Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

aveva

About This Vendor

aveva is a technology vendor producing software and infrastructure products. As a software provider, aveva's broad product portfolio across multiple domains—including operating systems, cloud infrastructure, enterprise applications, databases, networking, and security tools—creates a large attack surface. Additionally, long support cycles, widespread deployment, and continuous feature development contribute to the accumulation of discovered vulnerabilities over time. Major vendors typically report higher CVE counts not necessarily due to inferior security, but because of greater exposure to security research, responsible disclosure practices, and the sheer complexity of maintaining multiple product lines and legacy systems. Regular security assessments and patching of aveva's products are critical for organizations running their software in production environments.

Vulnerability Trends for This Vendor

SecUtils has indexed 68 known vulnerabilities from aveva. This includes 14 critical-severity issues and 39 high-severity issues that represent significant risk. These vulnerabilities affect 39 distinct products across aveva's portfolio, demonstrating the breadth of the vendor's product ecosystem and the importance of comprehensive patch management strategies. Disclosure dates span from 2011 through 2026, indicating decades of continuous security attention and research. Organizations deploying aveva products should maintain active vulnerability monitoring, prioritize critical patches, and implement compensating controls where patches cannot be applied immediately.

ID Date Published Last Modified Severity (CVSSv3) Severity (CVSSv2) Exploit Available
CVE-2011-3143 2011-08-16 2026-06-16 - 10.0 Likely
CVE-2011-3144 2011-08-16 2026-06-16 - 4.3 Likely
CVE-2013-6142 2014-01-15 2026-06-17 - 4.3 Likely
CVE-2014-0779 2014-03-14 2026-06-17 - 6.8 Likely
CVE-2014-5411 2014-09-18 2026-06-17 - 4.9 Unknown
CVE-2014-5412 2014-09-18 2026-06-17 - 6.4 Likely
CVE-2014-5413 2014-09-18 2026-06-17 - 6.4 Likely
CVE-2015-0996 2015-03-29 2026-06-17 - 2.1 Unknown
CVE-2015-0997 2015-03-29 2026-06-17 - 5.0 Likely
CVE-2015-0998 2015-03-29 2026-06-17 - 3.3 Unknown
CVE-2015-0999 2015-03-29 2026-06-17 - 2.1 Unknown
CVE-2017-5156 2017-04-20 2026-06-17 8.8 6.8 Likely
CVE-2017-5158 2017-04-20 2026-06-17 9.8 5.0 Likely
CVE-2017-5160 2017-04-20 2026-06-17 5.3 3.5 Unknown
CVE-2017-9962 2017-09-26 2026-06-17 7.5 5.0 Likely
CVE-2017-6021 2018-05-14 2026-06-17 7.5 5.0 Likely
CVE-2018-10620 2018-07-19 2026-06-17 9.8 7.5 Likely
CVE-2018-10628 2018-07-24 2026-06-17 9.8 7.5 Likely
CVE-2018-17914 2018-11-02 2026-06-17 9.8 10.0 Likely
CVE-2018-17916 2018-11-02 2026-06-17 9.8 10.0 Likely
CVE-2019-6543 2019-02-13 2026-06-17 9.8 10.0 Likely
CVE-2019-6545 2019-02-13 2026-06-17 7.5 5.0 Likely
CVE-2019-6525 2019-04-11 2026-06-17 8.8 4.0 Likely
