Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

3ds

First CVE: Mar 4, 2009Active for: 17 yearsTotal CVEs: 61
56.4
VTI Score
TOP TARGET

Dassault Systèmes (3DS) maintains a widely deployed portfolio of product-lifecycle-management, manufacturing, and design applications spanning 3DEXPERIENCE, SOLIDWORKS, ENOVIA, and DELMIA APRISO, serving critical workflows in engineering and production environments. Vulnerabilities affecting the vendor skew toward serious outcomes, with an elevated share reaching critical severity and a moderate tendency toward public exploit availability. The exposure recurs through web-tier and memory-safety weakness classes including cross-site scripting, code injection, out-of-bounds writes, use-after-free conditions, and untrusted deserialization, reflecting the complexity of large-scale CAD, collaboration, and manufacturing-operations platforms. Defenders should prioritize monitoring this vendor's security updates for internet-connected instances and supply-chain integration points. Current exploitation activity and exposure counts are shown alongside this summary.

FAUCET AI Generated
61
Total CVEs
More Total CVEs than 99% of tracked vendors
0.4
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 4% of tracked vendors
6.6
Avg CVSS Score
Higher Avg CVSS Score than 42% of tracked vendors
4.9%
In CISA KEV
Higher KEV Rate than 99% of tracked vendors

Trends Over Time

The number and severity of CVEs published that impact products developed by 3ds over time

Volume of CVEsAvg CVSS Base Score
First CVE
Mar 4, 2009
17 years ago
Most Recent CVE
Mar 31, 2026
115 days ago

Products(16 total)

Top CVEs

Signals from CVEs in this vendor scope (61 CVEs).

61 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2025-5086CRITICAL
A deserialization of untrusted data vulnerability affecting DELMIA Apriso from Release 2020 through Release 2025 could lead to a remote code execution.
Jun 2, 20259.097YESYES
CVE-2025-6205CRITICAL
A missing authorization vulnerability affecting DELMIA Apriso from Release 2020 through Release 2025 could allow an attacker to gain privileged access to the application.
Aug 4, 20259.196YESYES
CVE-2025-6204HIGH
An Improper Control of Generation of Code (Code Injection) vulnerability affecting DELMIA Apriso from Release 2020 through Release 2025 could allow an attacker to execute arbitrary
Aug 4, 20258.096YESYES
CVE-2014-2072CRITICAL
Dassault Systemes Catia V5-6R2013: Stack Buffer Overflow due to inadequate boundary checks
Jan 8, 20209.837NOYES
CVE-2023-6078CRITICAL
An OS Command Injection vulnerability exists in BIOVIA Materials Studio products from Release BIOVIA 2021 through Release BIOVIA 2023. Upload of a specially crafted perl script can
Feb 1, 20249.831NONO
CVE-2014-2073CRITICAL
Stack-based buffer overflow in Dassault Systemes CATIA V5-6R2013 allows remote attackers to execute arbitrary code via a crafted packet, related to "CATV5_Backbone_Bus."
Apr 10, 20189.831NONO
CVE-2023-1287CRITICAL
An XSL template vulnerability in ENOVIA Live Collaboration V6R2013xE allows Remote Code Execution.
Mar 9, 20239.830NONO
CVE-2025-10559CRITICAL
A Path Traversal vulnerability affecting Factory Resource Management in DELMIA Factory Resource Manager from Release 3DEXPERIENCE R2023x through Release 3DEXPERIENCE R2025x allows
Mar 31, 20269.129NONO
CVE-2026-3476HIGH
A Code Injection vulnerability affecting SOLIDWORKS Desktop from Release 2025 through Release 2026 could allow an attacker to execute arbitrary code on the user's machine while ope
Mar 16, 20267.827NONO
CVE-2026-1333HIGH
A Use of Uninitialized Variable vulnerability affecting the EPRT file reading procedure in SOLIDWORKS eDrawings from Release SOLIDWORKS Desktop 2025 through Release SOLIDWORKS Desk
Feb 16, 20267.827NONO
View all 61 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products61 CVEs
61%
26%
11%
Severity distribution among all CVEs352,294 CVEs
45%
40%
11%
LowMediumHighCritical
Attack Vector
Local8 (13.1%)
Network49 (80.3%)
Unknown4 (6.6%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low54 (88.5%)
High3 (4.9%)
Unknown4 (6.6%)
User Interaction
None14 (23.0%)
Unknown4 (6.6%)
Required43 (70.5%)
Privileges Required
Low32 (52.5%)
High1 (1.6%)
None24 (39.3%)
Unknown4 (6.6%)

Exploit Exposure

Signals from CVEs in this vendor scope (61 CVEs).

CISA KEV
3 CVEs
4.9% of CVEs· 99th percentile
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
3 CVEs
4.9% of CVEs· 96th percentile
ExploitDB
1 CVE
1.6% of CVEs· 74th percentile

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by 3ds.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by 3ds — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For 3ds's Products

View all 1 CNAs →

Top CWEs