Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

Dassault Systèmes — Vulnerabilities & Security Advisories 107

Browse all 107 CVE security advisories affecting Dassault Systèmes. AI-powered Chinese analysis, POCs, and references for each vulnerability.

Dassault Systèmes provides computer-aided design (CAD), computer-aided manufacturing (CAM), and product lifecycle management (PLM) software, primarily serving engineering and manufacturing sectors. The company’s extensive portfolio, including CATIA and SolidWorks, presents a significant attack surface, evidenced by the 95 recorded Common Vulnerabilities and Exposures (CVEs). Historically, these security flaws frequently involve remote code execution (RCE), cross-site scripting (XSS), and privilege escalation vulnerabilities, often stemming from complex integrations and legacy codebases within its enterprise applications. While no single catastrophic breach has defined the vendor’s public security history, the high volume of CVEs indicates persistent challenges in patching and securing its diverse software ecosystem. Security analysts recommend rigorous network segmentation and immediate application of vendor patches to mitigate risks associated with these known exploits, particularly given the critical nature of the industrial data handled by its platforms.

CVE ID Title CVSS Severity Published
CVE-2026-84154 Code Injection vulnerability affecting GEOVIA Geospatial Data Manager from Release 3DEXPERIENCE R2024x through Release 3DEXPERIENCE R2026x — GEOVIA Geospatial Data Manager CWE-94 9.9 Critical 2026-09-29
CVE-2026-84285 OS Command Injection vulnerability affecting Tuleap Enterprise Edition from 17.3 through 17.5 — Tuleap Enterprise Edition CWE-78 8.8 High 2026-09-21
CVE-2026-16279 Improper Authorization vulnerability affecting 3DPassport in 3DSwymer from Release 3DEXPERIENCE R2023x through Release 3DEXPERIENCE R2026x — 3DSwymer CWE-285 9.3 Critical 2026-08-27
CVE-2026-19851 Use of Default Password vulnerability affecting Tuleap Enterprise Edition from 17.0 through 17.5 — Tuleap Enterprise Edition CWE-1393 7.7 High 2026-08-25
CVE-2026-17061 Deserialization of Untrusted Data Vulnerability in SIMULIA Execution Engine from Release 2023 through Release 2026 — SIMULIA Execution Engine CWE-502 10.0 Critical 2026-08-11
CVE-2026-11756 Deserialization of Untrusted Data vulnerability affecting Station Launcher App in 3DEXPERIENCE platform from Release 3DEXPERIENCE R2023x through Release 3DEXPERIENCE R2026x — Station Launcher App in 3DEXPERIENCE platform CWE-502 10.0 Critical 2026-07-28
CVE-2026-14165 Authorization Bypass Through User-Controlled Key vulnerability affecting Tuleap Enterprise Edition from 17.0 through 17.5 — Tuleap Enterprise Edition CWE-639 7.5 High 2026-07-13
CVE-2026-9695 Improper Authentication vulnerability affecting DELMIA Apriso from Release 2020 through Release 2026 — DELMIA Apriso CWE-287 9.8 Critical 2026-07-08
CVE-2026-5120 Race Condition vulnerability affecting BIOVIA Workbook from Release 2021 through Release 2026 — BIOVIA Workbook CWE-362 8.1 High 2026-07-01
CVE-2026-10094 Path Traversal vulnerability affecting SOLIDWORKS Visualize from SOLIDWORKS Desktop Release 2024 through SOLIDWORKS Desktop Release 2026 — SOLIDWORKS Visualize CWE-22 9.8 Critical 2026-06-17
CVE-2026-9024 Stored Cross-site Scripting (XSS) vulnerability affecting Process Experience Studio in DELMIA Service Process Engineer from Release 3DEXPERIENCE R2024x through Release 3DEXPERIENCE R2026x — DELMIA Service Process Engineer CWE-79 8.7 High 2026-06-01
CVE-2026-7858 Deserialization of Untrusted Data vulnerability affecting Teamwork Cloud from No Magic Release 2022x through No Magic Release 2026x and Magic Collaboration Studio from CATIA Magic Release 2022x through CATIA Magic Release 2026x — Teamwork Cloud - Standard Edition CWE-502 9.8 Critical 2026-06-01
CVE-2025-10559 Path Traversal vulnerability affecting Factory Resource Management in DELMIA Factory Resource Manager from Release 3DEXPERIENCE R2023x through Release 3DEXPERIENCE R2025x — DELMIA Factory Resource Manager CWE-22 7.1 High 2026-03-31
