VYPR

Arduino Ide

by Arduino

Source repositories

CVEs (5)

  • CVE-2019-13991MedJul 19, 2019
    risk 0.42cvss 6.5epss 0.01

    Embedded systems based on Arduino before Rev3 allow remote attackers to send data to LEDs (directly connected to GPIO pins) via a laser, because of LED photosensitivity.

  • CVE-2025-64724HigDec 18, 2025
    risk 0.00cvss 7.3epss 0.00

    Arduino IDE is an integrated development environment. Prior to version 2.3.7, Arduino IDE for macOS is installed with world-writable file permissions on sensitive application components, allowing any local user to replace legitimate files with malicious code. When another user…

  • CVE-2025-64723MedDec 18, 2025
    risk 0.00cvss 4.4epss 0.00

    Arduino IDE is an integrated development environment. Prior to version 2.3.7, Arduino IDE for macOS was configured with overly permissive security entitlements that could bypass macOS Hardened Runtime protections. This configuration allows attackers to inject malicious dynamic…

  • CVE-2025-27608LowApr 2, 2025
    risk 0.00cvss epss 0.00

    Arduino IDE 2.x is an IDE based on the Theia IDE framework and built with Electron. A Self Cross-Site Scripting (XSS) vulnerability has been identified within the Arduino-IDE prior to version v2.3.5. The vulnerability occurs in the Additional Board Manager URLs field, which can…

  • CVE-2023-49296MedDec 13, 2023
    risk 0.00cvss 6.3epss 0.00

    The Arduino Create Agent allows users to use the Arduino Create applications to upload code to any USB connected Arduino board directly from the browser. A vulnerability in versions prior to 1.3.6 affects the endpoint `/certificate.crt` and the way the web interface of the…