dronecode records
26 published records for vendor dronecode.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 0
- With a fix record
- 30.8%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-120 Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')8
- CWE-121 Stack-based Buffer Overflow4
- CWE-229 Improper Handling of Values2
- CWE-362 Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')2
- CWE-862 Missing Authorization2
- CWE-319 Cleartext Transmission of Sensitive Information1
The weakness classes this vendor ships most often: where to look.
CWEAll records
26 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
40Plan | CVE-2020-10282No exploit | RVD#3316: No authentication in MAVLink protocoldronecode · micro air vehicle link · CWE-306 | Critical9.8 | — | 1.8% | Jul 3, 2020 |
39Monitor | CVE-2020-10283No exploit | RVD#3317: MAVLink version handshaking allows for an attacker to bypass authenticationdronecode · micro air vehicle link · CWE-288 | Critical9.8 | — | 1.5% | Aug 20, 2020 |
39Monitor | CVE-2023-46256No exploit | PX4-Autopilot Heap Buffer Overflow Bugdronecode · px4 drone autopilot · CWE-120 | Critical9.8 | — | 0.6% | Oct 31, 2023 |
32Monitor | CVE-2026-32706No exploit | PX4 autopilot has a global buffer overflow in crsf_rc via oversized variable-length known packetdronecode · px4 drone autopilot · CWE-120 | High8.1 | — | 0.3% | Mar 16, 2026 |
32Monitor | CVE-2026-26742No exploit | PX4 Autopilot versions 1.12.x through 1.15.x contain a protection mechanism failure in the "Re-arm Grace Period" logic.dronecode · px4 drone autopilot · CWE-862 | High8.1 | — | 0.3% | Mar 10, 2026 |
32Monitor | CVE-2026-26741No exploit | PX4 Autopilot versions 1.12.x through 1.15.x contain a logic flaw in the mode switching mechanism.dronecode · px4 drone autopilot · CWE-862 | High8.1 | — | 0.3% | Mar 10, 2026 |
32Monitor | CVE-2026-32708No exploit | Zenoh uORB Subscriber Allows Arbitrary Stack Allocation (PX4/PX4-Autopilot)dronecode · px4 drone autopilot · CWE-121 | High8.0 | — | 0.3% | Mar 16, 2026 |
31Monitor | CVE-2024-40427No exploit | Stack Buffer Overflow in PX4-Autopilot v1.14.3, which allows attackers to execute commands to exploit this vulnerability and cause the progrdronecode · px4 drone autopilot · CWE-120 | High7.9 | — | 0.3% | Jan 7, 2025 |
30Monitor | CVE-2021-34125No exploit | An issue discovered in Yuneec Mantis Q and PX4-Autopilot v 1.11.3 and below allow attacker to gain access to sensitive information via varioyuneec · mantis q firmware · CWE-200 | High7.5 | — | 1.0% | Mar 9, 2023 |
30Monitor | CVE-2021-46896No exploit | Buffer Overflow vulnerability in PX4-Autopilot allows attackers to cause a denial of service via handler function handling msgid 332.dronecode · px4 drone autopilot · CWE-120 | High7.5 | — | 0.8% | Jul 6, 2023 |
30Monitor | CVE-2020-10281No exploit | RVD#3315: Cleartext transmission of sensitive information in MAVLink protocol version 1.0 and 2.0dronecode · micro air vehicle link · CWE-319 | High7.5 | — | 0.7% | Jul 3, 2020 |
30Monitor | CVE-2024-38952No exploit | PX4-Autopilot v1.14.3 was discovered to contain a buffer overflow via the topic_name parameter at /logger/logged_topics.cpp.dronecode · px4 drone autopilot · CWE-120 | High7.5 | — | 0.7% | Jun 25, 2024 |
27Monitor | CVE-2026-32709No exploit | PX4 Autopilot MAVLink FTP Unauthenticated Path Traversal (Arbitrary File Read/Write/Delete)dronecode · px4 drone autopilot · CWE-22 | Medium6.8 | — | 0.3% | Mar 16, 2026 |
27Monitor | CVE-2026-32705No exploit | PX4 autopilot BST Device Name Length Can Overflow Driver Bufferdronecode · px4 drone autopilot · CWE-121 | Medium6.8 | — | 0.3% | Mar 16, 2026 |
26Monitor | CVE-2024-38951No exploit | A buffer overflow in PX4-Autopilot v1.12.3 allows attackers to cause a Denial of Service (DoS) via a crafted MavLink message.dronecode · px4 drone autopilot · CWE-120 | Medium6.5 | — | 0.5% | Jun 25, 2024 |
26Monitor | CVE-2026-32743Proof of concept | PX4 Autopilot: Stack-based Buffer Overflow via Oversized Path Input in MAVLink Log Request Handlingdronecode · px4 drone autopilot · CWE-121 | Medium6.5 | — | 0.3% | Mar 18, 2026 |
