Luxion develops a focused portfolio of 3D rendering and visualization applications, centered on KeyShot and its variants for professional design and real-time rendering workflows, which occupy a notable position in the graphics-software landscape. The vendor's vulnerability exposure reflects the memory-safety demands of native rendering codebases, with recurring weaknesses in out-of-bounds writes and reads, heap and stack buffer overflows, and use-after-free conditions that are characteristic of complex image-processing and graphics libraries. While the disclosure volume is modest relative to broad platform vendors, the concentration of memory-safety issues across the rendering stack warrants attention from organizations deploying KeyShot in production pipelines and handling untrusted model or scene files. Defenders should prioritize patches for this vendor given the attack surface presented by file parsing in graphics applications; current exploitation activity and severity counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Luxion over time
Signals from CVEs in this vendor scope (30 CVEs).
30 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2021-27496HIGH Datakit Software libraries CatiaV5_3dRead, CatiaV6_3dRead, Step3dRead, Ug3dReadPsr, Jt3dReadPsr modules in KeyShot Versions v10.1 and prior lack proper validation of user-supplied | May 27, 2021 | 7.8 | 25 | NO | NO |
CVE-2021-27488HIGH Datakit Software libraries CatiaV5_3dRead, CatiaV6_3dRead, Step3dRead, Ug3dReadPsr, Jt3dReadPsr modules in KeyShot Versions v10.1 and prior lack proper validation of user-supplied | May 27, 2021 | 7.8 | 25 | NO | NO |
CVE-2021-22649HIGH Luxion KeyShot versions prior to 10.1, Luxion KeyShot Viewer versions prior to 10.1, Luxion KeyShot Network Rendering versions prior to 10.1, and Luxion KeyVR versions prior to 10. | Feb 23, 2021 | 7.8 | 25 | NO | NO |
CVE-2021-27490HIGH Datakit Software libraries CatiaV5_3dRead, CatiaV6_3dRead, Step3dRead, Ug3dReadPsr, Jt3dReadPsr modules in KeyShot Versions v10.1 and prior are vulnerable to an out-of-bounds read, | May 27, 2021 | 7.8 | 24 | NO | NO |
CVE-2021-27494HIGH Datakit Software libraries CatiaV5_3dRead, CatiaV6_3dRead, Step3dRead, Ug3dReadPsr, Jt3dReadPsr modules in KeyShot Versions v10.1 and prior lack proper validation of user-supplied | May 27, 2021 | 7.8 | 24 | NO | NO |
CVE-2021-22651HIGH When loading a specially crafted file, Luxion KeyShot versions prior to 10.1, Luxion KeyShot Viewer versions prior to 10.1, Luxion KeyShot Network Rendering versions prior to 10.1, | Feb 23, 2021 | 7.8 | 24 | NO | NO |
CVE-2021-22647HIGH Luxion KeyShot versions prior to 10.1, Luxion KeyShot Viewer versions prior to 10.1, Luxion KeyShot Network Rendering versions prior to 10.1, and Luxion KeyVR versions prior to 10. | Feb 23, 2021 | 7.8 | 24 | NO | NO |
CVE-2021-22645HIGH Luxion KeyShot versions prior to 10.1, Luxion KeyShot Viewer versions prior to 10.1, Luxion KeyShot Network Rendering versions prior to 10.1, and Luxion KeyVR versions prior to 10. | Feb 23, 2021 | 7.8 | 24 | NO | NO |
CVE-2021-22643HIGH Luxion KeyShot versions prior to 10.1, Luxion KeyShot Viewer versions prior to 10.1, Luxion KeyShot Network Rendering versions prior to 10.1, and Luxion KeyVR versions prior to 10. | Feb 23, 2021 | 7.8 | 24 | NO | NO |
CVE-2025-1047HIGH Luxion KeyShot PVS File Parsing Access of Uninitialized Pointer Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affecte | Apr 23, 2025 | 7.8 | 23 | NO | NO |
Signals from CVEs in this vendor scope (30 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Luxion.
Media articles that mention a CVE ID that affects a product developed by Luxion — matched by CVE ID, not by vendor name.