CVEInsight.
TrendingZero-DayExploreBrowseSearchSaved
CVEInsight.

Free vulnerability intelligence for developers, security teams, and researchers. Data sourced from public databases for informational purposes only.

Explore

HomeTrendingZero-Day WatchAttack TypesBrowse CVEsSearch

Legal

Privacy PolicyTerms of ServiceData Disclaimer

© 2026CVEInsight. For informational use only — not a substitute for professional security advice.

CVE data sourced from NVD / NIST & public disclosures.

codesys

control_for_plcnext_sl

42 known vulnerabilities · sorted by CVSS score

CVE-2022-47385
HIGH8.8

An authenticated, remote attacker may use a stack based out-of-bounds write vulnerability in the CmpAppForce Component of multiple CODESYS products in multiple versions to write data into the stack which can lead to a denial-of-service condition, memory overwriting, or remote code execution.

codesys / control_for_beaglebone_sl+16
Network
Published May 15, 2023
Page 1 of 3
CVE-2022-47381
HIGH8.8

An authenticated remote attacker may use a stack based out-of-bounds write vulnerability in multiple CODESYS products in multiple versions to write data into the stack which can lead to a denial-of-service condition, memory overwriting, or remote code execution.

codesys / control_for_beaglebone_sl+16
Network
Published May 15, 2023
CVE-2022-47383
HIGH8.8

An authenticated, remote attacker may use a stack based out-of-bounds write vulnerability in the CmpTraceMgr Component of multiple CODESYS products in multiple versions to write data into the stack which can lead to a denial-of-service condition, memory overwriting, or remote code execution.

codesys / control_for_beaglebone_sl+16
Network
Published May 15, 2023
CVE-2022-47384
HIGH8.8

An authenticated remote attacker may use a stack based out-of-bounds write vulnerability in the CmpTraceMgr Component of multiple CODESYS products in multiple versions to write data into the stack which can lead to a denial-of-service condition, memory overwriting, or remote code execution.

codesys / control_for_beaglebone_sl+16
Network
Published May 15, 2023
CVE-2022-47387
HIGH8.8

An authenticated remote attacker may use a stack based out-of-bounds write vulnerability in the CmpTraceMgr Component of multiple CODESYS products in multiple versions to write data into the stack which can lead to a denial-of-service condition, memory overwriting, or remote code execution.

codesys / control_for_beaglebone_sl+16
Network
Published May 15, 2023
CVE-2022-4224
HIGH8.8

In multiple products of CODESYS v3 in multiple versions a remote low privileged user could utilize this vulnerability to read and modify system files and OS resources or DoS the device.

codesys / control_for_beaglebone_sl+15
Network
Published Mar 23, 2023
CVE-2022-4046
HIGH8.8

In CODESYS Control in multiple versions a improper restriction of operations within the bounds of a memory buffer allow an remote attacker with user privileges to gain full access of the device.

codesys / control_for_beaglebone_sl+13
Network
Published Aug 3, 2023
CVE-2022-47390
HIGH8.8

An authenticated, remote attacker may use a stack based out-of-bounds write vulnerability in the CmpTraceMgr Component of multiple CODESYS products in multiple versions to write data into the stack which can lead to a denial-of-service condition, memory overwriting, or remote code execution.

codesys / control_for_beaglebone_sl+16
Network
Published May 15, 2023
CVE-2022-47388
HIGH8.8

An authenticated, remote attacker may use a stack based out-of-bounds write vulnerability in the CmpTraceMgr Component of multiple CODESYS products in multiple versions to write data into the stack which can lead to a denial-of-service condition, memory overwriting, or remote code execution.

codesys / control_for_beaglebone_sl+16
Network
Published May 15, 2023
CVE-2022-47389
HIGH8.8

An authenticated, remote attacker may use a stack based out-of-bounds write vulnerability in the CmpTraceMgr Component of multiple CODESYS products in multiple versions to write data into the stack which can lead to a denial-of-service condition, memory overwriting, or remote code execution.

codesys / control_for_beaglebone_sl+16
Network
Published May 15, 2023
CVE-2023-6357
HIGH8.8

A low-privileged remote attacker could exploit the vulnerability and inject additional system commands via file system libraries which could give the attacker full control of the device.

codesys / control_for_beaglebone_sl+10
Network
Published Dec 5, 2023
CVE-2022-47386
HIGH8.8

An authenticated, remote attacker may use a stack based out-of-bounds write vulnerability in the CmpTraceMgr Component of multiple CODESYS products in multiple versions to write data into the stack which can lead to a denial-of-service condition, memory overwriting, or remote code execution.

codesys / control_for_beaglebone_sl+16
Network
Published May 15, 2023
CVE-2022-47379
HIGH8.8

An authenticated, remote attacker may use a out-of-bounds write vulnerability in multiple CODESYS products in multiple versions to write data into memory which can lead to a denial-of-service condition, memory overwriting, or remote code execution.

codesys / control_for_beaglebone_sl+16
Network
Published May 15, 2023
CVE-2022-47382
HIGH8.8

An authenticated remote attacker may use a stack based out-of-bounds write vulnerability in the CmpTraceMgr Component of multiple CODESYS products in multiple versions to write data into the stack which can lead to a denial-of-service condition, memory overwriting, or remote code execution.

codesys / control_for_beaglebone_sl+16
Network
Published May 15, 2023
CVE-2022-47380
HIGH8.8

An authenticated remote attacker may use a stack based  out-of-bounds write vulnerability in multiple CODESYS products in multiple versions to write data into the stack which can lead to a denial-of-service condition, memory overwriting, or remote code execution.

codesys / control_for_beaglebone_sl+16
Network
Published May 15, 2023
CVE-2022-22515
HIGH8.1

A remote, authenticated attacker could utilize the control program of the CODESYS Control runtime system to use the vulnerability in order to read and modify the configuration file(s) of the affected products.

codesys / control_for_beaglebone_sl+17
Network
Published Apr 7, 2022
CVE-2022-22519
HIGH7.5

A remote, unauthenticated attacker can send a specific crafted HTTP or HTTPS requests causing a buffer over-read resulting in a crash of the webserver of the CODESYS Control runtime system.

codesys / control_for_beaglebone_sl+17
Network
Published Apr 7, 2022
CVE-2022-22517
HIGH7.5

An unauthenticated, remote attacker can disrupt existing communication channels between CODESYS products by guessing a valid channel ID and injecting packets. This results in the communication channel to be closed.

codesys / control_for_beaglebone_sl+20
Network
Published Apr 7, 2022
CVE-2025-41738
HIGH7.5

An unauthenticated remote attacker may cause the visualisation server of the CODESYS Control runtime system to access a resource with a pointer of wrong type, potentially leading to a denial-of-service (DoS) condition.

codesys / control_for_beaglebone_sl+16
Network
Published Dec 1, 2025
CVE-2022-47391
HIGH7.5

In multiple CODESYS products in multiple versions an unauthorized, remote attacker may use a improper input validation vulnerability to read from invalid addresses leading to a denial of service.

codesys / control_for_beaglebone_sl+16
Network
Published May 15, 2023