26Monitor | CVE-2026-32713No exploit | PX4 Autopilot MAVLink FTP Session Validation Logic Error Allows Operations on Invalid File Descriptorsdronecode · px4 drone autopilot · CWE-670 | Medium6.5 | — | 0.3% | Mar 16, 2026 |
26Monitor | CVE-2024-29460No exploit | An issue in PX4 Autopilot v.1.14.0 allows an attacker to manipulate the flight path allowing for crashes of the drone via the home point locdronecode · px4 drone autopilot · CWE-229 | Medium6.6 | — | 0.2% | Apr 10, 2024 |
24Monitor | CVE-2026-32707Proof of concept | PX4 autopilot has a stack buffer overflow in tattu_can due to unbounded memcpy in frame assembly loopdronecode · px4 drone autopilot · CWE-121 | Medium6.1 | — | 0.3% | Mar 16, 2026 |
22Monitor | CVE-2024-30800No exploit | PX4 Autopilot v.1.14 allows an attacker to fly the drone into no-fly zones by breaching the geofence using flaws in the function.dronecode · px4 drone autopilot · CWE-229 | Medium5.6 | — | 0.2% | Apr 23, 2024 |
21Monitor | CVE-2026-32724No exploit | PX4 autopilot has a heap Use-After-Free in MavlinkShell::available() via SERIAL_CONTROL Race Conditiondronecode · px4 drone autopilot · CWE-416 | Medium5.3 | — | 0.2% | Mar 16, 2026 |
19Monitor | CVE-2025-15150No exploit | PX4 PX4-Autopilot mavlink_log_handler.cpp log_entry_from_id stack-based overflowdronecode · px4 drone autopilot · CWE-119 | Medium4.8 | — | 0.2% | Dec 28, 2025 |
17Monitor | CVE-2023-47625No exploit | Global Buffer Overflow leading to denial of service in PX4-Autopilotdronecode · px4 drone autopilot · CWE-120 | Medium4.3 | — | 0.5% | Nov 13, 2023 |
17Monitor | CVE-2024-30799No exploit | An issue in PX4 Autopilot v1.14 and before allows a remote attacker to execute arbitrary code and cause a denial of service via the Breach Rdronecode · px4 drone autopilot · CWE-120 | Medium4.4 | — | 0.3% | Apr 21, 2024 |
16Monitor | CVE-2024-24254No exploit | PX4 Autopilot 1.14 and earlier, due to the lack of synchronization mechanism for loading geofence data, has a Race Condition vulnerability idronecode · px4 drone autopilot · CWE-362 | Medium4.2 | — | 0.4% | Feb 6, 2024 |
- CVE-2020-1028240Plan
RVD#3316: No authentication in MAVLink protocol
CriticalCVSS 9.8No exploitEPSS 2%dronecode · micro air vehicle linkJul 3, 2020
- CVE-2020-1028339Monitor
RVD#3317: MAVLink version handshaking allows for an attacker to bypass authentication
CriticalCVSS 9.8No exploitEPSS 1%dronecode · micro air vehicle linkAug 20, 2020
- CVE-2023-4625639Monitor
PX4-Autopilot Heap Buffer Overflow Bug
CriticalCVSS 9.8No exploitEPSS 1%dronecode · px4 drone autopilotOct 31, 2023
- CVE-2026-3270632Monitor
PX4 autopilot has a global buffer overflow in crsf_rc via oversized variable-length known packet
HighCVSS 8.1No exploitEPSS 0%dronecode · px4 drone autopilotMar 16, 2026
- CVE-2026-2674232Monitor
PX4 Autopilot versions 1.12.x through 1.15.x contain a protection mechanism failure in the "Re-arm Grace Period" logic.
HighCVSS 8.1No exploitEPSS 0%dronecode · px4 drone autopilotMar 10, 2026
- CVE-2026-2674132Monitor
PX4 Autopilot versions 1.12.x through 1.15.x contain a logic flaw in the mode switching mechanism.
HighCVSS 8.1No exploitEPSS 0%dronecode · px4 drone autopilotMar 10, 2026
- CVE-2026-3270832Monitor
Zenoh uORB Subscriber Allows Arbitrary Stack Allocation (PX4/PX4-Autopilot)
HighCVSS 8.0No exploitEPSS 0%dronecode · px4 drone autopilotMar 16, 2026
- CVE-2024-4042731Monitor
Stack Buffer Overflow in PX4-Autopilot v1.14.3, which allows attackers to execute commands to exploit this vulnerability and cause the progr
HighCVSS 7.9No exploitEPSS 0%dronecode · px4 drone autopilotJan 7, 2025
- CVE-2021-3412530Monitor
An issue discovered in Yuneec Mantis Q and PX4-Autopilot v 1.11.3 and below allow attacker to gain access to sensitive information via vario
HighCVSS 7.5No exploitEPSS 1%yuneec · mantis q firmwareMar 9, 2023
- CVE-2021-4689630Monitor
Buffer Overflow vulnerability in PX4-Autopilot allows attackers to cause a denial of service via handler function handling msgid 332.
