CVEs we hold for Codesys
Records whose assigning authority named Codesys as the affected vendor. Newest identifiers first, capped at 200.
CVE-2025-41700CODESYS Development System - Deserialization of Untrusted DataCODESYS Development System
CVE-2025-41691CODESYS Control DoS via Unauthenticated NULL Pointer DereferenceCODESYS Virtual Control SL
CVE-2025-41660CODESYS Control Boot Application Replacement Enables Code ExecutionCODESYS Virtual Control SL
CVE-2025-41659CODESYS Control PKI Exposure Enables Remote Certificate AccessCODESYS Virtual Control SL
CVE-2025-41658CODESYS Toolkit Exposes Sensitive Files via Default PermissionsCODESYS Virtual Control SL
CVE-2024-5000CODESYS: Incorrect calculation of buffer size can cause DoS on CODESYS OPC UA productsCODESYS HMI (SL)
CVE-2023-6357OS Command Injection in multiple CODESYS productsCODESYS Runtime Toolkit for Linux or QNX
CVE-2023-5751CODESYS: Development system prone to DoS through exposure of resource to wrong sphereCODESYS HMI (SL)
CVE-2023-49676CODESYS: Use after free vulnerability through corrupted project filesCODESYS Development System V2.3
CVE-2023-49675CODESYS: Out-of-bounds write through corrupted project filesCODESYS Development System V2.3
CVE-2023-37559CODESYS Improper Validation of Consistency within Input in multiple productsCODESYS Safety SIL2 Runtime Toolkit
CVE-2023-37558CODESYS Improper Validation of Consistency within Input in multiple productsCODESYS Safety SIL2 Runtime Toolkit
CVE-2023-37557CODESYS Heap-based Buffer Overflow in multiple productsCODESYS Safety SIL2 Runtime Toolkit
CVE-2023-37551CODESYS Files or Directories Accessible to External Parties in CmpAppCODESYS Safety SIL2 Runtime Toolkit
CVE-2023-37550CODESYS: Improper Input Validation in CmpApp componentCODESYS Safety SIL2 Runtime Toolkit
CVE-2023-37549CODESYS: Improper Input Validation in CmpApp componentCODESYS Safety SIL2 Runtime Toolkit
CVE-2023-37548CODESYS: Improper Input Validation in CmpApp componentCODESYS Safety SIL2 Runtime Toolkit
CVE-2023-37547CODESYS: Improper Input Validation in CmpApp componentCODESYS Safety SIL2 Runtime Toolkit
CVE-2023-37546CODESYS: Improper Input Validation in CmpApp componentCODESYS Safety SIL2 Runtime Toolkit
CVE-2023-37545CODESYS: Improper Input Validation in CmpApp componentCODESYS Safety SIL2 Runtime Toolkit
CVE-2023-3670Codesys: Vulnerability in CODESYS Development System and CODESYS ScriptingCODESYS Scripting
CVE-2023-3669CODESYS: Missing Brute-Force protection in CODESYS Development SystemCODESYS Development System
CVE-2023-3663CODESYS: Missing integrity check in CODESYS Development SystemCODESYS Development System
CVE-2023-3662CODESYS: Vulnerability in CODESYS Development System allows for execution of binariesCODESYS Development System
CVE-2022-47393CODESYS: Multiple products prone to improperly restricted memory operationsCODESYS Control for WAGO Touch Panels 600 SL
CVE-2022-47392CODESYS: Multiple products prone to Improper Input ValidationCODESYS Control for WAGO Touch Panels 600 SL
CVE-2022-47391CODESYS: Multiple products prone to Improper Input ValidationCODESYS Edge Gateway for Linux
CVE-2022-47390CODESYS: Multiple products prone to stack based out-of-bounds writeCODESYS Control for WAGO Touch Panels 600 SL
CVE-2022-47389CODESYS: Multiple products prone to stack based out-of-bounds writeCODESYS Control for WAGO Touch Panels 600 SL
CVE-2022-47388CODESYS: Multiple products prone to stack based out-of-bounds writeCODESYS Control for WAGO Touch Panels 600 SL
CVE-2022-47387CODESYS: Multiple products prone to stack based out-of-bounds writeCODESYS Control for WAGO Touch Panels 600 SL
CVE-2022-47386CODESYS: Multiple products prone to stack based out-of-bounds writeCODESYS Control for WAGO Touch Panels 600 SL
CVE-2022-47385CODESYS: Multiple products prone to stack based out-of-bounds writeCODESYS Control for WAGO Touch Panels 600 SL
CVE-2022-47384CODESYS: Multiple products prone to stack based out-of-bounds writeCODESYS Control for WAGO Touch Panels 600 SL
