Vulnerability index

Browse CVEs

362 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Advance Steel MEDIUM 5.5
CVE-2026-17550

A maliciously crafted DWG or DXF file, when parsed through Autodesk AutoCAD, can force an Out-of-Bounds Read vulnerability. A malicious actor can lev…

No fix yet
Fix from $1,600 2026-07-29
Advance Steel HIGH 7.8
CVE-2026-16463

A maliciously crafted DXF file, when parsed through Autodesk AutoCAD, can force a Heap-Based Overflow vulnerability. A malicious actor can leverage t…

Fix: 2026.1.2+
Fix from $1,950 2026-07-29
Advance Steel HIGH 7.1
CVE-2026-16465

A maliciously crafted DWG or DXF file, when parsed through Autodesk AutoCAD, can force an Out-of-Bounds Read vulnerability. A malicious actor can lev…

Fix: 2026.1.2+
Fix from $1,950 2026-07-29
Fusion CRITICAL 9.6
CVE-2026-10789

A maliciously crafted webpage, when visited by a user with Autodesk Fusion Desktop running and the MCP extension enabled, can trigger a vulnerability…

Fix: 2703.1.20+
Fix from $2,300 2026-06-22
Revit MEDIUM 5.5
CVE-2026-1288

A maliciously crafted RFA file, when converted to FormIt via “Convert RFA to FormIt” in Autodesk Revit, can force a NULL Pointer Dereference vulnerab…

Fix: 2024.3.5 / 2025.4.5+
Fix from $1,600 2026-06-17
3ds Max HIGH 7.8
CVE-2026-7454

A maliciously crafted WRL file, when parsed through Autodesk 3ds Max, can force a Memory Corruption vulnerability. A malicious actor can leverage thi…

Mitigation only
Fix from $1,950 2026-05-26
3ds Max MEDIUM 5.5
CVE-2026-7453

A maliciously crafted WRL file, when parsed through Autodesk 3ds Max, can cause a Stack Exhaustion vulnerability, leading to a denial-of-service cond…

Mitigation only
Fix from $1,600 2026-05-26
3ds Max HIGH 7.8
CVE-2026-7451

A maliciously crafted TIF file, when parsed through Autodesk 3ds Max, can force an Out-of-Bounds Write vulnerability. A malicious actor may leverage …

Mitigation only
Fix from $1,950 2026-05-26
3ds Max HIGH 7.8
CVE-2026-7452

A maliciously crafted WRL file, when parsed through Autodesk 3ds Max, can force a Memory Corruption vulnerability. A malicious actor can leverage thi…

Mitigation only
Fix from $1,950 2026-05-26
3ds Max MEDIUM 5.5
CVE-2026-7450

A maliciously crafted PAR file, when parsed through Autodesk 3ds Max, can force a NULL Pointer Dereference vulnerability. Successful exploitation may…

Mitigation only
Fix from $1,600 2026-05-26
Fusion HIGH 7.1
CVE-2026-4344

A maliciously crafted HTML payload in a component name, when displayed during the delete confirmation dialog and clicked by a user, can trigger a Sto…

Fix: 2702.1.47+
Fix from $1,950 2026-04-14
Fusion HIGH 7.1
CVE-2026-4345

A maliciously crafted HTML payload, stored in a design name and exported to CSV, can trigger a Stored Cross-site Scripting (XSS) vulnerability in the…

Fix: 2702.1.47+
Fix from $1,950 2026-04-14
Fusion HIGH 7.1
CVE-2026-4369

A maliciously crafted HTML payload in an assembly variant name, when displayed during the delete confirmation dialog and clicked by a user, can trigg…

Fix: 2702.1.47+
Fix from $1,950 2026-04-14
Shared Components HIGH 7.8
CVE-2026-0874

A maliciously crafted CATPART file, when parsed through certain Autodesk products, can force an Out-of-Bounds Write vulnerability. A malicious actor …

Fix: 2026.6+
Fix from $1,950 2026-02-18
Shared Components HIGH 7.8
CVE-2026-0875

A maliciously crafted MODEL file, when parsed through certain Autodesk products, can force an Out-of-Bounds Write vulnerability. A malicious actor ma…

