Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Arduino

First CVE: Jul 19, 2019Active for: 7 yearsTotal CVEs: 9

Arduino's vulnerability footprint centers on a modestly represented set of development tools and microcontroller platforms, including its integrated development environment, firmware, and educational applications, which reach users across embedded systems and maker communities. The recurring weakness classes—path traversal, default permission errors, cross-site scripting in web interfaces, and OS command injection—reflect the mixed trust boundaries between local development tooling, web-based components, and embedded firmware that characterize this vendor's product stack. Current exploitation activity, severity distribution, and detailed exposure counts are shown alongside this summary.

FAUCET AI Generated
9
Total CVEs
More Total CVEs than 91% of tracked vendors
0.5
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 4% of tracked vendors
6.8
Avg CVSS Score
Higher Avg CVSS Score than 44% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Arduino over time

Volume of CVEsAvg CVSS Base Score
First CVE
Jul 19, 2019
7 years ago
Most Recent CVE
Feb 12, 2026
162 days ago

Products(5 total)

Top CVEs

Signals from CVEs in this vendor scope (9 CVEs).

9 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2025-64724HIGH
Arduino IDE is an integrated development environment. Prior to version 2.3.7, Arduino IDE for macOS is installed with world-writable file permissions on sensitive application compo
Dec 18, 20257.324NONO
CVE-2023-43800HIGH
Arduino Create Agent is a package to help manage Arduino development. The vulnerability affects the endpoint `/v2/pkgs/tools/installed`. A user who has the ability to perform HTTP
Oct 18, 20237.824NONO
CVE-2023-43802HIGH
Arduino Create Agent is a package to help manage Arduino development. This vulnerability affects the endpoint `/upload` which handles request with the `filename` parameter. A user
Oct 18, 20237.824NONO
CVE-2019-13991MEDIUM
Embedded systems based on Arduino before Rev3 allow remote attackers to send data to LEDs (directly connected to GPIO pins) via a laser, because of LED photosensitivity.
Jul 19, 20196.523NONO
CVE-2023-43801HIGH
Arduino Create Agent is a package to help manage Arduino development. This vulnerability affects the endpoint `/v2/pkgs/tools/installed` and the way it handles plugin names supplie
Oct 18, 20237.122NONO
CVE-2023-43803HIGH
Arduino Create Agent is a package to help manage Arduino development. This vulnerability affects the endpoint `/v2/pkgs/tools/installed` and the way it handles plugin names supplie
Oct 18, 20237.122NONO
CVE-2026-25933MEDIUM
Arduino App Lab is a cross-platform IDE for developing Arduino Apps. Prior to 0.4.0, a vulnerability was identified in the Terminal component of the arduino-app-lab application. Th
Feb 12, 20266.821NONO
CVE-2025-64723MEDIUM
Arduino IDE is an integrated development environment. Prior to version 2.3.7, Arduino IDE for macOS was configured with overly permissive security entitlements that could bypass ma
Dec 18, 20254.418NONO
CVE-2023-49296MEDIUM
The Arduino Create Agent allows users to use the Arduino Create applications to upload code to any USB connected Arduino board directly from the browser. A vulnerability in version
Dec 13, 20236.118NONO
View all 9 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products9 CVEs
44%
56%
Severity distribution among all CVEs352,294 CVEs
45%
40%
11%
MediumHigh
Attack Vector
Local6 (66.7%)
Network1 (11.1%)
Unknown0 (0.0%)
Physical1 (11.1%)
Adjacent Network1 (11.1%)
Attack Complexity
Low8 (88.9%)
High1 (11.1%)
Unknown0 (0.0%)
User Interaction
None6 (66.7%)
Unknown0 (0.0%)
Required3 (33.3%)
Privileges Required
Low6 (66.7%)
High1 (11.1%)
None2 (22.2%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (9 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Arduino.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Arduino — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Arduino's Products

View all 2 CNAs →

Top CWEs