Invt develops a focused suite of industrial automation and HMI (human-machine interface) design tools, including VT Designer, HMITool, and Studio, which serve embedded and operational-technology environments. The recurring vulnerability pattern centers on memory-safety and type-handling issues—out-of-bounds writes, type confusion, and buffer boundary violations—alongside deserialization flaws, reflecting the native-code implementation and data-processing demands typical of industrial software. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Invt over time
Signals from CVEs in this vendor scope (12 CVEs).
12 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2018-18987HIGH VT-Designer Version 2.1.7.31 is vulnerable by the program populating objects with user supplied input via a file without first checking for validity, allowing attacker supplied inp | Nov 30, 2018 | 8.8 | 28 | NO | NO |
CVE-2018-18983HIGH VT-Designer Version 2.1.7.31 is vulnerable by the program reading the contents of a file (which is already in memory) into another heap-based buffer, which may cause the program to | Nov 30, 2018 | 8.8 | 27 | NO | NO |
CVE-2025-7229HIGH INVT VT-Designer PM3 File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installa | Jul 21, 2025 | 7.8 | 23 | NO | NO |
CVE-2025-7231HIGH INVT VT-Designer PM3 File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installa | Jul 21, 2025 | 7.8 | 21 | NO | NO |
CVE-2025-7228HIGH INVT VT-Designer PM3 File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installa | Jul 21, 2025 | 7.8 | 21 | NO | NO |
CVE-2025-7227HIGH INVT VT-Designer PM3 File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installa | Jul 21, 2025 | 7.8 | 21 | NO | NO |
CVE-2025-7226HIGH INVT HMITool VPM File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installation | Jul 21, 2025 | 7.8 | 21 | NO | NO |
CVE-2025-7225HIGH INVT HMITool VPM File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installation | Jul 21, 2025 | 7.8 | 21 | NO | NO |
CVE-2025-7224HIGH INVT HMITool VPM File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installation | Jul 21, 2025 | 7.8 | 21 | NO | NO |
CVE-2025-7230HIGH INVT VT-Designer PM3 File Parsing Type Confusion Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations | Jul 21, 2025 | 7.8 | 19 | NO | NO |
Signals from CVEs in this vendor scope (12 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Invt.
Media articles that mention a CVE ID that affects a product developed by Invt — matched by CVE ID, not by vendor name.