026) allows remote, unauthenticated attackers to gain privileged ac...

2026-07-08
CVE-2026-9024
Analyzed
8.7
Dassault Systèmes DELMIA Service Process Engineer

A Stored Cross-site Scripting (XSS) vulnerability affecting Process Experience Studio in DELMIA Service Process Engineer from Release 3DEXPERIENCE R20...

2026-06-02
CVE-2026-7858
Analyzed
9.8
Dassault Systèmes Teamwork Cloud / Magic Collaboration Studio

A deserialization vulnerability in Teamwork Cloud and Magic Collaboration Studio allows unauthenticated remote code execution.

2026-06-02
CVE-2026-3476
Analyzed
7.8
Dassault Systèmes Multiple Products

A Code Injection vulnerability affecting SOLIDWORKS Desktop from Release 2025 through Release 2026 could allow an attacker to execute arbitrary code o...

2026-03-17
CVE-2026-2101
Analyzed
8.7
Dassault Systèmes ENOVIAvpm

A Reflected Cross-site Scripting (XSS) vulnerability affecting ENOVIAvpm Web Access from ENOVIAvpm Version 1 Release 16 through ENOVIAvpm Version 1 Re...

2026-02-17
CVE-2026-19851
Analyzed
7.7
Dassault Systèmes Tuleap Enterprise Edition

A Use of Default Password vulnerability affecting Tuleap Enterprise Edition from 17

2026-08-25
CVE-2026-17061
Analyzed
10
Dassault Systèmes SIMULIA Execution Engine

A deserialization of untrusted data vulnerability in the SIMULIA Execution Engine allows unauthenticated remote code execution.

2026-08-12
CVE-2026-14165
Analyzed
7.5
Dassault Systèmes Tuleap Enterprise Edition

An Authorization Bypass Through User-Controlled Key vulnerability affecting Tuleap Enterprise Edition from 17

2026-07-13
CVE-2026-1335
Analyzed
7.8
Dassault Systèmes eDrawings

An Out-Of-Bounds Write vulnerability affecting the EPRT file reading procedure in SOLIDWORKS eDrawings from Release SOLIDWORKS Desktop 2025 through Re...

2026-02-17
CVE-2026-1334
Analyzed
7.8
Dassault Systèmes eDrawings

An Out-Of-Bounds Read vulnerability affecting the EPRT file reading procedure in SOLIDWORKS eDrawings from Release SOLIDWORKS Desktop 2025 through Rel...

2026-02-17
CVE-2026-1333
Analyzed
7.8
Dassault Systèmes eDrawings

A Use of Uninitialized Variable vulnerability affecting the EPRT file reading procedure in SOLIDWORKS eDrawings from Release SOLIDWORKS Desktop 2025 t...

2026-02-17
CVE-2026-1284
Analyzed
7.8
Dassault Systèmes Multiple Products

An Out-Of-Bounds Write vulnerability affecting the EPRT file reading procedure in SOLIDWORKS eDrawings from Release SOLIDWORKS 2025 through Release SO...

2026-01-27
CVE-2026-1283
Analyzed
7.8
Dassault Systèmes Multiple Products

A Heap-based Buffer Overflow vulnerability affecting the EPRT file reading procedure in SOLIDWORKS eDrawings from Release SOLIDWORKS 2025 through Rele...

2026-01-27
CVE-2026-11756
Analyzed
10
Dassault Systèmes 3DEXPERIENCE platform (Station Launcher App)

A deserialization of untrusted data vulnerability in the 3DEXPERIENCE Station Launcher App allows unauthenticated remote code execution.

2026-07-28
CVE-2025-9976
Analyzed
9
Dassault Systèmes Multiple Products

An OS Command Injection vulnerability affecting Station Launcher App in 3DEXPERIENCE platform from Release 3DEXPERIENCE R2022x through Release 3DEXPER...

2025-10-13
CVE-2025-9450
Analyzed
7.8
Dassault Systèmes Multiple Products

A Use of Uninitialized Variable vulnerability affecting the JT file reading procedure in SOLIDWORKS eDrawings on Release SOLIDWORKS Desktop 2025 could...

2025-09-17
CVE-2025-9449
Analyzed
7.8
Dassault Systèmes Multiple Products

A Use After Free vulnerability affecting the PAR file reading procedure in SOLIDWORKS eDrawings on Release SOLIDWORKS Desktop 2025 could allow an atta...

2025-09-17
CVE-2025-9447
Analyzed
7.8
Dassault Systèmes Multiple Products

An Out-Of-Bounds Read vulnerability affecting the PAR file reading procedure in SOLIDWORKS eDrawings on Release SOLIDWORKS Desktop 2025 could allow an...

