Studio
This hub aggregates every CVE we track for Studio, a product in the ics ot iot space. Use it to gauge the current risk picture and drill into individual advisories.
29
CVEs tracked
4
Critical
6
High
0
In CISA KEV
Severity distribution
MEDIUM17HIGH6CRITICAL4LOW1
Monthly trend
0
0
0
0
0
0
0
0
0
1
0
0
0
0
0
0
1
2
0
0
0
0
0
1
2024-102026-09
Latest CVEs
The 15 most recently published vulnerabilities affecting Studio.
- CVE-2026-55650Outerbase Studio: Stored XSS in Text Widget Leads to Authentication Token Exposure4.4
- CVE-2018-25227Valentina Studio 9.0.4 Denial of Service via Host Parameter6.2
- CVE-2019-25567Valentina Studio 9.0.5 Linux Buffer Overflow via Host Field6.2
- CVE-2019-25276Studio 5000 Logix Designer 30.01.00 - 'FactoryTalk Activation Service' Unquoted Service Path7.8
- CVE-2025-34123VideoCharge Studio 2.12.3.685 SEH Buffer Overflow via .VSC File
- CVE-2023-39967Full read and controlled SSRF through URL parameter when testing a request inside wiremock-studio10.0
- CVE-2023-41327Controlled SSRF through URL in the WireMock4.6
- CVE-2023-41329Domain restrictions bypass via DNS Rebinding in WireMock and WireMock Studio3.9
- CVE-2023-38335Omnis Studio 10.22.00 has incorrect access control. It advertises a feature for making Omnis libraries "always private" - this is supposed to be an irreversible operation. However, due to implement...5.3
- CVE-2023-38334Omnis Studio 10.22.00 has incorrect access control. It advertises an irreversible feature for locking classes within Omnis libraries: it should be no longer possible to delete, view, change, copy, ...6.5
- CVE-2022-36243Directory Traversal on Shop Beat Services5.3
- CVE-2022-36250Cross Site Request Forgery on Shop Beat Services8.8
- CVE-2022-36249Shop Beat Services Vulnerable To Bypass 2FA via APIs5.4
- CVE-2022-36246Shop Beat Services Vulnerable To Insecure Permissions9.8
- CVE-2022-36244Multiple Stored Cross-Site Scripting Vulnerabilities on Shop Beat Services5.4
Product normalization is registry-driven with AI assist and human review. How it works