Datakit's vulnerability footprint concentrates in CrossCADware, a specialized engineering and design software suite, where disclosures recur around memory-safety and XML-parsing weaknesses including out-of-bounds reads and writes, buffer overflows, and improper XML external entity handling. The vendor occupies a niche position within the broader landscape, reflecting the narrower deployment scope of specialized CAD and engineering tooling. Current exploitation activity, severity distribution, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Datakit over time
Signals from CVEs in this vendor scope (10 CVEs).
10 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2021-27496HIGH Datakit Software libraries CatiaV5_3dRead, CatiaV6_3dRead, Step3dRead, Ug3dReadPsr, Jt3dReadPsr modules in KeyShot Versions v10.1 and prior lack proper validation of user-supplied | May 27, 2021 | 7.8 | 25 | NO | NO |
CVE-2021-27488HIGH Datakit Software libraries CatiaV5_3dRead, CatiaV6_3dRead, Step3dRead, Ug3dReadPsr, Jt3dReadPsr modules in KeyShot Versions v10.1 and prior lack proper validation of user-supplied | May 27, 2021 | 7.8 | 25 | NO | NO |
CVE-2023-23579HIGH
Datakit CrossCadWare_x64.dll contains an out-of-bounds write past the end of an allocated buffer while parsing a specially crafted SLDPRT file. This could allow an attacke | Apr 20, 2023 | 7.8 | 24 | NO | NO |
CVE-2021-27490HIGH Datakit Software libraries CatiaV5_3dRead, CatiaV6_3dRead, Step3dRead, Ug3dReadPsr, Jt3dReadPsr modules in KeyShot Versions v10.1 and prior are vulnerable to an out-of-bounds read, | May 27, 2021 | 7.8 | 24 | NO | NO |
CVE-2021-27494HIGH Datakit Software libraries CatiaV5_3dRead, CatiaV6_3dRead, Step3dRead, Ug3dReadPsr, Jt3dReadPsr modules in KeyShot Versions v10.1 and prior lack proper validation of user-supplied | May 27, 2021 | 7.8 | 24 | NO | NO |
CVE-2023-22354MEDIUM
Datakit CrossCadWare_x64.dll contains an out-of-bounds read past the end of an allocated buffer while parsing a specially crafted SLDPRT file. This vulnerability could allow a | Apr 20, 2023 | 5.5 | 20 | NO | NO |
CVE-2021-27492MEDIUM When opening a specially crafted 3DXML file, the application containing Datakit Software libraries CatiaV5_3dRead, CatiaV6_3dRead, Step3dRead, Ug3dReadPsr, Jt3dReadPsr modules in K | May 27, 2021 | 5.5 | 20 | NO | NO |
CVE-2023-22846MEDIUM
Datakit CrossCadWare_x64.dll contains an out-of-bounds read past the end of an allocated buffer while parsing a specially crafted SLDPRT file. This vulnerability could allow | Apr 20, 2023 | 5.5 | 19 | NO | NO |
CVE-2023-22321MEDIUM
Datakit CrossCadWare_x64.dll contains an out-of-bounds read past the end of an allocated buffer while parsing a specially crafted SLDPRT file. This vulnerability could allow an | Apr 20, 2023 | 5.5 | 19 | NO | NO |
CVE-2023-22295MEDIUM Datakit CrossCadWare_x64.dll contains an out of bounds read past the end of an allocated buffer while parsing a specially crafted SLDPRT file. This vulnerability could allow an att | Apr 20, 2023 | 5.5 | 19 | NO | NO |
Signals from CVEs in this vendor scope (10 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Datakit.
Media articles that mention a CVE ID that affects a product developed by Datakit — matched by CVE ID, not by vendor name.