HighCVSS 7.5No exploitEPSS 1%dronecode · px4 drone autopilotJul 6, 2023
- CVE-2020-1028130Monitor
RVD#3315: Cleartext transmission of sensitive information in MAVLink protocol version 1.0 and 2.0
HighCVSS 7.5No exploitEPSS 1%dronecode · micro air vehicle linkJul 3, 2020
- CVE-2024-3895230Monitor
PX4-Autopilot v1.14.3 was discovered to contain a buffer overflow via the topic_name parameter at /logger/logged_topics.cpp.
HighCVSS 7.5No exploitEPSS 1%dronecode · px4 drone autopilotJun 25, 2024
- CVE-2026-3270927Monitor
PX4 Autopilot MAVLink FTP Unauthenticated Path Traversal (Arbitrary File Read/Write/Delete)
MediumCVSS 6.8No exploitEPSS 0%dronecode · px4 drone autopilotMar 16, 2026
- CVE-2026-3270527Monitor
PX4 autopilot BST Device Name Length Can Overflow Driver Buffer
MediumCVSS 6.8No exploitEPSS 0%dronecode · px4 drone autopilotMar 16, 2026
- CVE-2024-3895126Monitor
A buffer overflow in PX4-Autopilot v1.12.3 allows attackers to cause a Denial of Service (DoS) via a crafted MavLink message.
MediumCVSS 6.5No exploitEPSS 1%dronecode · px4 drone autopilotJun 25, 2024
- CVE-2026-3274326Monitor
PX4 Autopilot: Stack-based Buffer Overflow via Oversized Path Input in MAVLink Log Request Handling
MediumCVSS 6.5Proof of conceptEPSS 0%dronecode · px4 drone autopilotMar 18, 2026
- CVE-2026-3271326Monitor
PX4 Autopilot MAVLink FTP Session Validation Logic Error Allows Operations on Invalid File Descriptors
MediumCVSS 6.5No exploitEPSS 0%dronecode · px4 drone autopilotMar 16, 2026
- CVE-2024-2946026Monitor
An issue in PX4 Autopilot v.1.14.0 allows an attacker to manipulate the flight path allowing for crashes of the drone via the home point loc
MediumCVSS 6.6No exploitEPSS 0%dronecode · px4 drone autopilotApr 10, 2024
- CVE-2026-3270724Monitor
PX4 autopilot has a stack buffer overflow in tattu_can due to unbounded memcpy in frame assembly loop
MediumCVSS 6.1Proof of conceptEPSS 0%dronecode · px4 drone autopilotMar 16, 2026
- CVE-2024-3080022Monitor
PX4 Autopilot v.1.14 allows an attacker to fly the drone into no-fly zones by breaching the geofence using flaws in the function.
MediumCVSS 5.6No exploitEPSS 0%dronecode · px4 drone autopilotApr 23, 2024
- CVE-2026-3272421Monitor
PX4 autopilot has a heap Use-After-Free in MavlinkShell::available() via SERIAL_CONTROL Race Condition
MediumCVSS 5.3No exploitEPSS 0%dronecode · px4 drone autopilotMar 16, 2026
- CVE-2025-1515019Monitor
PX4 PX4-Autopilot mavlink_log_handler.cpp log_entry_from_id stack-based overflow
MediumCVSS 4.8No exploitEPSS 0%dronecode · px4 drone autopilotDec 28, 2025
- CVE-2023-4762517Monitor
Global Buffer Overflow leading to denial of service in PX4-Autopilot
MediumCVSS 4.3No exploitEPSS 1%dronecode · px4 drone autopilotNov 13, 2023
- CVE-2024-3079917Monitor
An issue in PX4 Autopilot v1.14 and before allows a remote attacker to execute arbitrary code and cause a denial of service via the Breach R
MediumCVSS 4.4No exploitEPSS 0%dronecode · px4 drone autopilotApr 21, 2024
- CVE-2024-2425416Monitor
PX4 Autopilot 1.14 and earlier, due to the lack of synchronization mechanism for loading geofence data, has a Race Condition vulnerability i
MediumCVSS 4.2No exploitEPSS 0%dronecode · px4 drone autopilotFeb 6, 2024