CVEInsight.
TrendingZero-DayExploreBrowseSearchSaved
CVEInsight.

Free vulnerability intelligence for developers, security teams, and researchers. Data sourced from public databases for informational purposes only.

Explore

HomeTrendingZero-Day WatchAttack TypesBrowse CVEsSearch

Legal

Privacy PolicyTerms of ServiceData Disclaimer

© 2026CVEInsight. For informational use only — not a substitute for professional security advice.

CVE data sourced from NVD / NIST & public disclosures.

codesys

control_runtime_system_toolkit

52 known vulnerabilities · sorted by CVSS score

CVE-2020-10245
CRITICAL9.8

CODESYS V3 web server before 3.5.15.40, as used in CODESYS Control runtime systems, has a buffer overflow.

codesys / control_for_beaglebone+14
Network
Published Mar 26, 2020
Page 1 of 3
CVE-2019-18858
CRITICAL9.8

CODESYS 3 web server before 3.5.15.20, as distributed with CODESYS Control runtime systems, has a Buffer Overflow.

codesys / control_for_beaglebone+13
Network
Published Nov 20, 2019
CVE-2021-33485
CRITICAL9.8

CODESYS Control Runtime system before 3.5.17.10 has a Heap-based Buffer Overflow.

codesys / control+15
Network
Published Aug 3, 2021
CVE-2019-13548
CRITICAL9.8

CODESYS V3 web server, all versions prior to 3.5.14.10, allows an attacker to send specially crafted http or https requests which could cause a stack overflow and create a denial-of-service condition or allow remote code execution.

codesys / control_for_beaglebone+15
Network
Published Sep 13, 2019
CVE-2022-4046
HIGH8.8

In CODESYS Control in multiple versions a improper restriction of operations within the bounds of a memory buffer allow an remote attacker with user privileges to gain full access of the device.

codesys / control_for_beaglebone_sl+13
Network
Published Aug 3, 2023
CVE-2022-47388
HIGH8.8

An authenticated, remote attacker may use a stack based out-of-bounds write vulnerability in the CmpTraceMgr Component of multiple CODESYS products in multiple versions to write data into the stack which can lead to a denial-of-service condition, memory overwriting, or remote code execution.

codesys / control_for_beaglebone_sl+16
Network
Published May 15, 2023
CVE-2022-47383
HIGH8.8

An authenticated, remote attacker may use a stack based out-of-bounds write vulnerability in the CmpTraceMgr Component of multiple CODESYS products in multiple versions to write data into the stack which can lead to a denial-of-service condition, memory overwriting, or remote code execution.

codesys / control_for_beaglebone_sl+16
Network
Published May 15, 2023
CVE-2022-47381
HIGH8.8

An authenticated remote attacker may use a stack based out-of-bounds write vulnerability in multiple CODESYS products in multiple versions to write data into the stack which can lead to a denial-of-service condition, memory overwriting, or remote code execution.

codesys / control_for_beaglebone_sl+16
Network
Published May 15, 2023
CVE-2022-47384
HIGH8.8

An authenticated remote attacker may use a stack based out-of-bounds write vulnerability in the CmpTraceMgr Component of multiple CODESYS products in multiple versions to write data into the stack which can lead to a denial-of-service condition, memory overwriting, or remote code execution.

codesys / control_for_beaglebone_sl+16
Network
Published May 15, 2023
CVE-2022-47385
HIGH8.8

An authenticated, remote attacker may use a stack based out-of-bounds write vulnerability in the CmpAppForce Component of multiple CODESYS products in multiple versions to write data into the stack which can lead to a denial-of-service condition, memory overwriting, or remote code execution.

codesys / control_for_beaglebone_sl+16
Network
Published May 15, 2023
CVE-2022-47380
HIGH8.8

An authenticated remote attacker may use a stack based  out-of-bounds write vulnerability in multiple CODESYS products in multiple versions to write data into the stack which can lead to a denial-of-service condition, memory overwriting, or remote code execution.

codesys / control_for_beaglebone_sl+16
Network
Published May 15, 2023
CVE-2022-47389
HIGH8.8

An authenticated, remote attacker may use a stack based out-of-bounds write vulnerability in the CmpTraceMgr Component of multiple CODESYS products in multiple versions to write data into the stack which can lead to a denial-of-service condition, memory overwriting, or remote code execution.

codesys / control_for_beaglebone_sl+16
Network
Published May 15, 2023
CVE-2022-47387
HIGH8.8

An authenticated remote attacker may use a stack based out-of-bounds write vulnerability in the CmpTraceMgr Component of multiple CODESYS products in multiple versions to write data into the stack which can lead to a denial-of-service condition, memory overwriting, or remote code execution.

codesys / control_for_beaglebone_sl+16
Network
Published May 15, 2023
CVE-2022-47386
HIGH8.8

An authenticated, remote attacker may use a stack based out-of-bounds write vulnerability in the CmpTraceMgr Component of multiple CODESYS products in multiple versions to write data into the stack which can lead to a denial-of-service condition, memory overwriting, or remote code execution.

codesys / control_for_beaglebone_sl+16
Network
Published May 15, 2023
CVE-2022-47382
HIGH8.8

An authenticated remote attacker may use a stack based out-of-bounds write vulnerability in the CmpTraceMgr Component of multiple CODESYS products in multiple versions to write data into the stack which can lead to a denial-of-service condition, memory overwriting, or remote code execution.

codesys / control_for_beaglebone_sl+16
Network
Published May 15, 2023
CVE-2022-47390
HIGH8.8

An authenticated, remote attacker may use a stack based out-of-bounds write vulnerability in the CmpTraceMgr Component of multiple CODESYS products in multiple versions to write data into the stack which can lead to a denial-of-service condition, memory overwriting, or remote code execution.

codesys / control_for_beaglebone_sl+16
Network
Published May 15, 2023
CVE-2022-47379
HIGH8.8

An authenticated, remote attacker may use a out-of-bounds write vulnerability in multiple CODESYS products in multiple versions to write data into memory which can lead to a denial-of-service condition, memory overwriting, or remote code execution.

codesys / control_for_beaglebone_sl+16
Network
Published May 15, 2023
CVE-2022-22515
HIGH8.1

A remote, authenticated attacker could utilize the control program of the CODESYS Control runtime system to use the vulnerability in order to read and modify the configuration file(s) of the affected products.

codesys / control_for_beaglebone_sl+17
Network
Published Apr 7, 2022
CVE-2020-15806
HIGH7.5

CODESYS Control runtime system before 3.5.16.10 allows Uncontrolled Memory Allocation.

codesys / control_for_beaglebone+16
Network
Published Jul 22, 2020
CVE-2022-22517
HIGH7.5

An unauthenticated, remote attacker can disrupt existing communication channels between CODESYS products by guessing a valid channel ID and injecting packets. This results in the communication channel to be closed.

codesys / control_for_beaglebone_sl+20
Network
Published Apr 7, 2022