Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Ashlar

First CVE: Oct 26, 2023Active for: 3 yearsTotal CVEs: 104
46.6
VTI Score
High

Ashlar maintains a highly specialized portfolio of design and visualization software serving professional engineering and architectural workflows, with a notably concentrated product line including Cobalt, Graphite, Argon, Lithium, and Xenon. Despite this narrow product scope, the vendor's vulnerability footprint is well-represented in the landscape, reflecting the complexity inherent to graphics-intensive and geometry-processing applications. The recurring vulnerability pattern centers on memory-safety issues—out-of-bounds reads and writes, heap and stack buffer overflows, and type-confusion flaws—that are characteristic of native codebases handling unstructured geometric and design data. These weakness classes pose particular risk in environments where Ashlar tools process untrusted or adversarially crafted design files, as such flaws can lead to memory corruption and code execution within design workflows. Current severity, exploitation activity, and exposure counts are shown alongside this summary.

FAUCET AI Generated
104
Total CVEs
More Total CVEs than 99% of tracked vendors
4.3
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 97% of tracked vendors
7.9
Avg CVSS Score
Higher Avg CVSS Score than 77% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Ashlar over time

Volume of CVEsAvg CVSS Base Score
First CVE
Oct 26, 2023
2 years ago
Most Recent CVE
May 12, 2026
72 days ago

Products(6 total)

Top CVEs

Signals from CVEs in this vendor scope (104 CVEs).

104 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2025-2023HIGH
Ashlar-Vellum Cobalt LI File Parsing Integer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installa
Mar 11, 20257.831NONO
CVE-2025-2021HIGH
Ashlar-Vellum Cobalt XE File Parsing Integer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installa
Mar 11, 20257.831NONO
CVE-2025-65085CRITICAL
A Heap-based Buffer Overflow vulnerability is present in Ashlar-Vellum Cobalt, Xenon, Argon, Lithium, and Cobalt Share versions 12.6.1204.216 and prior that could allow an attacker
Nov 25, 20259.830NONO
CVE-2025-65088HIGH
An Out-of-Bounds Read vulnerability is present in Ashlar-Vellum Cobalt, Xenon, Argon, Lithium, and Cobalt Share versions 12.6.1204.216 and prior that could allow an attacker to dis
May 12, 20267.828NONO
CVE-2025-65087HIGH
An Out-of-Bounds Read vulnerability is present in Ashlar-Vellum Cobalt, Xenon, Argon, Lithium, and Cobalt Share versions 12.6.1204.216 and prior that could allow an attacker to dis
May 12, 20267.828NONO
CVE-2025-65086HIGH
An Out-of-Bounds Write vulnerability is present in Ashlar-Vellum Cobalt, Xenon, Argon, Lithium, and Cobalt Share versions 12.6.1204.216 and prior that could allow an attacker to ex
May 12, 20267.828NONO
CVE-2025-65084CRITICAL
An Out-of-Bounds Write vulnerability is present in Ashlar-Vellum Cobalt, Xenon, Argon, Lithium, and Cobalt Share versions 12.6.1204.216 and prior that could allow an attacker to di
Nov 25, 20259.827NONO
CVE-2025-8000HIGH
Ashlar-Vellum Cobalt LI File Parsing Type Confusion Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installati
Sep 17, 20257.827NONO
CVE-2025-2022HIGH
Ashlar-Vellum Cobalt VS File Parsing Type Confusion Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installati
Mar 11, 20257.827NONO
CVE-2025-2020HIGH
Ashlar-Vellum Cobalt VC6 File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected inst
Mar 11, 20257.827NONO
View all 104 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products104 CVEs
98%
Severity distribution among all CVEs352,101 CVEs
45%
40%
11%
HighCritical
Attack Vector
Local95 (91.3%)
Network9 (8.7%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low103 (99.0%)
High1 (1.0%)
Unknown0 (0.0%)
User Interaction
None2 (1.9%)
Unknown0 (0.0%)
Required102 (98.1%)
Privileges Required
Low0 (0.0%)
High0 (0.0%)
None104 (100.0%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (104 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Ashlar.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Ashlar — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Ashlar's Products

View all 2 CNAs →

Top CWEs