VendorsAutodeskfusionall versions
Vulnerabilities

Autodesk Fusion

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

13CVEs
CVE-2026-10789
MCP Extension Code Injection Vulnerability in Autodesk Fusion Desktop
Published 2026-06-22 · Analyzed
9.6EPSS 0.007
CVE-2025-10244
HTML Payload Stored Cross-Site Scripting (XSS) Vulnerability
Published 2025-09-23 · Analyzed
8.7EPSS 0.004
CVE-2026-0533
Stored XSS in Fusion desktop when attempting to delete a file
Published 2026-01-22 · Modified
8.1EPSS 0.007
CVE-2026-0535
Stored XSS in Electronic Library Component Description
Published 2026-01-22 · Modified
8.1EPSS 0.007
CVE-2026-0534
Stored XSS in the value of a part attribute
Published 2026-01-22 · Modified
8.1EPSS 0.005
CVE-2021-40164
A heap-based buffer overflow could occur while parsing TIFF, PICT, TGA, or RLC files. This vulnerability may be exploited to execute arbitrary code.
Published 2022-10-07 · Modified
7.8EPSS 0.009
CVE-2021-40162
A maliciously crafted TIF, PICT, TGA, or RLC files in Autodesk Image Processing component may be forced to read beyond allocated boundaries when parsing the TIFF, PICT, TGA, or RLC files. This vulnerability may be exploited to execute arbitrary code.
Published 2022-10-07 · Modified
7.8EPSS 0.009
CVE-2021-40163
A Memory Corruption vulnerability may lead to code execution through maliciously crafted DLL files through Autodesk Image Processing component.
Published 2022-10-07 · Modified
7.8EPSS 0.009
CVE-2021-40165
A maliciously crafted TIFF, PICT, TGA, or RLC file in Autodesk Image Processing component may be used to write beyond the allocated buffer while parsing TIFF, PICT, TGA, or RLC files. This vulnerability may be exploited to execute arbitrary code.
Published 2022-10-07 · Modified
7.8EPSS 0.009
CVE-2021-40166
A maliciously crafted PNG file in Autodesk Image Processing component may be used to attempt to free an object that has already been freed while parsing them. This vulnerability may be exploited by attackers to execute arbitrary code.
Published 2022-10-07 · Modified
7.8EPSS 0.009
CVE-2026-4344
Stored Cross-Site Scripting (XSS) Vulnerability in Assembly Component Name
Published 2026-04-14 · Analyzed
7.1EPSS 0.003
CVE-2026-4345
Stored Cross-Site Scripting (XSS) Vulnerability in Design Name
Published 2026-04-14 · Analyzed
7.1EPSS 0.003
CVE-2026-4369
Stored Cross-Site Scripting (XSS) Vulnerability in Assembly Variant Name
Published 2026-04-14 · Analyzed
7.1EPSS 0.003