← Back

Autodesk

autodesk

364 CVEs • 74 products

Products (74)

Click to collapse
Toggle
Autocad
autocad
Autocad Mep
autocad_mep
Advance Steel
advance_steel
Civil 3d
civil_3d
Autocad Lt
autocad_lt
Navisworks
navisworks
Design Review
design_review
Revit
revit
3ds Max
3ds_max
Dwg Trueview
dwg_trueview
Inventor
inventor
Fusion
fusion
Fbx Review
fbx_review
Infraworks
infraworks
Autocad P&id
autocad_p&id
Vred
vred
Maya Usd
maya_usd
3ds Max Usd
3ds_max_usd
Installer
installer
Maya
maya
Alias
alias
Dwf Viewer
dwf_viewer
Vault
vault
Civil Design
civil_design
Land Desktop
land_desktop
Map 3d
map_3d
Raster Design
raster_design
Survey
survey
Utility Design
utility_design
Viz
viz
Backburner
backburner
Autodesk Maya
autodesk_maya
Autocad Ecscad
autocad_ecscad
Sketchbook
sketchbook
Dynamo Bim
dynamo_bim
Fusion 360
fusion_360
Revit Lt
revit_lt

CVEs (364)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Autodesk
1Fusion
Jun 24, 2026
Jun 22, 2026
N/A· v4
9.6 CRITICAL· v3
N/A· v2
A maliciously crafted webpage, when visited by a user with Autodesk Fusion Desktop running and the MCP extension enabled, can trigger a vulnerability in the MCP extension that could allow arbitrary code execution. A succ...Show more
A maliciously crafted webpage, when visited by a user with Autodesk Fusion Desktop running and the MCP extension enabled, can trigger a vulnerability in the MCP extension that could allow arbitrary code execution. A successful exploit may allow code to execute with the privileges of the current user.Show less
1Autodesk
1Revit
Jun 29, 2026
Jun 17, 2026
N/A· v4
5.5 MEDIUM· v3
N/A· v2
A maliciously crafted RFA file, when converted to FormIt via “Convert RFA to FormIt” in Autodesk Revit, can force a NULL Pointer Dereference vulnerability. Successful exploitation may cause the application to crash, lead...Show more
A maliciously crafted RFA file, when converted to FormIt via “Convert RFA to FormIt” in Autodesk Revit, can force a NULL Pointer Dereference vulnerability. Successful exploitation may cause the application to crash, leading to a denial-of-service condition.Show less
1Autodesk
13ds Max
Jul 24, 2026
May 26, 2026
N/A· v4
7.8 HIGH· v3
N/A· v2
A maliciously crafted WRL file, when parsed through Autodesk 3ds Max, can force a Memory Corruption vulnerability. A malicious actor can leverage this vulnerability to execute arbitrary code in the context of the current...Show more
A maliciously crafted WRL file, when parsed through Autodesk 3ds Max, can force a Memory Corruption vulnerability. A malicious actor can leverage this vulnerability to execute arbitrary code in the context of the current process.Show less
1Autodesk
13ds Max
Jul 24, 2026
May 26, 2026
N/A· v4
5.5 MEDIUM· v3
N/A· v2
A maliciously crafted WRL file, when parsed through Autodesk 3ds Max, can cause a Stack Exhaustion vulnerability, leading to a denial-of-service condition.
1Autodesk
13ds Max
Jul 24, 2026
May 26, 2026
N/A· v4
7.8 HIGH· v3
N/A· v2
A maliciously crafted WRL file, when parsed through Autodesk 3ds Max, can force a Memory Corruption vulnerability. A malicious actor can leverage this vulnerability to execute arbitrary code in the context of the current...Show more
A maliciously crafted WRL file, when parsed through Autodesk 3ds Max, can force a Memory Corruption vulnerability. A malicious actor can leverage this vulnerability to execute arbitrary code in the context of the current process.Show less
1Autodesk
13ds Max
Jul 24, 2026
May 26, 2026
N/A· v4
7.8 HIGH· v3
N/A· v2
A maliciously crafted TIF file, when parsed through Autodesk 3ds Max, can force an Out-of-Bounds Write vulnerability. A malicious actor may leverage this vulnerability to cause a crash, cause data corruption, or execute...Show more
A maliciously crafted TIF file, when parsed through Autodesk 3ds Max, can force an Out-of-Bounds Write vulnerability. A malicious actor may leverage this vulnerability to cause a crash, cause data corruption, or execute arbitrary code in the context of the current process.Show less
1Autodesk
13ds Max
Jul 24, 2026
