Skip to main content

Vendor archive

arduino CVEs

Beta · best-effort

9 CVEs tagged to vendor arduino0 Critical, 2 High, 7 Medium, 0 Low, 0 Unrated.

CVE-2026-25933

Published Feb 12, 2026

Arduino App Lab is a cross-platform IDE for developing Arduino Apps. Prior to 0.4.0, a vulnerability was identified in the Terminal component of the arduino-app-lab application. T…

CVSS 6.8 · Medium
evidence mentions
2
Buzz score
16.0
Vendor/product tagsBeta · best-effort

CVE-2025-64724

Published Dec 18, 2025

Arduino IDE is an integrated development environment. Prior to version 2.3.7, Arduino IDE for macOS is installed with world-writable file permissions on sensitive application comp…

CVSS 4.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-64723

Published Dec 18, 2025

Arduino IDE is an integrated development environment. Prior to version 2.3.7, Arduino IDE for macOS was configured with overly permissive security entitlements that could bypass m…

CVSS 4.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-49296

Published Dec 13, 2023

The Arduino Create Agent allows users to use the Arduino Create applications to upload code to any USB connected Arduino board directly from the browser. A vulnerability in versio…

CVSS 6.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-43801

Published Oct 18, 2023

Arduino Create Agent is a package to help manage Arduino development. This vulnerability affects the endpoint `/v2/pkgs/tools/installed` and the way it handles plugin names suppli…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-43800

Published Oct 18, 2023

Arduino Create Agent is a package to help manage Arduino development. The vulnerability affects the endpoint `/v2/pkgs/tools/installed`. A user who has the ability to perform HTTP…

CVSS 7.3 · High
Vendor/product tagsBeta · best-effort

CVE-2023-43803

Published Oct 18, 2023

Arduino Create Agent is a package to help manage Arduino development. This vulnerability affects the endpoint `/v2/pkgs/tools/installed` and the way it handles plugin names suppli…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-43802

Published Oct 18, 2023

Arduino Create Agent is a package to help manage Arduino development. This vulnerability affects the endpoint `/upload` which handles request with the `filename` parameter. A user…

CVSS 7.1 · High
Vendor/product tagsBeta · best-effort

CVE-2019-13991

Published Jul 19, 2019

Embedded systems based on Arduino before Rev3 allow remote attackers to send data to LEDs (directly connected to GPIO pins) via a laser, because of LED photosensitivity.

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort
Showing 1-9 of 9 CVEsPage 1 of 1