CVE-2019-13537 2020-01-14 2026-06-17 7.5 5.0 Likely
CVE-2020-13499 2020-09-24 2026-06-17 9.8 7.5 Likely
CVE-2020-13500 2020-09-24 2026-06-17 9.8 7.5 Likely
CVE-2020-13501 2020-09-24 2026-06-17 9.8 7.5 Likely
CVE-2020-13504 2020-09-24 2026-06-17 9.8 7.5 Likely
CVE-2020-13505 2020-09-24 2026-06-17 9.8 7.5 Likely
CVE-2021-32942 2021-06-09 2026-06-17 6.6 2.1 Unknown
CVE-2021-32959 2021-09-23 2026-06-17 8.1 7.5 Likely
CVE-2021-32963 2021-09-23 2026-06-17 7.5 5.0 Likely
CVE-2021-32971 2021-09-23 2026-06-17 7.5 5.0 Likely
CVE-2021-32979 2021-09-23 2026-06-17 7.5 5.0 Likely
CVE-2021-32987 2021-09-23 2026-06-17 7.5 5.0 Likely
CVE-2021-32999 2021-09-23 2026-06-17 7.5 5.0 Likely
CVE-2021-32977 2022-04-04 2026-06-17 7.2 6.5 Likely
CVE-2021-32981 2022-04-04 2026-06-17 7.2 6.5 Likely
CVE-2021-32985 2022-04-04 2026-06-17 7.2 6.5 Likely
CVE-2021-33008 2022-04-04 2026-06-17 8.8 7.5 Likely
CVE-2021-33010 2022-04-04 2026-06-17 7.5 5.0 Likely
CVE-2022-0835 2022-04-11 2026-06-17 8.1 1.9 Unknown
CVE-2022-1467 2022-05-23 2026-06-17 7.4 8.5 Unknown
CVE-2021-38410 2022-07-27 2026-06-17 7.3 - -
CVE-2022-23854 2022-12-23 2026-06-17 7.5 - -
CVE-2023-1256 2023-03-16 2026-06-17 9.8 - -
CVE-2022-28685 2023-03-29 2026-06-17 7.8 - -
CVE-2022-28686 2023-03-29 2026-06-17 7.8 - -
CVE-2022-28687 2023-03-29 2026-06-17 7.8 - -
CVE-2022-28688 2023-03-29 2026-06-17 7.8 - -
CVE-2022-36969 2023-03-29 2026-06-17 7.1 - -
CVE-2022-36970 2023-03-29 2026-06-17 7.8 - -
CVE-2023-33873 2023-11-15 2026-06-17 7.8 - -
CVE-2023-34982 2023-11-15 2026-06-17 5.5 - -
CVE-2021-42794 2023-12-16 2026-06-17 5.3 - -
CVE-2021-42796 2023-12-16 2026-06-17 9.8 - -
CVE-2021-42797 2023-12-16 2026-06-17 7.5 - -
CVE-2023-31274 2024-01-18 2026-06-17 5.3 - -
CVE-2023-34348 2024-01-18 2026-06-17 7.5 - -
CVE-2023-6132 2024-02-29 2026-06-17 7.3 - -
CVE-2024-3467 2024-06-12 2026-06-17 7.8 - -
CVE-2025-61937 2026-01-16 2026-06-17 10.0 - -
CVE-2025-61943 2026-01-16 2026-06-17 8.4 - -
CVE-2025-64691 2026-01-16 2026-06-17 8.8 - -
CVE-2025-64729 2026-01-16 2026-06-17 8.1 - -
CVE-2025-64769 2026-01-16 2026-06-17 7.1 - -
CVE-2025-65117 2026-01-16 2026-06-17 7.4 - -
CVE-2025-65118 2026-01-16 2026-06-17 8.8 - -

How SecUtils Normalizes Vendor Data

SecUtils aggregates National Vulnerability Database (NVD) and MITRE records for aveva by normalizing vendor identifiers across diverse data sources, mapping vendor names to their associated product lines, and collecting all known vulnerabilities under a unified vendor context. For every CVE associated with aveva's products, we extract and structure Common Platform Enumeration (CPE) data, Common Weakness Enumeration (CWE) categories, CVSS severity metrics, and reference links to enable rapid vulnerability identification and asset correlation. This record contains no exploit code, proof-of-concept instructions, or attack methodologies—only defensive intelligence necessary for patch management, risk assessment, and vendor vulnerability tracking.