Codemeter
Vendor:
First CVE: Sep 7, 2017 · Active for 8 years
10
Total CVEs
More Total CVEs than 88% of tracked products
2.5
Avg CVEs / Year
Higher CVE frequency than 74% of tracked products
8.0
Avg CVSS
Higher Avg CVSS than 69% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Codemeter over time
Volume of CVEsAvg CVSS Base Score
First CVE
Sep 7, 2017
8 years ago
Most Recent CVE
May 16, 2025
434 days ago
CVE Severity & Scoring
Codemeter10 CVEs
10%
60%
30%
All CVEs352,231 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local1 (10.0%)
Network9 (90.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low10 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None9 (90.0%)
Unknown0 (0.0%)
Required1 (10.0%)
Privileges Required
Low1 (10.0%)
High1 (10.0%)
None8 (80.0%)
Unknown0 (0.0%)
Top CVEs
Signals from CVEs in this product scope (10 CVEs).
10 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2021-20093CRITICAL A buffer over-read vulnerability exists in Wibu-Systems CodeMeter versions < 7.21a. An unauthenticated remote attacker can exploit this issue to disclose heap memory contents or cr | Jun 16, 2021 | 9.1 | 46 | NO | NO |
CVE-2017-13754MEDIUM Cross-site scripting (XSS) vulnerability in the "advanced settings - time server" module in Wibu-Systems CodeMeter before 6.50b allows remote attackers to inject arbitrary web scri | Sep 7, 2017 | 5.4 | 30 | NO | YES |
CVE-2021-20094HIGH A denial of service vulnerability exists in Wibu-Systems CodeMeter versions < 7.21a. An unauthenticated remote attacker can exploit this issue to crash the CodeMeter Runtime Server | Jun 16, 2021 | 7.5 | 26 | NO | NO |
CVE-2020-14509CRITICAL Multiple memory corruption vulnerabilities exist in CodeMeter (All versions prior to 7.10) where the packet parser mechanism does not verify length fields. An attacker could send s | Sep 16, 2020 | 9.8 | 26 | NO | NO |
CVE-2020-16233HIGH An attacker could send a specially crafted packet that could have CodeMeter (All versions prior to 7.10) send back packets containing data from the heap. | Sep 16, 2020 | 7.5 | 25 | NO | NO |
CVE-2020-14517CRITICAL Protocol encryption can be easily broken for CodeMeter (All versions prior to 6.90 are affected, including Version 6.90 or newer only if CodeMeter Runtime is running as server) and | Sep 16, 2020 | 9.8 | 25 | NO | NO |
CVE-2020-14513HIGH CodeMeter (All versions prior to 6.81) and the software using it may crash while processing a specifically crafted license file due to unverified length fields. | Sep 16, 2020 | 7.5 | 25 | NO | NO |
CVE-2025-47809HIGH Wibu CodeMeter before 8.30a sometimes allows privilege escalation immediately after installation (before a logoff or reboot). For exploitation, there must have been an unprivileged | May 16, 2025 | 8.2 | 24 | NO | NO |
CVE-2020-14519HIGH This vulnerability allows an attacker to use the internal WebSockets API for CodeMeter (All versions prior to 7.00 are affected, including Version 7.0 or newer with the affected We | Sep 16, 2020 | 7.5 | 24 | NO | NO |
CVE-2020-14515HIGH CodeMeter (All versions prior to 6.90 when using CmActLicense update files with CmActLicense Firm Code) has an issue in the license-file signature checking mechanism, which allows | Sep 16, 2020 | 7.5 | 20 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (10 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
1 CVE
10.0% of CVEs· 89th percentile
Social Chatter
Signals from CVEs in this product scope (10 CVEs).
Media Mentions
Signals from CVEs in this product scope (10 CVEs).
Top CNAs Publishing CVEs For Codemeter
Top CWEs
Versions
No cataloged versions.