VYPR
Vendor

Arduino

Products
7
CVEs
12
Across products
15
Status
Private

Products

7

Recent CVEs

12
  • CVE-2025-69209MedJan 21, 2026
    risk 0.45cvss epss 0.00

    ArduinoCore-avr contains the source code and configuration files of the Arduino AVR Boards platform. A vulnerability in versions prior to 1.8.7 allows an attacker to trigger a stack-based buffer overflow when converting floating-point values to strings with high precision. By…

  • CVE-2026-25933MedFeb 12, 2026
    risk 0.44cvss 6.8epss 0.00

    Arduino App Lab is a cross-platform IDE for developing Arduino Apps. Prior to 0.4.0, a vulnerability was identified in the Terminal component of the arduino-app-lab application. The issue stems from insufficient sanitization and validation of input data received from connected…

  • CVE-2019-13991MedJul 19, 2019
    risk 0.42cvss 6.5epss 0.01

    Embedded systems based on Arduino before Rev3 allow remote attackers to send data to LEDs (directly connected to GPIO pins) via a laser, because of LED photosensitivity.

  • CVE-2023-43800HigOct 18, 2023
    risk 0.40cvss 7.3epss 0.00

    Arduino Create Agent is a package to help manage Arduino development. The vulnerability affects the endpoint `/v2/pkgs/tools/installed`. A user who has the ability to perform HTTP requests to the localhost interface, or is able to bypass the CORS configuration, can escalate his…

  • CVE-2023-43802HigOct 18, 2023
    risk 0.39cvss 7.1epss 0.00

    Arduino Create Agent is a package to help manage Arduino development. This vulnerability affects the endpoint `/upload` which handles request with the `filename` parameter. A user who has the ability to perform HTTP requests to the localhost interface, or is able to bypass the…

  • CVE-2026-26399MedApr 20, 2026
    risk 0.34cvss 5.3epss 0.00

    A stack-use-after-return issue exists in the Arduino_Core_STM32 library prior to version 1.7.0. The pwm_start() function allocates a TIM_HandleTypeDef structure on the stack and passes its address to HAL initialization routines, where it is stored in a global timer handle…

  • CVE-2023-43801MedOct 18, 2023
    risk 0.33cvss 6.1epss 0.00

    Arduino Create Agent is a package to help manage Arduino development. This vulnerability affects the endpoint `/v2/pkgs/tools/installed` and the way it handles plugin names supplied as user input. A user who has the ability to perform HTTP requests to the localhost interface, or…

  • CVE-2023-43803MedOct 18, 2023
    risk 0.33cvss 6.1epss 0.00

    Arduino Create Agent is a package to help manage Arduino development. This vulnerability affects the endpoint `/v2/pkgs/tools/installed` and the way it handles plugin names supplied as user input. A user who has the ability to perform HTTP requests to the localhost interface, or…

  • CVE-2025-64724HigDec 18, 2025
    risk 0.00cvss 7.3epss 0.00

    Arduino IDE is an integrated development environment. Prior to version 2.3.7, Arduino IDE for macOS is installed with world-writable file permissions on sensitive application components, allowing any local user to replace legitimate files with malicious code. When another user…

  • CVE-2025-64723MedDec 18, 2025
    risk 0.00cvss 4.4epss 0.00

    Arduino IDE is an integrated development environment. Prior to version 2.3.7, Arduino IDE for macOS was configured with overly permissive security entitlements that could bypass macOS Hardened Runtime protections. This configuration allows attackers to inject malicious dynamic…

  • CVE-2025-27608LowApr 2, 2025
    risk 0.00cvss epss 0.00

    Arduino IDE 2.x is an IDE based on the Theia IDE framework and built with Electron. A Self Cross-Site Scripting (XSS) vulnerability has been identified within the Arduino-IDE prior to version v2.3.5. The vulnerability occurs in the Additional Board Manager URLs field, which can…

  • CVE-2023-49296MedDec 13, 2023
    risk 0.00cvss 6.3epss 0.00

    The Arduino Create Agent allows users to use the Arduino Create applications to upload code to any USB connected Arduino board directly from the browser. A vulnerability in versions prior to 1.3.6 affects the endpoint `/certificate.crt` and the way the web interface of the…