CVE-2025-10553 Stored Cross-site Scripting (XSS) vulnerability affecting Factory Resource Management in DELMIA Factory Resource Manager from Release 3DEXPERIENCE R2023x through Release 3DEXPERIENCE R2025x — DELMIA Factory Resource Manager CWE-79 8.7 High 2026-03-31
CVE-2025-10551 Stored Cross-site Scripting (XSS) vulnerability affecting Document Management in ENOVIA Collaborative Industry Innovator from Release 3DEXPERIENCE R2023x through Release 3DEXPERIENCE R2025x — ENOVIA Collaborative Industry Innovator CWE-79 8.7 High 2026-03-31
CVE-2026-3476 Code Injection vulnerability affecting SOLIDWORKS Desktop from Release 2025 through Release 2026 — SOLIDWORKS Desktop CWE-94 7.8 High 2026-03-16
CVE-2026-2101 Reflected Cross-site Scripting (XSS) vulnerability affecting ENOVIAvpm Web Access from ENOVIAvpm Version 1 Release 16 through ENOVIAvpm Version 1 Release 19 — ENOVIAvpm Web Access CWE-79 8.7 High 2026-02-16
CVE-2026-1335 Out-Of-Bounds Write vulnerability affecting the EPRT file reading procedure in SOLIDWORKS eDrawings from Release SOLIDWORKS Desktop 2025 through Release SOLIDWORKS Desktop 2026 — SOLIDWORKS eDrawings CWE-787 7.8 High 2026-02-16
CVE-2026-1334 Out-Of-Bounds Read vulnerability affecting the EPRT file reading procedure in SOLIDWORKS eDrawings from Release SOLIDWORKS Desktop 2025 through Release SOLIDWORKS Desktop 2026 — SOLIDWORKS eDrawings CWE-125 7.8 High 2026-02-16
CVE-2026-1333 Use of Uninitialized Variable vulnerability affecting the EPRT file reading procedure in SOLIDWORKS eDrawings from Release SOLIDWORKS Desktop 2025 through Release SOLIDWORKS Desktop 2026 — SOLIDWORKS eDrawings CWE-457 7.8 High 2026-02-16
CVE-2026-1284 Out-Of-Bounds Write vulnerability affecting the EPRT file reading procedure in SOLIDWORKS eDrawings from Release SOLIDWORKS Desktop 2025 through Release SOLIDWORKS Desktop 2026 — SOLIDWORKS eDrawings CWE-787 7.8 High 2026-01-26
CVE-2026-1283 Heap-based Buffer Overflow vulnerability affecting the EPRT file reading procedure in SOLIDWORKS eDrawings from Release SOLIDWORKS Desktop 2025 through Release SOLIDWORKS Desktop 2026 — SOLIDWORKS eDrawings CWE-122 7.8 High 2026-01-26
CVE-2025-12956 Reflected Cross-site Scripting (XSS) vulnerability affecting ENOVIA Collaborative Industry Innovator from Release 3DEXPERIENCE R2022x through Release 3DEXPERIENCE R2025x — ENOVIA Collaborative Industry Innovator CWE-79 8.7 High 2025-12-08
CVE-2025-10555 Stored Cross-site Scripting (XSS) vulnerability affecting Service Items Management in DELMIA Service Process Engineer on Release 3DEXPERIENCE R2025x — DELMIA Service Process Engineer CWE-79 8.7 High 2025-11-24
CVE-2025-10554 Stored Cross-site Scripting (XSS) vulnerability affecting Requirements in ENOVIA Product Manager from Release 3DEXPERIENCE R2023x through Release 3DEXPERIENCE R2025x — ENOVIA Product Manager CWE-79 8.7 High 2025-11-24
CVE-2025-10558 Stored Cross-site Scripting (XSS) vulnerability affecting 3DSearch in 3DSwymer on Release 3DEXPERIENCE R2025x — 3DSwymer CWE-79 8.7 High 2025-10-13
CVE-2025-10557 Stored Cross-site Scripting (XSS) vulnerability affecting Issue Management in ENOVIA Collaborative Industry Innovator from Release 3DEXPERIENCE R2022x through Release 3DEXPERIENCE R2025x — ENOVIA Collaborative Industry Innovator CWE-79 8.7 High 2025-10-13
CVE-2025-10556 Stored Cross-site Scripting (XSS) vulnerability affecting Specification Management in ENOVIA Specification Manager from Release 3DEXPERIENCE R2023x through Release 3DEXPERIENCE R2025x — ENOVIA Specification Manager CWE-79 8.7 High 2025-10-13
CVE-2025-10552 Stored Cross-site Scripting (XSS) vulnerability affecting 3DSwym in 3DSwymer on Release 3DEXPERIENCE R2025x — 3DSwymer CWE-79 8.7 High 2025-10-13
CVE-2025-9976 OS Command Injection vulnerability affecting Station Launcher App in 3DEXPERIENCE platform from Release 3DEXPERIENCE R2022x through Release 3DEXPERIENCE R2025x — Station Launcher App in 3DEXPERIENCE platform CWE-78 9.0 Critical 2025-10-13

This page lists every published CVE security advisory associated with Dassault Systèmes. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.