May 26, 2026
N/A· v4
5.5 MEDIUM· v3
N/A· v2
A maliciously crafted PAR file, when parsed through Autodesk 3ds Max, can force a NULL Pointer Dereference vulnerability. Successful exploitation may cause the application to crash, leading to a denial-of-service conditi...Show more
A maliciously crafted PAR file, when parsed through Autodesk 3ds Max, can force a NULL Pointer Dereference vulnerability. Successful exploitation may cause the application to crash, leading to a denial-of-service condition.Show less
1Autodesk
1Fusion
Jun 17, 2026
Apr 14, 2026
N/A· v4
7.1 HIGH· v3
N/A· v2
A maliciously crafted HTML payload in an assembly variant name, when displayed during the delete confirmation dialog and clicked by a user, can trigger a Stored Cross-site Scripting (XSS) vulnerability in the Autodesk Fu...Show more
A maliciously crafted HTML payload in an assembly variant name, when displayed during the delete confirmation dialog and clicked by a user, can trigger a Stored Cross-site Scripting (XSS) vulnerability in the Autodesk Fusion desktop application. A malicious actor may leverage this vulnerability to read local files or execute arbitrary code in the context of the current process.Show less
1Autodesk
1Fusion
Jun 17, 2026
Apr 14, 2026
N/A· v4
7.1 HIGH· v3
N/A· v2
A maliciously crafted HTML payload, stored in a design name and exported to CSV, can trigger a Stored Cross-site Scripting (XSS) vulnerability in the Autodesk Fusion desktop application. A malicious actor may leverage th...Show more
A maliciously crafted HTML payload, stored in a design name and exported to CSV, can trigger a Stored Cross-site Scripting (XSS) vulnerability in the Autodesk Fusion desktop application. A malicious actor may leverage this vulnerability to read local files or execute arbitrary code in the context of the current process.Show less
1Autodesk
1Fusion
Jun 17, 2026
Apr 14, 2026
N/A· v4
7.1 HIGH· v3
N/A· v2
A maliciously crafted HTML payload in a component name, when displayed during the delete confirmation dialog and clicked by a user, can trigger a Stored Cross-site Scripting (XSS) vulnerability in the Autodesk Fusion des...Show more
A maliciously crafted HTML payload in a component name, when displayed during the delete confirmation dialog and clicked by a user, can trigger a Stored Cross-site Scripting (XSS) vulnerability in the Autodesk Fusion desktop application. A malicious actor may leverage this vulnerability to read local files or execute arbitrary code in the context of the current process.Show less
1Autodesk
1Shared Components
Jun 17, 2026
Feb 18, 2026
N/A· v4
7.8 HIGH· v3
N/A· v2
A maliciously crafted MODEL file, when parsed through certain Autodesk products, can force an Out-of-Bounds Write vulnerability. A malicious actor may leverage this vulnerability to cause a crash, cause data corruption,...Show more
A maliciously crafted MODEL file, when parsed through certain Autodesk products, can force an Out-of-Bounds Write vulnerability. A malicious actor may leverage this vulnerability to cause a crash, cause data corruption, or execute arbitrary code in the context of the current process.Show less
1Autodesk
1Shared Components
Jun 17, 2026
Feb 18, 2026
N/A· v4
7.8 HIGH· v3
N/A· v2
A maliciously crafted CATPART file, when parsed through certain Autodesk products, can force an Out-of-Bounds Write vulnerability. A malicious actor may leverage this vulnerability to cause a crash, cause data corruption...Show more
A maliciously crafted CATPART file, when parsed through certain Autodesk products, can force an Out-of-Bounds Write vulnerability. A malicious actor may leverage this vulnerability to cause a crash, cause data corruption, or execute arbitrary code in the context of the current process.Show less
1Autodesk
13ds Max
Jun 17, 2026
Feb 4, 2026
N/A· v4
7.8 HIGH· v3
N/A· v2
A maliciously crafted GIF file, when parsed through Autodesk 3ds Max, can cause a Stack-Based Buffer Overflow vulnerability. A malicious actor can leverage this vulnerability to execute arbitrary code in the context of t...Show more
