TeamViewer Germany GmbH maintains a narrowly focused portfolio of remote-access and digital-employee-experience solutions—primarily its flagship TeamViewer application alongside meeting and remote-support offerings—that are widely deployed across enterprise and consumer segments. Although the vendor's disclosure volume is modest, these products sit in a privileged position on user endpoints and networks, making their security posture consequential to defenders. Vulnerabilities affecting the vendor recur through input-validation and command-injection weaknesses, alongside parser-oriented flaws such as out-of-bounds reads, reflecting the complexity of handling untrusted protocol data and user input in remote-access software. The vendor's disclosures show a moderate tendency toward public exploit availability, elevating the urgency of patching despite the focused product scope. Current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by TeamViewer Germany GmbH over time
Of all the CVEs published by TeamViewer Germany GmbH as a CNA, 68.4% affect products that TeamViewer Germany GmbH develops as a vendor.
Of all the CVEs published that affect products developed by TeamViewer Germany GmbH, 66.7% are self-published by TeamViewer Germany GmbH as a CNA.
Signals from CVEs in this vendor scope (39 CVEs).
39 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2019-18988HIGH TeamViewer Desktop through 14.7.1965 allows a bypass of remote-login access control because the same key is used for different customers' installations. It used a shared AES key fo | Feb 7, 2020 | 7.0 | 74 | YES | YES |
CVE-2020-13699HIGH TeamViewer Desktop for Windows before 15.8.3 does not properly quote its custom URI handlers. A malicious website could launch TeamViewer with arbitrary parameters, as demonstrated | Jul 29, 2020 | 8.8 | 53 | NO | YES |
CVE-2010-3128HIGH Untrusted search path vulnerability in TeamViewer 5.0.8703 and earlier allows local users, and possibly remote attackers, to execute arbitrary code and conduct DLL hijacking attack | Aug 26, 2010 | 9.3 | 41 | NO | YES |
CVE-2018-16550CRITICAL TeamViewer 10.x through 13.x allows remote attackers to bypass the brute-force authentication protection mechanism by skipping the "Cancel" step, which makes it easier to determine | Sep 5, 2018 | 9.8 | 32 | NO | NO |
CVE-2025-44016HIGH A vulnerability in TeamViewer DEX Client (former 1E client) - Content Distribution Service (NomadBranch.exe) prior version 25.11 for Windows allows malicious actors to bypass file | Dec 11, 2025 | 8.8 | 31 | NO | NO |
CVE-2021-34859HIGH This vulnerability allows remote attackers to execute arbitrary code on affected installations of TeamViewer 15.16.8.0. User interaction is required to exploit this vulnerability i | Oct 25, 2021 | 8.8 | 31 | NO | NO |
CVE-2021-34858HIGH This vulnerability allows remote attackers to execute arbitrary code on affected installations of TeamViewer. User interaction is required to exploit this vulnerability in that the | Jan 13, 2022 | 7.8 | 27 | NO | NO |
CVE-2019-18251HIGH In Omron CX-Supervisor, Versions 3.5 (12) and prior, Omron CX-Supervisor ships with Teamviewer Version 5.0.8703 QS. This version of Teamviewer is vulnerable to an obsolete function | Nov 26, 2019 | 8.8 | 27 | NO | NO |
CVE-2026-23568HIGH An out-of-bounds read vulnerability in the TeamViewer DEX Client (former 1E Client) - Content Distribution Service (NomadBranch.exe) prior version 26.1 for Windows allows an attack | Jan 29, 2026 | 8.1 | 26 | NO | NO |
CVE-2018-14333HIGH TeamViewer through 13.1.1548 stores a password in Unicode format within TeamViewer.exe process memory between "[00 88] and "[00 00 00]" delimiters, which might make it easier for a | Jul 17, 2018 | 8.1 | 26 | NO | NO |
Signals from CVEs in this vendor scope (39 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by TeamViewer Germany GmbH.
Media articles that mention a CVE ID that affects a product developed by TeamViewer Germany GmbH — matched by CVE ID, not by vendor name.