Записи dronecode
26 опубликованных записей вендора dronecode.
Профиль для исследователя
- Попали в KEV
- 0 · 0 %
- С эксплойтом
- 0 · 0 %
- Pre-auth RCE
- 0
- С записью об исправлении
- 30,8 %
- Медиана: публикация → KEV
- Ни одна запись не попала в KEV
Повторяющиеся классы
- CWE-120 Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')8
- CWE-121 Stack-based Buffer Overflow4
- CWE-229 Improper Handling of Values2
- CWE-362 Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')2
- CWE-862 Missing Authorization2
- CWE-319 Cleartext Transmission of Sensitive Information1
Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.
CWEВсе записи
26 записей| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
40В плане | CVE-2020-10282Эксплойта нет | RVD#3316: No authentication in MAVLink protocoldronecode · micro air vehicle link · CWE-306 | Критическая9,8 | — | 1,8 % | 3 июл. 2020 г. |
39Наблюдать | CVE-2020-10283Эксплойта нет | RVD#3317: MAVLink version handshaking allows for an attacker to bypass authenticationdronecode · micro air vehicle link · CWE-288 | Критическая9,8 | — | 1,5 % | 20 авг. 2020 г. |
39Наблюдать | CVE-2023-46256Эксплойта нет | PX4-Autopilot Heap Buffer Overflow Bugdronecode · px4 drone autopilot · CWE-120 | Критическая9,8 | — | 0,6 % | 31 окт. 2023 г. |
32Наблюдать | CVE-2026-32706Эксплойта нет | PX4 autopilot has a global buffer overflow in crsf_rc via oversized variable-length known packetdronecode · px4 drone autopilot · CWE-120 | Высокая8,1 | — | 0,3 % | 16 мар. 2026 г. |
32Наблюдать | CVE-2026-26742Эксплойта нет | PX4 Autopilot versions 1.12.x through 1.15.x contain a protection mechanism failure in the "Re-arm Grace Period" logic.dronecode · px4 drone autopilot · CWE-862 | Высокая8,1 | — | 0,3 % | 10 мар. 2026 г. |
32Наблюдать | CVE-2026-26741Эксплойта нет | PX4 Autopilot versions 1.12.x through 1.15.x contain a logic flaw in the mode switching mechanism.dronecode · px4 drone autopilot · CWE-862 | Высокая8,1 | — | 0,3 % | 10 мар. 2026 г. |
32Наблюдать | CVE-2026-32708Эксплойта нет | Zenoh uORB Subscriber Allows Arbitrary Stack Allocation (PX4/PX4-Autopilot)dronecode · px4 drone autopilot · CWE-121 | Высокая8,0 | — | 0,3 % | 16 мар. 2026 г. |
31Наблюдать | CVE-2024-40427Эксплойта нет | Stack Buffer Overflow in PX4-Autopilot v1.14.3, which allows attackers to execute commands to exploit this vulnerability and cause the progrdronecode · px4 drone autopilot · CWE-120 | Высокая7,9 | — | 0,3 % | 7 янв. 2025 г. |
30Наблюдать | CVE-2021-34125Эксплойта нет | An issue discovered in Yuneec Mantis Q and PX4-Autopilot v 1.11.3 and below allow attacker to gain access to sensitive information via varioyuneec · mantis q firmware · CWE-200 | Высокая7,5 | — | 1,0 % | 9 мар. 2023 г. |
30Наблюдать | CVE-2021-46896Эксплойта нет | Buffer Overflow vulnerability in PX4-Autopilot allows attackers to cause a denial of service via handler function handling msgid 332.dronecode · px4 drone autopilot · CWE-120 | Высокая7,5 | — | 0,8 % | 6 июл. 2023 г. |
30Наблюдать | CVE-2020-10281Эксплойта нет | RVD#3315: Cleartext transmission of sensitive information in MAVLink protocol version 1.0 and 2.0dronecode · micro air vehicle link · CWE-319 | Высокая7,5 | — | 0,7 % | 3 июл. 2020 г. |
30Наблюдать | CVE-2024-38952Эксплойта нет | PX4-Autopilot v1.14.3 was discovered to contain a buffer overflow via the topic_name parameter at /logger/logged_topics.cpp.dronecode · px4 drone autopilot · CWE-120 | Высокая7,5 | — | 0,7 % | 25 июн. 2024 г. |
27Наблюдать | CVE-2026-32709Эксплойта нет | PX4 Autopilot MAVLink FTP Unauthenticated Path Traversal (Arbitrary File Read/Write/Delete)dronecode · px4 drone autopilot · CWE-22 | Средняя6,8 | — | 0,3 % | 16 мар. 2026 г. |
27Наблюдать | CVE-2026-32705Эксплойта нет | PX4 autopilot BST Device Name Length Can Overflow Driver Bufferdronecode · px4 drone autopilot · CWE-121 | Средняя6,8 | — | 0,3 % | 16 мар. 2026 г. |