Fix: 2026.6+
Fix from $1,950 2026-02-18
3ds Max HIGH 7.8
CVE-2026-0536

A maliciously crafted GIF file, when parsed through Autodesk 3ds Max, can cause a Stack-Based Buffer Overflow vulnerability. A malicious actor can le…

Fix: 2026.3.2+
Fix from $1,950 2026-02-04
3ds Max HIGH 7.8
CVE-2026-0662

A maliciously crafted project directory, when opening a max file in Autodesk 3ds Max, could lead to execution of arbitrary code in the context of the…

Fix: 2026.3.2+
Fix from $1,950 2026-02-04
3ds Max HIGH 8.4
CVE-2026-0537

A maliciously crafted RGB file, when parsed through Autodesk 3ds Max, can force a Memory Corruption vulnerability. A malicious actor can leverage thi…

Fix: 2026.3.2+
Fix from $1,950 2026-02-04
3ds Max HIGH 8.4
CVE-2026-0538

A maliciously crafted GIF file, when parsed through Autodesk 3ds Max, can force an Out-of-Bounds Write vulnerability. A malicious actor can leverage …

Fix: 2026.3.2+
Fix from $1,950 2026-02-04
3ds Max HIGH 8.4
CVE-2026-0660

A maliciously crafted GIF file, when parsed through Autodesk 3ds Max, can cause a Stack-Based Buffer Overflow vulnerability. A malicious actor can le…

Fix: 2026.3.2+
Fix from $1,950 2026-02-04
3ds Max HIGH 8.4
CVE-2026-0661

A maliciously crafted RGB file, when parsed through Autodesk 3ds Max, can force a Memory Corruption vulnerability. A malicious actor can leverage thi…

Fix: 2026.3.2+
Fix from $1,950 2026-02-04
Fusion HIGH 8.1
CVE-2026-0535

A maliciously crafted HTML payload, stored in a component’s description and clicked by a user, can trigger a Stored Cross-site Scripting (XSS) vulner…

Fix: 2606.1.21+
Fix from $1,950 2026-01-22
Fusion HIGH 8.1
CVE-2026-0534

A maliciously crafted HTML payload, stored in a part’s attribute and clicked by a user, can trigger a Stored Cross-site Scripting (XSS) vulnerability…

Fix: 2606.1.21+
Fix from $1,950 2026-01-22
Fusion HIGH 8.1
CVE-2026-0533

A maliciously crafted HTML payload in a design name, when displayed during the delete confirmation dialog and clicked by a user, can trigger a Stored…

Fix: 2606.1.21+
Fix from $1,950 2026-01-22
Shared Components HIGH 7.8
CVE-2025-9453

A maliciously crafted PRT file, when parsed through certain Autodesk products, can force an Out-of-Bounds Read vulnerability. A malicious actor can l…

Fix: 2026.5+
Fix from $1,950 2025-12-16
Shared Components HIGH 7.8
CVE-2025-9454

A maliciously crafted PRT file, when parsed through certain Autodesk products, can force an Out-of-Bounds Read vulnerability. A malicious actor can l…

Fix: 2026.5+
Fix from $1,950 2025-12-16
Shared Components HIGH 7.8
CVE-2025-9455

A maliciously crafted CATPRODUCT file, when parsed through certain Autodesk products, can force an Out-of-Bounds Read vulnerability. A malicious acto…

Fix: 2026.5+
Fix from $1,950 2025-12-16
Shared Components HIGH 7.8
CVE-2025-9456

A maliciously crafted SLDPRT file, when parsed through certain Autodesk products, can force a Memory corruption vulnerability. A malicious actor can …

Fix: 2026.5+
Fix from $1,950 2025-12-16
Shared Components HIGH 7.8
CVE-2025-9457

A maliciously crafted PRT file, when parsed through certain Autodesk products, can force a Memory corruption vulnerability. A malicious actor can lev…

Fix: 2026.5+
Fix from $1,950 2025-12-16
Shared Components HIGH 7.8
CVE-2025-9459

A maliciously crafted SLDPRT file, when parsed through certain Autodesk products, can force an Out-of-Bounds Read vulnerability. A malicious actor ca…

Fix: 2026.5+
Fix from $1,950 2025-12-16