CVE-2022-47383CODESYS: Multiple products prone to stack based out-of-bounds writeCODESYS Control for WAGO Touch Panels 600 SL
CVE-2022-47382CODESYS: Multiple products prone to stack based out-of-bounds writeCODESYS Control for WAGO Touch Panels 600 SL
CVE-2022-47381CODESYS: Multiple products prone to stack based out-of-bounds writeCODESYS Control for WAGO Touch Panels 600 SL
CVE-2022-47380CODESYS: Multiple products prone to out-of-bounds writeCODESYS Control for WAGO Touch Panels 600 SL
CVE-2022-47379CODESYS: Multiple products prone to out-of-bounds writeCODESYS Control for WAGO Touch Panels 600 SL
CVE-2022-47378CODESYS: Multiple products prone to Improper Input ValidationCODESYS Control for WAGO Touch Panels 600 SL
CVE-2022-4224CODESYS: Exposure of Resource to Wrong Sphere in CODESYS V3CODESYS Control for WAGO Touch Panels 600 SL
CVE-2022-32142CODESYS runtime system prone to denial of service due to use of out of range pointerCODESYS PLCWinNT
CVE-2022-32141CODESYS runtime system prone to denial of service due to buffer over readCODESYS PLCWinNT
CVE-2022-32139CODESYS runtime system prone to denial of service due to out of bounds readCODESYS PLCWinNT
CVE-2022-32138CODESYS runtime system prone to denial of service due to Unexpected Sign ExtensionCODESYS PLCWinNT
CVE-2022-32136Codesys runtime systems: Access of uninitialised pointer lead to denial of service.CODESYS PLCWinNT
CVE-2022-31806Insecure default settings in CODESYS Runtime Toolkit 32 bit full and CODESYS PLCWinNTCODESYS Runtime Toolkit 32 bit full
CVE-2022-31804CODESYS Gateway server prone to denial of service attack due to excessive memory allocationCODESYS Gateway Server V2
CVE-2022-30792CODESYS: CmpChannelServer, CmpChannelServerEmbedded allow unauthenticated attackers to block all their available…CODESYS Edge Gateway for Linux
CVE-2022-30791CODESYS V3: CmpBlkDrvTcp allows unauthenticated attackers to block all its available TCP connectionsCODESYS Edge Gateway for Linux
CVE-2022-22519Special HTTP(s) Requests can cause a buffer-read causing a crash of the webserver and the runtime system.CODESYS Control for WAGO Touch Panels 600 SL
CVE-2022-22518A bug in the CODESYS V3 CmpUserMgr component fails to correctly apply a security policy.CODESYS Control Runtime System Toolkit
CVE-2022-22517Communication Components in multiple CODESYS products vulnerable to communication channel disruptionCODESYS PLCHandler
CVE-2022-22516CODESYS driver SysDrv3S allows SYSTEM users on Microsoft Windows to read and write in restricted memory space.CODESYS Development System V3
CVE-2022-22515A component of the CODESYS Control runtime system allows read and write access to configuration filesCODESYS Control for WAGO Touch Panels 600 SL
CVE-2022-22514Untrusted Pointer Dereference in multiple CODESYS products can lead to a DoS.CODESYS Edge Gateway for Linux
CVE-2022-22513Null Pointer Dereference in multiple CODESYS products can lead to a DoS.CODESYS Edge Gateway for Linux
CVE-2022-1965CODESYS runtime system prone to file deletion due to improper error handlingCODESYS PLCWinNT
CVE-2021-34596CODESYS V2 runtime: Access of Uninitialized Pointer may result in denial-of-serviceCODESYS V2
CVE-2021-34595CODESYS V2 runtime: out-of-bounds read or write access may result in denial-of-serviceCODESYS V2
CVE-2021-34593CODESYS V2 runtime: unauthenticated invalid requests may result in denial-of-serviceCODESYS V2
CVE-2021-34586CODESYS V2 web server: crafted requests could trigger a null pointer dereference (DoS)CODESYS V2
CVE-2021-34585CODESYS V2 web server: crafted requests could trigger a pointer dereference with an invalid address (DoS)CODESYS V2
CVE-2021-34584CODESYS V2 web server: crafted requests could trigger a buffer over-read (DoS)CODESYS V2
CVE-2021-34583CODESYS V2 web server: crafted requests could trigger a heap-based buffer overflow (DoS)CODESYS V2
111 records, read from the index as it stood on 20 Sep 2026. Every row opens the record it names, and every value on that record opens its own receipt.
Everything on this page is free. Public data. Withholding it protects nothing.