Agile Product Lifecycle Management (PLM) vulnerabilities: known CVEs & security history
Oracle · Actively exploited · 88 tracked CVEs · 4 actively exploited · updated September 2026 · what is a CVE? →
This is the full list of known vulnerabilities (CVEs) across all Agile Product Lifecycle Management (PLM) release lines — 88 in total, with 4 actively exploited in the wild. A CVE here doesn't mean your version is affected — check Agile Product Lifecycle Management (PLM)'s current status and the safe version to run.
Known Agile Product Lifecycle Management (PLM) CVEs
Actively-exploited and most-severe first. Showing the top 80 of 88. Open any CVE for full details.
| CVE | Severity | CVSS | EPSS | Year |
|---|---|---|---|---|
| CVE-2020-1938⚡ exploited | critical | 9.8 | 99% | 2020 |
| CVE-2019-2725⚡ exploited | critical | 9.8 | 100% | 2019 |
| CVE-2016-8735⚡ exploited | critical | 9.8 | 90% | 2017 |
| CVE-2017-12617⚡ exploited | high | 8.1 | 100% | 2017 |
| CVE-2026-71040 | critical | 9.8 | 0% | 2026 |
| CVE-2026-61167 | critical | 9.8 | 1% | 2026 |
| CVE-2026-46859 | critical | 9.8 | 1% | 2026 |
| CVE-2020-10683 | critical | 9.8 | 7% | 2020 |
| CVE-2020-9548 | critical | 9.8 | 18% | 2020 |
| CVE-2020-9546 | critical | 9.8 | 5% | 2020 |
| CVE-2026-61171 | critical | 9.1 | 0% | 2026 |
| CVE-2026-71046 | high | 8.8 | 0% | 2026 |
| CVE-2026-71045 | high | 8.8 | 0% | 2026 |
| CVE-2026-71044 | high | 8.8 | 0% | 2026 |
| CVE-2026-71039 | high | 8.8 | 0% | 2026 |
| CVE-2026-61168 | high | 8.8 | 0% | 2026 |
| CVE-2026-61166 | high | 8.8 | 0% | 2026 |
| CVE-2020-11113 | high | 8.8 | 6% | 2020 |
| CVE-2020-11112 | high | 8.8 | 4% | 2020 |
| CVE-2020-11111 | high | 8.8 | 4% | 2020 |
| CVE-2020-10969 | high | 8.8 | 4% | 2020 |
| CVE-2020-10968 | high | 8.8 | 4% | 2020 |
| CVE-2020-10673 | high | 8.8 | 8% | 2020 |
| CVE-2020-10672 | high | 8.8 | 3% | 2020 |
| CVE-2018-1258 | high | 8.8 | 2% | 2018 |
| CVE-2022-25762 | high | 8.6 | 8% | 2022 |
| CVE-2021-2351 | high | 8.3 | 2% | 2021 |
| CVE-2021-41164 | high | 8.2 | 1% | 2021 |
| CVE-2026-71042 | high | 8.1 | 0% | 2026 |
| CVE-2026-61170 | high | 8.1 | 0% | 2026 |
| CVE-2020-36183 | high | 8.1 | 5% | 2021 |
| CVE-2020-36182 | high | 8.1 | 5% | 2021 |
| CVE-2020-36180 | high | 8.1 | 5% | 2021 |
| CVE-2020-36179 | high | 8.1 | 21% | 2021 |
| CVE-2020-36189 | high | 8.1 | 5% | 2021 |
| CVE-2020-36188 | high | 8.1 | 11% | 2021 |
| CVE-2020-36187 | high | 8.1 | 5% | 2021 |
| CVE-2020-36186 | high | 8.1 | 5% | 2021 |
| CVE-2020-36185 | high | 8.1 | 5% | 2021 |
| CVE-2020-36184 | high | 8.1 | 10% | 2021 |
| CVE-2020-36181 | high | 8.1 | 5% | 2021 |
| CVE-2020-35728 | high | 8.1 | 13% | 2020 |
| CVE-2020-35491 | high | 8.1 | 9% | 2020 |
| CVE-2020-35490 | high | 8.1 | 8% | 2020 |
| CVE-2020-24750 | high | 8.1 | 7% | 2020 |
| CVE-2020-24616 | high | 8.1 | 9% | 2020 |
| CVE-2020-14195 | high | 8.1 | 5% | 2020 |
| CVE-2020-14060 | high | 8.1 | 9% | 2020 |
| CVE-2020-14062 | high | 8.1 | 8% | 2020 |
| CVE-2020-14061 | high | 8.1 | 4% | 2020 |
| CVE-2020-11619 | high | 8.1 | 4% | 2020 |
| CVE-2026-71043 | high | 7.5 | 0% | 2026 |