26Наблюдать | CVE-2024-38951Эксплойта нет | A buffer overflow in PX4-Autopilot v1.12.3 allows attackers to cause a Denial of Service (DoS) via a crafted MavLink message.dronecode · px4 drone autopilot · CWE-120 | Средняя6,5 | — | 0,5 % | 25 июн. 2024 г. |
26Наблюдать | CVE-2026-32743Proof of concept | PX4 Autopilot: Stack-based Buffer Overflow via Oversized Path Input in MAVLink Log Request Handlingdronecode · px4 drone autopilot · CWE-121 | Средняя6,5 | — | 0,3 % | 18 мар. 2026 г. |
26Наблюдать | CVE-2026-32713Эксплойта нет | PX4 Autopilot MAVLink FTP Session Validation Logic Error Allows Operations on Invalid File Descriptorsdronecode · px4 drone autopilot · CWE-670 | Средняя6,5 | — | 0,3 % | 16 мар. 2026 г. |
26Наблюдать | CVE-2024-29460Эксплойта нет | An issue in PX4 Autopilot v.1.14.0 allows an attacker to manipulate the flight path allowing for crashes of the drone via the home point locdronecode · px4 drone autopilot · CWE-229 | Средняя6,6 | — | 0,2 % | 10 апр. 2024 г. |
24Наблюдать | CVE-2026-32707Proof of concept | PX4 autopilot has a stack buffer overflow in tattu_can due to unbounded memcpy in frame assembly loopdronecode · px4 drone autopilot · CWE-121 | Средняя6,1 | — | 0,3 % | 16 мар. 2026 г. |
22Наблюдать | CVE-2024-30800Эксплойта нет | PX4 Autopilot v.1.14 allows an attacker to fly the drone into no-fly zones by breaching the geofence using flaws in the function.dronecode · px4 drone autopilot · CWE-229 | Средняя5,6 | — | 0,2 % | 23 апр. 2024 г. |
21Наблюдать | CVE-2026-32724Эксплойта нет | PX4 autopilot has a heap Use-After-Free in MavlinkShell::available() via SERIAL_CONTROL Race Conditiondronecode · px4 drone autopilot · CWE-416 | Средняя5,3 | — | 0,2 % | 16 мар. 2026 г. |
19Наблюдать | CVE-2025-15150Эксплойта нет | PX4 PX4-Autopilot mavlink_log_handler.cpp log_entry_from_id stack-based overflowdronecode · px4 drone autopilot · CWE-119 | Средняя4,8 | — | 0,2 % | 28 дек. 2025 г. |
17Наблюдать | CVE-2023-47625Эксплойта нет | Global Buffer Overflow leading to denial of service in PX4-Autopilotdronecode · px4 drone autopilot · CWE-120 | Средняя4,3 | — | 0,5 % | 13 нояб. 2023 г. |
17Наблюдать | CVE-2024-30799Эксплойта нет | An issue in PX4 Autopilot v1.14 and before allows a remote attacker to execute arbitrary code and cause a denial of service via the Breach Rdronecode · px4 drone autopilot · CWE-120 | Средняя4,4 | — | 0,3 % | 21 апр. 2024 г. |
16Наблюдать | CVE-2024-24254Эксплойта нет | PX4 Autopilot 1.14 and earlier, due to the lack of synchronization mechanism for loading geofence data, has a Race Condition vulnerability idronecode · px4 drone autopilot · CWE-362 | Средняя4,2 | — | 0,4 % | 6 февр. 2024 г. |
- CVE-2020-1028240В плане
RVD#3316: No authentication in MAVLink protocol
КритическаяCVSS 9,8Эксплойта нетEPSS 2 %dronecode · micro air vehicle link3 июл. 2020 г.
- CVE-2020-1028339Наблюдать
RVD#3317: MAVLink version handshaking allows for an attacker to bypass authentication
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %dronecode · micro air vehicle link20 авг. 2020 г.
- CVE-2023-4625639Наблюдать
PX4-Autopilot Heap Buffer Overflow Bug
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %dronecode · px4 drone autopilot31 окт. 2023 г.
- CVE-2026-3270632Наблюдать
PX4 autopilot has a global buffer overflow in crsf_rc via oversized variable-length known packet
ВысокаяCVSS 8,1Эксплойта нетEPSS 0 %dronecode · px4 drone autopilot16 мар. 2026 г.
- CVE-2026-2674232Наблюдать
PX4 Autopilot versions 1.12.x through 1.15.x contain a protection mechanism failure in the "Re-arm Grace Period" logic.
ВысокаяCVSS 8,1Эксплойта нетEPSS 0 %dronecode · px4 drone autopilot10 мар. 2026 г.
- CVE-2026-2674132Наблюдать
PX4 Autopilot versions 1.12.x through 1.15.x contain a logic flaw in the mode switching mechanism.
ВысокаяCVSS 8,1Эксплойта нетEPSS 0 %dronecode · px4 drone autopilot10 мар. 2026 г.
- CVE-2026-3270832Наблюдать
Zenoh uORB Subscriber Allows Arbitrary Stack Allocation (PX4/PX4-Autopilot)
ВысокаяCVSS 8,0Эксплойта нетEPSS 0 %dronecode · px4 drone autopilot16 мар. 2026 г.
