Vulnerability index

Browse CVEs

22 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Px4 Drone Autopilot MEDIUM 6.5
CVE-2026-32743

PX4 is an open-source autopilot stack for drones and unmanned vehicles. Versions 1.17.0-rc2 and below are vulnerable to Stack-based Buffer Overflow t…

Fix: 1.17.0+
Fix from $1,600 2026-03-19
Px4 Drone Autopilot MEDIUM 5.3
CVE-2026-32724

PX4 autopilot is a flight control solution for drones. Prior to 1.17.0-rc1, a heap-use-after-free is detected in the MavlinkShell::available() functi…

Fix: 1.17.0+
Fix from $1,600 2026-03-16
Px4 Drone Autopilot MEDIUM 6.8
CVE-2026-32709

PX4 autopilot is a flight control solution for drones. Prior to 1.17.0-rc2, An unauthenticated path traversal vulnerability in the PX4 Autopilot MAVL…

Fix: 1.17.0+
Fix from $1,600 2026-03-16
Px4 Drone Autopilot MEDIUM 6.5
CVE-2026-32713

PX4 autopilot is a flight control solution for drones. Prior to 1.17.0-rc2, A logic error in the PX4 Autopilot MAVLink FTP session validation uses in…

Fix: 1.17.0+
Fix from $1,600 2026-03-16
Px4 Drone Autopilot HIGH 8.1
CVE-2026-32706

PX4 autopilot is a flight control solution for drones. Prior to 1.17.0-rc2, The crsf_rc parser accepts an oversized variable-length known packet and …

Fix: 1.17.0+
Fix from $1,950 2026-03-16
Px4 Drone Autopilot HIGH 8.0
CVE-2026-32708

PX4 autopilot is a flight control solution for drones. Prior to 1.17.0-rc2, the Zenoh uORB subscriber allocates a stack VLA directly from the incomin…

Fix: 1.17.0+
Fix from $1,950 2026-03-16
Px4 Drone Autopilot MEDIUM 6.8
CVE-2026-32705

PX4 autopilot is a flight control solution for drones. Prior to 1.17.0-rc2, the BST telemetry probe writes a string terminator using a device-provide…

Fix: 1.17.0+
Fix from $1,600 2026-03-16
Px4 Drone Autopilot MEDIUM 6.1
CVE-2026-32707

PX4 autopilot is a flight control solution for drones. Prior to 1.17.0-rc2, tattu_can contains an unbounded memcpy in its multi-frame assembly loop, …

Fix: 1.17.0+
Fix from $1,600 2026-03-16
Px4 Drone Autopilot HIGH 8.1
CVE-2026-26741

PX4 Autopilot versions 1.12.x through 1.15.x contain a logic flaw in the mode switching mechanism. When switching from Auto mode to Manual mode while…

Fix: 1.16.0+
Fix from $1,950 2026-03-10
Px4 Drone Autopilot HIGH 8.1
CVE-2026-26742

PX4 Autopilot versions 1.12.x through 1.15.x contain a protection mechanism failure in the "Re-arm Grace Period" logic. The system incorrectly applie…

Fix: 1.16.0+
Fix from $1,950 2026-03-10
Px4 Drone Autopilot HIGH 7.8
CVE-2025-15150

A vulnerability was found in PX4 PX4-Autopilot up to 1.16.0. Affected by this issue is the function MavlinkLogHandler::state_listing/MavlinkLogHandle…

Fix: after 1.16.0
Fix from $1,950 2025-12-28
Px4 Drone Autopilot HIGH 7.9
CVE-2024-40427

Stack Buffer Overflow in PX4-Autopilot v1.14.3, which allows attackers to execute commands to exploit this vulnerability and cause the program to ref…

Fix: 1.14.3+
Fix from $1,950 2025-01-07
Px4 Drone Autopilot HIGH 7.5
CVE-2024-38952

PX4-Autopilot v1.14.3 was discovered to contain a buffer overflow via the topic_name parameter at /logger/logged_topics.cpp.

No fix yet
Fix from $1,950 2024-06-25
Px4 Drone Autopilot MEDIUM 6.5
CVE-2024-38951

A buffer overflow in PX4-Autopilot v1.12.3 allows attackers to cause a Denial of Service (DoS) via a crafted MavLink message.

No fix yet
Fix from $1,600 2024-06-25
Px4 Drone Autopilot MEDIUM 5.6
CVE-2024-30800

PX4 Autopilot v.1.14 allows an attacker to fly the drone into no-fly zones by breaching the geofence using flaws in the function.

Patch available
Fix from $1,600 2024-04-23
Px4 Drone Autopilot MEDIUM 6.6
CVE-2024-29460

An issue in PX4 Autopilot v.1.14.0 allows an attacker to manipulate the flight path allowing for crashes of the drone via the home point location of …

Patch available
Fix from $1,600 2024-04-10
Px4 Drone Autopilot CRITICAL 9.8
CVE-2023-46256

PX4-Autopilot provides PX4 flight control solution for drones. In versions 1.14.0-rc1 and prior, PX4-Autopilot has a heap buffer overflow vulnerabili…

Fix: after 1.13.3
Fix from $2,300 2023-10-31
Px4 Drone Autopilot HIGH 7.5
CVE-2021-46896

Buffer Overflow vulnerability in PX4-Autopilot allows attackers to cause a denial of service via handler function handling msgid 332.

No fix yet
Fix from $1,950 2023-07-06
Px4 Drone Autopilot HIGH 7.5
CVE-2021-34125

An issue discovered in Yuneec Mantis Q and PX4-Autopilot v 1.11.3 and below allow attacker to gain access to sensitive information via various nuttx …

Fix: after 1.11.3
Fix from $1,950 2023-03-09
Micro Air Vehicle Link CRITICAL 9.8
CVE-2020-10283

The Micro Air Vehicle Link (MAVLink) protocol presents authentication mechanisms on its version 2.0 however according to its documentation, in order …

No fix yet
Fix from $2,300 2020-08-20
Micro Air Vehicle Link CRITICAL 9.8
CVE-2020-10282

The Micro Air Vehicle Link (MAVLink) protocol presents no authentication mechanism on its version 1.0 (nor authorization) whichs leads to a variety o…

Mitigation only
Fix from $2,300 2020-07-03
Micro Air Vehicle Link HIGH 7.5
CVE-2020-10281

This vulnerability applies to the Micro Air Vehicle Link (MAVLink) protocol and allows a remote attacker to gain access to sensitive information prov…

Mitigation only
Fix from $1,950 2020-07-03