vciy

CVEs we hold for Aveva

Records whose assigning authority named Aveva as the affected vendor. Newest identifiers first, capped at 200.

CVE-2026-81824AVEVA Pipeline Integrity Monitor cross-site scriptingAVEVA Pipeline Integrity Monitor
CVE-2026-81823AVEVA Pipeline Integrity Monitor Missing AuthorizationAVEVA Pipeline Integrity Monitor
CVE-2026-81822AVEVA Pipeline Integrity Monitor Use of a Broken or Risky Cryptographic AlgorithmAVEVA Pipeline Integrity Monitor
CVE-2026-81821AVEVA Pipeline Integrity Monitor Use of hard-coded cryptographic keyAVEVA Pipeline Integrity Monitor
CVE-2026-5387AVEVA Pipeline Simulation Missing AuthorizationAVEVA Pipeline Simulation 2025
CVE-2026-1507Uncaught Exception vulnerability in AVEVA PI Data ArchiveAVEVA PI Data Archive PI Server
CVE-2026-1495Insertion of Sensitive Information into Log File vulnerability in AVEVA PI to CONNECT AgentAVEVA PI to CONNECT Agent
CVE-2025-9317AVEVA Edge Use of a Broken or Risky Cryptographic AlgorithmAVEVA Edge
CVE-2025-8386AVEVA Application Server IDE Basic Cross-site ScriptingAVEVA Application Server
CVE-2025-7639AVEVA Enterprise SCADA Deserialization of Untrusted DataAVEVA Measurement Advisor
CVE-2025-65118AVEVA Process Optimization Uncontrolled Search Path ElementAVEVA Process Optimization
CVE-2025-65117AVEVA Process Optimization Use of Potentially Dangerous FunctionAVEVA Process Optimization
CVE-2025-64769AVEVA Process Optimization Cleartext Transmission of Sensitive InformationAVEVA Process Optimization
CVE-2025-64729AVEVA Process Optimization Missing AuthorizationAVEVA Process Optimization
CVE-2025-64691AVEVA Process Optimization Code InjectionAVEVA Process Optimization
CVE-2025-61943AVEVA Process Optimization SQL InjectionAVEVA Process Optimization
CVE-2025-61937AVEVA Process Optimization Code InjectionAVEVA Process Optimization
CVE-2025-54460AVEVA PI Integrator Unrestricted Upload of File with Dangerous TypeAVEVA PI Integrator
CVE-2025-4418AVEVA PI Connector for CygNet Improper Validation of Integrity Check ValueAVEVA PI Connector for CygNet
CVE-2025-4417AVEVA PI Connector for CygNet Cross-site ScriptingAVEVA PI Connector for CygNet
CVE-2025-44019AVEVA PI Data Archive Uncaught ExceptionAVEVA PI Server
CVE-2025-41415AVEVA PI Integrator Insertion of Sensitive Information into Sent DataAVEVA PI Integrator
CVE-2025-36539AVEVA PI Data Archive Uncaught ExceptionAVEVA PI Server
CVE-2025-2745AVEVA PI Web API Cross-site ScriptingAVEVA PI Web API
CVE-2024-7113Allocation of Resources Without Limits or Throttling in AVEVA SuiteLink ServerAVEVA Batch Management
CVE-2024-6456SQL Injection vulnerability in AVEVA Historian ServerAVEVA Historian Web Server
CVE-2024-3468Deserialization of Untrusted Data in AVEVA PI Web APIAVEVA PI Web API
CVE-2024-3467Deserialization of Untrusted Data in AVEVA PI Asset Framework ClientAVEVA PI Asset Framework Client
CVE-2023-6132AVEVA Edge products Uncontrolled Search Path ElementAVEVA Edge
CVE-2023-34982AVEVA Operations Control Logger External Control of File Name or PathAVEVA Telemetry Server
CVE-2023-34348Improper Check or Handling of Exceptional Conditions in Aveva PI ServerAveva PI Server
CVE-2023-33873AVEVA Operations Control Logger Execution with Unnecessary PrivilegesAVEVA Telemetry Server
CVE-2023-31274Missing Release of Resource after Effective Lifetime vulnerability in Aveva PI ServerAveva PI Server
CVE-2023-1256CVE-2023-1256AVEVA Telemetry Server
CVE-2022-36970no title heldAVEVA Edge
CVE-2022-36969no title heldAVEVA Edge
CVE-2022-28688no title heldAVEVA Edge
CVE-2022-28687no title heldAVEVA Edge
CVE-2022-28686no title heldAVEVA Edge
CVE-2022-28685no title heldAVEVA Edge
CVE-2022-23854no title heldAVEVA InTouch Access Anywhere
CVE-2022-1467AVEVA InTouch Access Anywhere Exposure of Resource to Wrong SphereAVEVA Plant SCADA Access Anywhere
CVE-2022-0835AVEVA System Platform Cleartext Storage of Sensitive Information in MemoryAVEVA System Platform
CVE-2021-38410AVEVA PCS Portal Uncontrolled Search Path ElementAVEVA Platform Common Services (PCS) Portal
CVE-2021-33010AVEVA System Platform Uncaught ExceptionAVEVA System Platform
CVE-2021-33008AVEVA System Platform Missing Authentication for Critical FunctionAVEVA System Platform
CVE-2021-32999AVEVA SuiteLink Server Improper Handling of Exceptional ConditionsAVEVA MES 2014
CVE-2021-32987AVEVA SuiteLink Server Null Pointer DereferenceAVEVA MES 2014
CVE-2021-32985AVEVA System Platform Origin Validation ErrorAVEVA System Platform
CVE-2021-32981AVEVA System Platform Path TraversalAVEVA System Platform
CVE-2021-32979AVEVA SuiteLink Server Null Pointer DereferenceAVEVA MES 2014
CVE-2021-32977AVEVA System Platform Improper Verification of Cryptographic SignatureAVEVA System Platform
CVE-2021-32971AVEVA SuiteLink Server Null Pointer DereferenceAVEVA MES 2014
CVE-2021-32963AVEVA SuiteLink Server Null Pointer DereferenceAVEVA MES 2014
CVE-2021-32959AVEVA SuiteLink Server Buffer OverflowAVEVA MES 2014
CVE-2021-32942no title heldAVEVA InTouch
CVE-2020-13505no title heldn/a Aveva
CVE-2020-13504no title heldn/a Aveva
CVE-2020-13501no title heldn/a Aveva
CVE-2020-13500no title heldn/a Aveva
CVE-2020-13499no title heldn/a Aveva
CVE-2019-6525no title heldAVEVA Wonderware System Platform
CVE-2019-13537no title heldAVEVA Vijeo Citect and Citect SCADA
CVE-2019-10981no title heldAVEVA Vijeo Citect and CitectSCADA
CVE-2018-10628no title heldAVEVA Software, LLC. InTouch
CVE-2018-10620no title heldAVEVA Software, LLC InTouch Machine Edition

66 records, read from the index as it stood on 20 Sep 2026. Every row opens the record it names, and every value on that record opens its own receipt.

Everything on this page is free. Public data. Withholding it protects nothing.