2025-09-17
CVE-2025-7042
Analyzed
7.8
Dassault Systèmes Multiple Products

Use After Free vulnerability exists in the IPT file reading procedure in SOLIDWORKS eDrawings on Release SOLIDWORKS Desktop 2025

2025-07-15
CVE-2025-6974
Analyzed
7.8
Dassault Systèmes Multiple Products

Use of Uninitialized Variable vulnerability exists in the JT file reading procedure in SOLIDWORKS eDrawings on Release SOLIDWORKS Desktop 2025

2025-07-15
CVE-2025-6973
Analyzed
7.8
Dassault Systèmes Multiple Products

Use After Free vulnerability exists in the JT file reading procedure in SOLIDWORKS eDrawings on Release SOLIDWORKS Desktop 2025

2025-07-15
CVE-2025-6972
Analyzed
7.8
Dassault Systèmes Multiple Products

Use After Free vulnerability exists in the CATPRODUCT file reading procedure in SOLIDWORKS eDrawings on Release SOLIDWORKS Desktop 2025

2025-07-15
CVE-2025-6971
Analyzed
7.8
Dassault Systèmes Multiple Products

Use After Free vulnerability exists in the CATPRODUCT file reading procedure in SOLIDWORKS eDrawings on Release SOLIDWORKS Desktop 2025

2025-07-15
CVE-2025-6205
KEV Analyzed
9.1
Dassault Systèmes Multiple Products

A missing authorization vulnerability affecting DELMIA Apriso from Release 2020 through Release 2025 could allow an attacker to gain privileged access...

2025-08-05
CVE-2025-6204
KEV Analyzed
8
Dassault Systèmes Multiple Products

An Improper Control of Generation of Code (Code Injection) vulnerability affecting DELMIA Apriso from Release 2020 through Release 2025 could allow an...

2025-08-05
CVE-2025-5086
KEV Analyzed
9.5
Dassault Systèmes DELMIA Apriso

Dassault Systèmes DELMIA Apriso Deserialization of Untrusted Data Vulnerability - Active in CISA KEV catalog.

2025-09-12
CVE-2025-12956
Analyzed
8.7
Dassault Systèmes Multiple Products

A reflected Cross-site Scripting (XSS) vulnerability affecting ENOVIA Collaborative Industry Innovator from Release 3DEXPERIENCE R2022x through Releas...

2025-12-09
CVE-2025-10559
Analyzed
7.1
Dassault Systèmes Multiple Products

A Path Traversal vulnerability affecting Factory Resource Management in DELMIA Factory Resource Manager from Release 3DEXPERIENCE R2023x through Relea...

2026-04-01
CVE-2025-10558
Analyzed
8.7
Dassault Systèmes Multiple Products

A stored Cross-site Scripting (XSS) vulnerability affecting 3DSearch in 3DSwymer on Release 3DEXPERIENCE R2025x allows an attacker to execute arbitrar...

2025-10-13
CVE-2025-10557
Analyzed
8.7
Dassault Systèmes Multiple Products

A stored Cross-site Scripting (XSS) vulnerability affecting Issue Management in ENOVIA Collaborative Industry Innovator from Release 3DEXPERIENCE R202...

2025-10-13
CVE-2025-10556
Analyzed
8.7
Dassault Systèmes Multiple Products

A stored Cross-site Scripting (XSS) vulnerability affecting Specification Management in ENOVIA Specification Manager from Release 3DEXPERIENCE R2023x...

2025-10-13
CVE-2025-10555
Analyzed
8.7
Dassault Systèmes Multiple Products

A stored Cross-site Scripting (XSS) vulnerability affecting Service Items Management in DELMIA Service Process Engineer on Release 3DEXPERIENCE R2025x...

2025-11-25
CVE-2025-10554
Analyzed
8.7
Dassault Systèmes Multiple Products

A stored Cross-site Scripting (XSS) vulnerability affecting Requirements in ENOVIA Product Manager from Release 3DEXPERIENCE R2023x through Release 3D...

2025-11-25
CVE-2025-10553
Analyzed
8.7
Dassault Systèmes Multiple Products

A Stored Cross-site Scripting (XSS) vulnerability affecting Factory Resource Management in DELMIA Factory Resource Manager from Release 3DEXPERIENCE R...

2026-04-01
CVE-2025-10552
Analyzed
8.7
Dassault Systèmes Multiple Products

A stored Cross-site Scripting (XSS) vulnerability affecting 3DSwym in 3DSwymer on Release 3DEXPERIENCE R2025x allows an attacker to execute arbitrary...

2025-10-13
CVE-2025-10551
Analyzed
8.7
Dassault Systèmes Multiple Products

A Stored Cross-site Scripting (XSS) vulnerability affecting Document Management in ENOVIA Collaborative Industry Innovator from Release 3DEXPERIENCE R...

2026-04-01
CVE-2025-0831
Analyzed
7.8
Dassault Systèmes Multiple Products

Out-Of-Bounds Read vulnerability exists in the JT file reading procedure in SOLIDWORKS eDrawings on Release SOLIDWORKS Desktop 2025

2025-07-15