arduino has 3 CVEs on record between 2023 and 2026. 1 was published in the last 90 days. The median CVSS is 7.3 (high). Most affected products: github.com/arduino/arduino-create-agent (2), ArduinoCore-avr (1).
CVEs per month
Last 12 months, by publish date
1025/101125/111225/120126/010226/020326/030426/040526/050626/060726/070826/080926/09
- Exploited share
- 0% vs 1% corpus
- Median CVSS
- 7.3
- Publish → KEV
- —
- Last 90 days
- 1 prev 0
Weakness classes
Products
- github.com/arduino/arduino-create-agent 2
- ArduinoCore-avr 1
3
Total CVEs
0
Critical
0
CISA KEV
0
Exploited
Worst active — by depth score
CVE-2023-43802High· 7.3Arduino Create Agent path traversal - local privilege escalation vulnerability40CVE-2023-43800High· 7.3Arduino Create Agent Insufficient Verification of Data Authenticity vulnerability40CVE-2026-48490Medium· 6.9ArduinoCore-avr contains the source code and configuration files of the Arduino AVR Boards platform38
arduino vulnerabilities
CVEs affecting arduino, newest first. Open any entry for full detail, references, and exploit status.
3 CVEsRSS
CVE-2026-48490Medium· 6.9ArduinoCore-avr contains the source code and configuration files of the Arduino AVR Boards platform
ArduinoCore-avr contains the source code and configuration files of the Arduino AVR Boards platform. A vulnerability in versions prior to 1.8.8 allows an attacker to trigger a stack-based buffer overflow when concatenating floating-point…
▾ Sunlitarduino · ArduinoCore-avrEPSS 0.39%via NVD
CVE-2023-43802High· 7.3Arduino Create Agent path traversal - local privilege escalation vulnerability
Arduino Create Agent path traversal - local privilege escalation vulnerability
▾ Twilightarduino · github.com/arduino/arduino-create-agentEPSS 0.35%via OSV
CVE-2023-43800High· 7.3Arduino Create Agent Insufficient Verification of Data Authenticity vulnerability
Arduino Create Agent Insufficient Verification of Data Authenticity vulnerability
▾ Twilightarduino · github.com/arduino/arduino-create-agentEPSS 0.21%via OSV