Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Bentley

First CVE: Sep 7, 2012Active for: 14 yearsTotal CVEs: 224
70.1
VTI Score
TOP TARGET

Bentley Systems develops a tightly focused portfolio of design, visualization, and infrastructure-modeling applications—principally MicroStation, Bentley View, and ContextCapture Viewer—that are widely deployed across engineering and construction workflows and occupy a prominent position in the landscape. The vendor's vulnerability footprint, despite a small product count, spans a large volume of disclosures and concentrates durably around memory-safety issues: out-of-bounds reads and writes, use-after-free conditions, and heap- and stack-based buffer overflows that reflect the native-code complexity and file-parsing demands of computer-aided design and geospatial processing engines. These weakness classes are characteristic of large binaries that parse untrusted CAD, modeling, and image data in complex formats, creating a consistent exposure surface across MicroStation and its variants. Defenders should treat this vendor's updates as broadly applicable to engineering environments and prioritize patching for any internet-connected or data-import-facing deployments; current severity and exploitation figures are shown alongside this summary.

FAUCET AI Generated
224
Total CVEs
More Total CVEs than 100% of tracked vendors
4.5
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 97% of tracked vendors
6.9
Avg CVSS Score
Higher Avg CVSS Score than 49% of tracked vendors
0.9%
In CISA KEV
Higher KEV Rate than 99% of tracked vendors

Trends Over Time

The number and severity of CVEs published that impact products developed by Bentley over time

Volume of CVEsAvg CVSS Base Score
First CVE
Sep 7, 2012
13 years ago
Most Recent CVE
May 7, 2024
808 days ago

Products(10 total)

Top CVEs

Signals from CVEs in this vendor scope (224 CVEs).

224 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2021-44228CRITICAL
Apache Log4j2 2.0-beta9 through 2.15.0 (excluding security releases 2.12.2, 2.12.3, and 2.3.1) JNDI features used in configuration, log messages, and parameters do not protect agai
Dec 10, 202110.099YESYES
CVE-2023-4863HIGH
Heap buffer overflow in libwebp in Google Chrome prior to 116.0.5845.187 and libwebp 1.3.2 allowed a remote attacker to perform an out of bounds memory write via a crafted HTML pag
Sep 12, 20238.896YESNO
CVE-2021-46604HIGH
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Bentley MicroStation CONNECT 10.16.0.80. User interaction is required to exploit t
Feb 18, 20227.826NONO
CVE-2022-28310HIGH
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Bentley MicroStation CONNECT 10.16.02.034. User interaction is required to exploit
Mar 29, 20237.825NONO
CVE-2022-28306HIGH
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Bentley MicroStation CONNECT 10.16.02.034. User interaction is required to exploit
Mar 29, 20237.825NONO
CVE-2022-28305HIGH
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Bentley MicroStation CONNECT 10.16.02.034. User interaction is required to exploit
Mar 29, 20237.825NONO
CVE-2022-1229HIGH
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Bentley MicroStation CONNECT 10.16.2.034. User interaction is required to exploit
Mar 28, 20237.825NONO
CVE-2022-41613HIGH
Bentley Systems MicroStation Connect versions 10.17.0.209 and prior are vulnerable to an Out-of-Bounds Read when when parsing DGN files, which may allow an attacker to crash the
Jan 6, 20237.825NONO
CVE-2022-40201HIGH
Bentley Systems MicroStation Connect versions 10.17.0.209 and prior are vulnerable to a Stack-Based Buffer Overflow when a malformed design (DGN) file is parsed. This may allow a
Jan 6, 20237.825NONO
CVE-2022-42901HIGH
Bentley MicroStation and MicroStation-based applications may be affected by out-of-bounds and stack overflow issues when opening crafted XMT files. Exploiting these issues could le
Oct 13, 20227.825NONO
View all 224 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products224 CVEs
12%
15%
73%
Severity distribution among all CVEs352,294 CVEs
45%
40%
11%
LowMediumHighCritical
Attack Vector
Local220 (98.2%)
Network3 (1.3%)
Unknown1 (0.4%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low223 (99.6%)
High0 (0.0%)
Unknown1 (0.4%)
User Interaction
None2 (0.9%)
Unknown1 (0.4%)
Required221 (98.7%)
Privileges Required
Low0 (0.0%)
High0 (0.0%)
None223 (99.6%)
Unknown1 (0.4%)

Exploit Exposure

Signals from CVEs in this vendor scope (224 CVEs).

CISA KEV
2 CVEs
0.9% of CVEs· 99th percentile
Metasploit
1 CVE
0.4% of CVEs· 97th percentile
Nuclei
1 CVE
0.4% of CVEs· 95th percentile
ExploitDB
1 CVE
0.4% of CVEs· 74th percentile

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Bentley.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Bentley — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Bentley's Products

View all 5 CNAs →

Top CWEs