| CVE-2026-61172 | high | 7.5 | 0% | 2026 |
| CVE-2021-40690 | high | 7.5 | 7% | 2021 |
| CVE-2021-25122 | high | 7.5 | 18% | 2021 |
| CVE-2020-25649 | high | 7.5 | 18% | 2020 |
| CVE-2020-13935 | high | 7.5 | 87% | 2020 |
| CVE-2020-13934 | high | 7.5 | 64% | 2020 |
| CVE-2018-15756 | high | 7.5 | 10% | 2018 |
| CVE-2026-61173 | high | 7.4 | 0% | 2026 |
| CVE-2019-10086 | high | 7.3 | 30% | 2019 |
| CVE-2026-71041 | high | 7 | 0% | 2026 |
| CVE-2021-25329 | high | 7 | 9% | 2021 |
| CVE-2020-9484 | high | 7 | 57% | 2020 |
| CVE-2017-10039 | medium | 6.8 | 2% | 2017 |
| CVE-2026-61169 | medium | 6.5 | 0% | 2026 |
| CVE-2026-47009 | medium | 6.5 | 0% | 2026 |
| CVE-2022-21467 | medium | 6.5 | 1% | 2022 |
| CVE-2022-23437 | medium | 6.5 | 12% | 2022 |
| CVE-2021-41184 | medium | 6.5 | 41% | 2021 |
| CVE-2021-41183 | medium | 6.5 | 9% | 2021 |
| CVE-2021-41182 | medium | 6.5 | 39% | 2021 |
| CVE-2021-26272 | medium | 6.5 | 2% | 2021 |
| CVE-2021-26271 | medium | 6.5 | 2% | 2021 |
| CVE-2020-27193 | medium | 6.1 | 2% | 2020 |
| CVE-2020-9281 | medium | 6.1 | 4% | 2020 |
| CVE-2019-10219 | medium | 6.1 | 2% | 2019 |
| CVE-2021-45105 | medium | 5.9 | 100% | 2021 |
| CVE-2021-24122 | medium | 5.9 | 23% | 2021 |
| CVE-2018-11039 | medium | 5.9 | 3% | 2018 |
8 older / lower-severity CVEs not shown — see Agile Product Lifecycle Management (PLM)'s full record.
Is my Agile Product Lifecycle Management (PLM) version affected?
The list above spans every release. To know whether your version is affected — and the minimum safe version to upgrade to — check it directly.
Check your Agile Product Lifecycle Management (PLM) version → · Monitor Agile Product Lifecycle Management (PLM) for new CVEs →
Agile Product Lifecycle Management (PLM) vulnerabilities — frequently asked
How many known vulnerabilities does Agile Product Lifecycle Management (PLM) have?
IsItPatched tracks 88 CVEs for Agile Product Lifecycle Management (PLM), 4 of which are actively exploited (CISA KEV). 10 are critical-severity and 54 high-severity. These span every release line — what matters is whether the version you run is affected.
Does Agile Product Lifecycle Management (PLM) have any actively-exploited vulnerabilities?
Yes — 4 Agile Product Lifecycle Management (PLM) CVEs are in CISA's Known Exploited Vulnerabilities catalog, meaning they are confirmed exploited in the wild (1 linked to ransomware). Patch these as a priority.
What is the most severe Agile Product Lifecycle Management (PLM) vulnerability?
Among tracked issues, CVE-2020-1938 (CRITICAL, CVSS 9.8), which is actively exploited, ranks highest.
Is Agile Product Lifecycle Management (PLM) safe to use?
It depends on the version. The latest supported Agile Product Lifecycle Management (PLM) release clears the known issues; older versions may still be affected. Check the exact version you run for a verdict.
CVE data aggregated from NVD, CISA KEV and EPSS (FIRST.org). Related: Agile Product Lifecycle Management (PLM) security status · Agile Product Lifecycle Management (PLM) end-of-life · actively-exploited CVEs. Always verify against Oracle's advisories — see our disclaimer.