Vulnerabilities > 3DS

DATE CVE VULNERABILITY TITLE RISK
2024-09-02 CVE-2024-7932 Cross-site Scripting vulnerability in 3DS 3Dexperience R2024X
A stored Cross-site Scripting (XSS) vulnerability affecting 3DDashboard in 3DSwymer on Release 3DEXPERIENCE R2024x allows an attacker to execute arbitrary script code in user's browser session.
network
low complexity
3ds CWE-79
5.4
2024-09-02 CVE-2024-7938 Cross-site Scripting vulnerability in 3DS 3Dexperience R2023X/R2024X
A stored Cross-site Scripting (XSS) vulnerability affecting 3DDashboard in 3DSwymer from Release 3DEXPERIENCE R2023x through Release 3DEXPERIENCE R2024x allows an attacker to execute arbitrary script code in user's browser session.
network
low complexity
3ds CWE-79
5.4
2024-09-02 CVE-2024-7939 Cross-site Scripting vulnerability in 3DS 3Dexperience R2024X
A stored Cross-site Scripting (XSS) vulnerability affecting 3DSwym in 3DSwymer on Release 3DEXPERIENCE R2024x allows an attacker to execute arbitrary script code in user's browser session.
network
low complexity
3ds CWE-79
5.4
2024-09-02 CVE-2024-8004 Cross-site Scripting vulnerability in 3DS 3Dexperience Enovia R2022X/R2023X/R2024X
A stored Cross-site Scripting (XSS) vulnerability affecting ENOVIA Collaborative Industry Innovator from Release 3DEXPERIENCE R2022x through Release 3DEXPERIENCE R2024x allows an attacker to execute arbitrary script code in user's browser session.
network
low complexity
3ds CWE-79
5.4
2024-08-20 CVE-2024-6377 Open Redirect vulnerability in 3DS 3Dexperience R2022X/R2023X
An URL redirection to untrusted site (open redirect) vulnerability affecting 3DPassport in 3DSwymer from Release 3DEXPERIENCE R2022x through Release 3DEXPERIENCE R2024x allows an attacker to redirect users to an arbitrary website via a crafted URL.
network
low complexity
3ds CWE-601
6.1
2024-08-20 CVE-2024-6378 Cross-site Scripting vulnerability in 3DS 3Dexperience R2022X/R2023X
A reflected Cross-site Scripting (XSS) vulnerability affecting ENOVIA Collaborative Industry Innovator from Release 3DEXPERIENCE R2022x through Release 3DEXPERIENCE R2024x allows an attacker to execute arbitrary script code in user's browser session.
network
low complexity
3ds CWE-79
5.4
2024-08-20 CVE-2024-6379 Cross-site Scripting vulnerability in 3DS 3Dexperience R2022X/R2023X
A reflected Cross-site Scripting (XSS) vulnerability affecting 3DSwymer from Release 3DEXPERIENCE R2022x through Release 3DEXPERIENCE R2024x allows an attacker to execute arbitrary script code in user's browser session.
network
low complexity
3ds CWE-79
6.1
2024-02-28 CVE-2024-1847 Unspecified vulnerability in 3DS Solidworks 2023/2024
Heap-based Buffer Overflow, Memory Corruption, Out-Of-Bounds Read, Out-Of-Bounds Write, Stack-based Buffer Overflow, Type Confusion, Uninitialized Variable, Use-After-Free vulnerabilities exist in the file reading procedure in eDrawings from Release SOLIDWORKS 2023 through Release SOLIDWORKS 2024.
local
low complexity
3ds
7.8
2024-02-01 CVE-2023-6078 OS Command Injection vulnerability in 3DS Biovia Materials Studio 2021/2023
An OS Command Injection vulnerability exists in BIOVIA Materials Studio products from Release BIOVIA 2021 through Release BIOVIA 2023.
network
low complexity
3ds CWE-78
critical
9.8
2024-02-01 CVE-2024-0935 Information Exposure Through Log Files vulnerability in 3DS Delmia Apriso 2019/2022/2024
Insertion of Sensitive Information into Log File vulnerabilities are affecting DELMIA Apriso Release 2019 through Release 2024
network
low complexity
3ds CWE-532
7.5