CVE Browser

Page 1 (more results available)

Vendor: Dronecode Remove filter Clear all
CVE-2026-32743 MEDIUM

PX4 Autopilot: Stack-based Buffer Overflow via Oversized Path Input in MAVLink Log Request Handling

CVSS 6.5 EPSS 0.33% Mar 18, 2026
CVE-2026-32724 MEDIUM

PX4 autopilot has a heap Use-After-Free in MavlinkShell::available() via SERIAL_CONTROL Race Condition

CVSS 5.3 EPSS 0.23% Mar 13, 2026
CVE-2026-32713 MEDIUM

PX4 Autopilot MAVLink FTP Session Validation Logic Error Allows Operations on Invalid File Descriptors

CVSS 6.5 EPSS 0.29% Mar 13, 2026
CVE-2026-32709 MEDIUM

PX4 Autopilot MAVLink FTP Unauthenticated Path Traversal (Arbitrary File Read/Write/Delete)

CVSS 6.8 EPSS 0.32% Mar 13, 2026
CVE-2026-32708 HIGH

Zenoh uORB Subscriber Allows Arbitrary Stack Allocation (PX4/PX4-Autopilot)

CVSS 8.0 EPSS 0.26% Mar 13, 2026
CVE-2026-32707 MEDIUM

PX4 autopilot has a stack buffer overflow in tattu_can due to unbounded memcpy in frame assembly loop

CVSS 6.1 EPSS 0.27% Mar 13, 2026
CVE-2026-32706 HIGH

PX4 autopilot has a global buffer overflow in crsf_rc via oversized variable-length known packet

CVSS 8.1 EPSS 0.31% Mar 13, 2026
CVE-2026-32705 MEDIUM

PX4 autopilot BST Device Name Length Can Overflow Driver Buffer

CVSS 6.8 EPSS 0.28% Mar 13, 2026
CVE-2026-26742 HIGH

PX4 Autopilot versions 1.12.x through 1.15.x contain a protection mechanism failure in the "Re-arm Grace Period" logic. The system incorrectly applies the in-a…

CVSS 8.1 EPSS 0.31% Mar 10, 2026
CVE-2026-26741 HIGH

PX4 Autopilot versions 1.12.x through 1.15.x contain a logic flaw in the mode switching mechanism. When switching from Auto mode to Manual mode while the drone…

CVSS 8.1 EPSS 0.30% Mar 10, 2026
CVE-2025-15150 MEDIUM

PX4 PX4-Autopilot mavlink_log_handler.cpp log_entry_from_id stack-based overflow

CVSS 4.8 EPSS 0.25% Dec 28, 2025
CVE-2024-40427 HIGH

Stack Buffer Overflow in PX4-Autopilot v1.14.3, which allows attackers to execute commands to exploit this vulnerability and cause the program to refuse to exe…

CVSS 7.9 EPSS 0.35% Jan 7, 2025
CVE-2024-38952 HIGH

PX4-Autopilot v1.14.3 was discovered to contain a buffer overflow via the topic_name parameter at /logger/logged_topics.cpp.

CVSS 7.5 EPSS 0.70% Jun 25, 2024
CVE-2024-38951 MEDIUM

A buffer overflow in PX4-Autopilot v1.12.3 allows attackers to cause a Denial of Service (DoS) via a crafted MavLink message.

CVSS 6.5 EPSS 0.53% Jun 25, 2024
CVE-2024-30800 MEDIUM

PX4 Autopilot v.1.14 allows an attacker to fly the drone into no-fly zones by breaching the geofence using flaws in the function.

CVSS 5.6 EPSS 0.21% Apr 23, 2024
CVE-2024-30799 MEDIUM

An issue in PX4 Autopilot v1.14 and before allows a remote attacker to execute arbitrary code and cause a denial of service via the Breach Return Point functio…

CVSS 4.4 EPSS 0.26% Apr 22, 2024
CVE-2024-29460 MEDIUM

An issue in PX4 Autopilot v.1.14.0 allows an attacker to manipulate the flight path allowing for crashes of the drone via the home point location of the missio…

CVSS 6.6 EPSS 0.24% Apr 10, 2024
CVE-2024-24255 MEDIUM

A Race Condition discovered in geofence.cpp and mission_feasibility_checker.cpp in PX4 Autopilot 1.14 and earlier allows attackers to send drones on unintended…

CVSS 4.2 EPSS 0.34% Feb 6, 2024
CVE-2024-24254 MEDIUM

PX4 Autopilot 1.14 and earlier, due to the lack of synchronization mechanism for loading geofence data, has a Race Condition vulnerability in the geofence.cpp…

CVSS 4.2 EPSS 0.36% Feb 6, 2024
CVE-2023-47625 MEDIUM

Global Buffer Overflow leading to denial of service in PX4-Autopilot

CVSS 4.3 EPSS 0.52% Nov 13, 2023
CVE-2023-46256 CRITICAL

PX4-Autopilot Heap Buffer Overflow Bug

CVSS 9.8 EPSS 0.63% Oct 31, 2023
CVE-2021-46896 HIGH

Buffer Overflow vulnerability in PX4-Autopilot allows attackers to cause a denial of service via handler function handling msgid 332.

CVSS 7.5 EPSS 0.81% Jul 6, 2023
CVE-2021-34125 HIGH

An issue discovered in Yuneec Mantis Q and PX4-Autopilot v 1.11.3 and below allow attacker to gain access to sensitive information via various nuttx commands.

CVSS 7.5 EPSS 0.96% Mar 9, 2023
CVE-2020-10283 CRITICAL

RVD#3317: MAVLink version handshaking allows for an attacker to bypass authentication

CVSS 9.8 EPSS 1.47% Aug 20, 2020
CVE-2020-10282 CRITICAL

RVD#3316: No authentication in MAVLink protocol

CVSS 9.8 EPSS 1.76% Jul 3, 2020

Showing 1 to 25 CVEs · page 1 (more available)