Dassault Systèmes (3DS) maintains a widely deployed portfolio of product-lifecycle-management, manufacturing, and design applications spanning 3DEXPERIENCE, SOLIDWORKS, ENOVIA, and DELMIA APRISO, serving critical workflows in engineering and production environments. Vulnerabilities affecting the vendor skew toward serious outcomes, with an elevated share reaching critical severity and a moderate tendency toward public exploit availability. The exposure recurs through web-tier and memory-safety weakness classes including cross-site scripting, code injection, out-of-bounds writes, use-after-free conditions, and untrusted deserialization, reflecting the complexity of large-scale CAD, collaboration, and manufacturing-operations platforms. Defenders should prioritize monitoring this vendor's security updates for internet-connected instances and supply-chain integration points. Current exploitation activity and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by 3ds over time
Signals from CVEs in this vendor scope (61 CVEs).
61 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2025-5086CRITICAL A deserialization of untrusted data vulnerability affecting DELMIA Apriso from Release 2020 through Release 2025 could lead to a remote code execution. | Jun 2, 2025 | 9.0 | 97 | YES | YES |
CVE-2025-6205CRITICAL A missing authorization vulnerability affecting DELMIA Apriso from Release 2020 through Release 2025 could allow an attacker to gain privileged access to the application. | Aug 4, 2025 | 9.1 | 96 | YES | YES |
CVE-2025-6204HIGH An Improper Control of Generation of Code (Code Injection) vulnerability affecting DELMIA Apriso from Release 2020 through Release 2025 could allow an attacker to execute arbitrary | Aug 4, 2025 | 8.0 | 96 | YES | YES |
CVE-2014-2072CRITICAL Dassault Systemes Catia V5-6R2013: Stack Buffer Overflow due to inadequate boundary checks | Jan 8, 2020 | 9.8 | 37 | NO | YES |
CVE-2023-6078CRITICAL An OS Command Injection vulnerability exists in BIOVIA Materials Studio products from Release BIOVIA 2021 through Release BIOVIA 2023. Upload of a specially crafted perl script can | Feb 1, 2024 | 9.8 | 31 | NO | NO |
CVE-2014-2073CRITICAL Stack-based buffer overflow in Dassault Systemes CATIA V5-6R2013 allows remote attackers to execute arbitrary code via a crafted packet, related to "CATV5_Backbone_Bus." | Apr 10, 2018 | 9.8 | 31 | NO | NO |
CVE-2023-1287CRITICAL
An XSL template vulnerability in
ENOVIA Live Collaboration V6R2013xE allows Remote Code Execution.
| Mar 9, 2023 | 9.8 | 30 | NO | NO |
CVE-2025-10559CRITICAL A Path Traversal vulnerability affecting Factory Resource Management in DELMIA Factory Resource Manager from Release 3DEXPERIENCE R2023x through Release 3DEXPERIENCE R2025x allows | Mar 31, 2026 | 9.1 | 29 | NO | NO |
CVE-2026-3476HIGH A Code Injection vulnerability affecting SOLIDWORKS Desktop from Release 2025 through Release 2026 could allow an attacker to execute arbitrary code on the user's machine while ope | Mar 16, 2026 | 7.8 | 27 | NO | NO |
CVE-2026-1333HIGH A Use of Uninitialized Variable vulnerability affecting the EPRT file reading procedure in SOLIDWORKS eDrawings from Release SOLIDWORKS Desktop 2025 through Release SOLIDWORKS Desk | Feb 16, 2026 | 7.8 | 27 | NO | NO |
Signals from CVEs in this vendor scope (61 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by 3ds.
Media articles that mention a CVE ID that affects a product developed by 3ds — matched by CVE ID, not by vendor name.