- CVE-2024-4042731Наблюдать
Stack Buffer Overflow in PX4-Autopilot v1.14.3, which allows attackers to execute commands to exploit this vulnerability and cause the progr
ВысокаяCVSS 7,9Эксплойта нетEPSS 0 %dronecode · px4 drone autopilot7 янв. 2025 г.
- CVE-2021-3412530Наблюдать
An issue discovered in Yuneec Mantis Q and PX4-Autopilot v 1.11.3 and below allow attacker to gain access to sensitive information via vario
ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %yuneec · mantis q firmware9 мар. 2023 г.
- CVE-2021-4689630Наблюдать
Buffer Overflow vulnerability in PX4-Autopilot allows attackers to cause a denial of service via handler function handling msgid 332.
ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %dronecode · px4 drone autopilot6 июл. 2023 г.
- CVE-2020-1028130Наблюдать
RVD#3315: Cleartext transmission of sensitive information in MAVLink protocol version 1.0 and 2.0
ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %dronecode · micro air vehicle link3 июл. 2020 г.
- CVE-2024-3895230Наблюдать
PX4-Autopilot v1.14.3 was discovered to contain a buffer overflow via the topic_name parameter at /logger/logged_topics.cpp.
ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %dronecode · px4 drone autopilot25 июн. 2024 г.
- CVE-2026-3270927Наблюдать
PX4 Autopilot MAVLink FTP Unauthenticated Path Traversal (Arbitrary File Read/Write/Delete)
СредняяCVSS 6,8Эксплойта нетEPSS 0 %dronecode · px4 drone autopilot16 мар. 2026 г.
- CVE-2026-3270527Наблюдать
PX4 autopilot BST Device Name Length Can Overflow Driver Buffer
СредняяCVSS 6,8Эксплойта нетEPSS 0 %dronecode · px4 drone autopilot16 мар. 2026 г.
- CVE-2024-3895126Наблюдать
A buffer overflow in PX4-Autopilot v1.12.3 allows attackers to cause a Denial of Service (DoS) via a crafted MavLink message.
СредняяCVSS 6,5Эксплойта нетEPSS 1 %dronecode · px4 drone autopilot25 июн. 2024 г.
- CVE-2026-3274326Наблюдать
PX4 Autopilot: Stack-based Buffer Overflow via Oversized Path Input in MAVLink Log Request Handling
СредняяCVSS 6,5Proof of conceptEPSS 0 %dronecode · px4 drone autopilot18 мар. 2026 г.
- CVE-2026-3271326Наблюдать
PX4 Autopilot MAVLink FTP Session Validation Logic Error Allows Operations on Invalid File Descriptors
СредняяCVSS 6,5Эксплойта нетEPSS 0 %dronecode · px4 drone autopilot16 мар. 2026 г.
- CVE-2024-2946026Наблюдать
An issue in PX4 Autopilot v.1.14.0 allows an attacker to manipulate the flight path allowing for crashes of the drone via the home point loc
СредняяCVSS 6,6Эксплойта нетEPSS 0 %dronecode · px4 drone autopilot10 апр. 2024 г.
- CVE-2026-3270724Наблюдать
PX4 autopilot has a stack buffer overflow in tattu_can due to unbounded memcpy in frame assembly loop
СредняяCVSS 6,1Proof of conceptEPSS 0 %dronecode · px4 drone autopilot16 мар. 2026 г.
- CVE-2024-3080022Наблюдать
PX4 Autopilot v.1.14 allows an attacker to fly the drone into no-fly zones by breaching the geofence using flaws in the function.
СредняяCVSS 5,6Эксплойта нетEPSS 0 %dronecode · px4 drone autopilot23 апр. 2024 г.
- CVE-2026-3272421Наблюдать
PX4 autopilot has a heap Use-After-Free in MavlinkShell::available() via SERIAL_CONTROL Race Condition
СредняяCVSS 5,3Эксплойта нетEPSS 0 %dronecode · px4 drone autopilot16 мар. 2026 г.
- CVE-2025-1515019Наблюдать
PX4 PX4-Autopilot mavlink_log_handler.cpp log_entry_from_id stack-based overflow
СредняяCVSS 4,8Эксплойта нетEPSS 0 %dronecode · px4 drone autopilot28 дек. 2025 г.
- CVE-2023-4762517Наблюдать
Global Buffer Overflow leading to denial of service in PX4-Autopilot
СредняяCVSS 4,3Эксплойта нетEPSS 1 %dronecode · px4 drone autopilot13 нояб. 2023 г.
- CVE-2024-3079917Наблюдать
An issue in PX4 Autopilot v1.14 and before allows a remote attacker to execute arbitrary code and cause a denial of service via the Breach R
СредняяCVSS 4,4Эксплойта нетEPSS 0 %dronecode · px4 drone autopilot21 апр. 2024 г.
- CVE-2024-2425416Наблюдать
PX4 Autopilot 1.14 and earlier, due to the lack of synchronization mechanism for loading geofence data, has a Race Condition vulnerability i
СредняяCVSS 4,2Эксплойта нетEPSS 0 %dronecode · px4 drone autopilot6 февр. 2024 г.