A maliciously crafted GIF file, when parsed through Autodesk 3ds Max, can cause a Stack-Based Buffer Overflow vulnerability. A malicious actor can leverage this vulnerability to execute arbitrary code in the context of the current process.Show less
1Autodesk
13ds Max
Jun 17, 2026
Feb 4, 2026
N/A· v4
7.8 HIGH· v3
N/A· v2
A maliciously crafted project directory, when opening a max file in Autodesk 3ds Max, could lead to execution of arbitrary code in the context of the current process due to an Untrusted Search Path being utilized.
1Autodesk
13ds Max
Jun 17, 2026
Feb 4, 2026
N/A· v4
8.4 HIGH· v3
N/A· v2
A maliciously crafted RGB file, when parsed through Autodesk 3ds Max, can force a Memory Corruption vulnerability. A malicious actor can leverage this vulnerability to execute arbitrary code in the context of the current...Show more
A maliciously crafted RGB file, when parsed through Autodesk 3ds Max, can force a Memory Corruption vulnerability. A malicious actor can leverage this vulnerability to execute arbitrary code in the context of the current process.Show less
1Autodesk
13ds Max
Jun 17, 2026
Feb 4, 2026
N/A· v4
8.4 HIGH· v3
N/A· v2
A maliciously crafted GIF file, when parsed through Autodesk 3ds Max, can cause a Stack-Based Buffer Overflow vulnerability. A malicious actor can leverage this vulnerability to execute arbitrary code in the context of t...Show more
A maliciously crafted GIF file, when parsed through Autodesk 3ds Max, can cause a Stack-Based Buffer Overflow vulnerability. A malicious actor can leverage this vulnerability to execute arbitrary code in the context of the current process.Show less
1Autodesk
13ds Max
Jun 17, 2026
Feb 4, 2026
N/A· v4
8.4 HIGH· v3
N/A· v2
A maliciously crafted GIF file, when parsed through Autodesk 3ds Max, can force an Out-of-Bounds Write vulnerability. A malicious actor can leverage this vulnerability to execute arbitrary code in the context of the curr...Show more
A maliciously crafted GIF file, when parsed through Autodesk 3ds Max, can force an Out-of-Bounds Write vulnerability. A malicious actor can leverage this vulnerability to execute arbitrary code in the context of the current process.Show less
1Autodesk
13ds Max
Jun 17, 2026
Feb 4, 2026
N/A· v4
8.4 HIGH· v3
N/A· v2
A maliciously crafted RGB file, when parsed through Autodesk 3ds Max, can force a Memory Corruption vulnerability. A malicious actor can leverage this vulnerability to execute arbitrary code in the context of the current...Show more
A maliciously crafted RGB file, when parsed through Autodesk 3ds Max, can force a Memory Corruption vulnerability. A malicious actor can leverage this vulnerability to execute arbitrary code in the context of the current process.Show less
1Autodesk
1Fusion
Jun 17, 2026
Jan 22, 2026
N/A· v4
8.1 HIGH· v3
N/A· v2
A maliciously crafted HTML payload, stored in a component’s description and clicked by a user, can trigger a Stored Cross-site Scripting (XSS) vulnerability in the Autodesk Fusion desktop application. A malicious actor m...Show more
A maliciously crafted HTML payload, stored in a component’s description and clicked by a user, can trigger a Stored Cross-site Scripting (XSS) vulnerability in the Autodesk Fusion desktop application. A malicious actor may leverage this vulnerability to read local files or execute arbitrary code in the context of the current process.Show less
1Autodesk
1Fusion
Jun 17, 2026
Jan 22, 2026
N/A· v4
8.1 HIGH· v3
N/A· v2
A maliciously crafted HTML payload, stored in a part’s attribute and clicked by a user, can trigger a Stored Cross-site Scripting (XSS) vulnerability in the Autodesk Fusion desktop application. A malicious actor may leve...Show more
A maliciously crafted HTML payload, stored in a part’s attribute and clicked by a user, can trigger a Stored Cross-site Scripting (XSS) vulnerability in the Autodesk Fusion desktop application. A malicious actor may leverage this vulnerability to read local files or execute arbitrary code in the context of the current process.Show less