Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Dronecode

First CVE: Jul 3, 2020Active for: 6 yearsTotal CVEs: 26
33.3
VTI Score
Medium

Dronecode develops autopilot and communication firmware for small unmanned aircraft systems, with a narrow but strategically significant product portfolio centered on the PX4 drone autopilot and the Micro Air Vehicle Link protocol. Vulnerabilities affecting the vendor skew toward critical severity outcomes and reflect the memory-safety demands of embedded avionics code: the recurring weakness classes include classic and stack-based buffer overflows, out-of-bounds writes, race conditions, and improper value handling that arise from direct memory manipulation and concurrent access patterns in safety-critical flight control software. The exposure concentrates on core autopilot and communication products that are widely integrated into both commercial and defense unmanned systems, making flaws in this codebase consequential despite the narrow vendor footprint. Defenders should prioritize firmware inventory and validation for unmanned platforms that rely on these components; live severity and exploitation counts are shown alongside this summary.

FAUCET AI Generated
26
Total CVEs
More Total CVEs than 97% of tracked vendors
2.6
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 91% of tracked vendors
7.0
Avg CVSS Score
Higher Avg CVSS Score than 49% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Dronecode over time

Volume of CVEsAvg CVSS Base Score
First CVE
Jul 3, 2020
6 years ago
Most Recent CVE
Mar 19, 2026
127 days ago

Products(2 total)

Top CVEs

Signals from CVEs in this vendor scope (26 CVEs).

26 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2026-32708HIGH
PX4 autopilot is a flight control solution for drones. Prior to 1.17.0-rc2, the Zenoh uORB subscriber allocates a stack VLA directly from the incoming payload length without bounds
Mar 13, 20268.028NONO
CVE-2023-46256CRITICAL
PX4-Autopilot provides PX4 flight control solution for drones. In versions 1.14.0-rc1 and prior, PX4-Autopilot has a heap buffer overflow vulnerability in the parser function due t
Oct 31, 20239.827NONO
CVE-2026-26742HIGH
PX4 Autopilot versions 1.12.x through 1.15.x contain a protection mechanism failure in the "Re-arm Grace Period" logic. The system incorrectly applies the in-air emergency re-arm l
Mar 10, 20268.126NONO
CVE-2026-26741HIGH
PX4 Autopilot versions 1.12.x through 1.15.x contain a logic flaw in the mode switching mechanism. When switching from Auto mode to Manual mode while the drone is in the "ARMED" st
Mar 10, 20268.126NONO
CVE-2026-32743MEDIUM
PX4 is an open-source autopilot stack for drones and unmanned vehicles. Versions 1.17.0-rc2 and below are vulnerable to Stack-based Buffer Overflow through the MavlinkLogHandler, a
Mar 19, 20266.525NONO
CVE-2025-15150HIGH
A vulnerability was found in PX4 PX4-Autopilot up to 1.16.0. Affected by this issue is the function MavlinkLogHandler::state_listing/MavlinkLogHandler::log_entry_from_id of the fil
Dec 28, 20257.825NONO
CVE-2021-34125HIGH
An issue discovered in Yuneec Mantis Q and PX4-Autopilot v 1.11.3 and below allow attacker to gain access to sensitive information via various nuttx commands.
Mar 9, 20237.524NONO
CVE-2020-10283CRITICAL
The Micro Air Vehicle Link (MAVLink) protocol presents authentication mechanisms on its version 2.0 however according to its documentation, in order to maintain backwards compatibi
Aug 20, 20209.824NONO
CVE-2020-10282CRITICAL
The Micro Air Vehicle Link (MAVLink) protocol presents no authentication mechanism on its version 1.0 (nor authorization) whichs leads to a variety of attacks including identity sp
Jul 3, 20209.824NONO
CVE-2026-32706HIGH
PX4 autopilot is a flight control solution for drones. Prior to 1.17.0-rc2, The crsf_rc parser accepts an oversized variable-length known packet and copies it into a fixed 64-byte
Mar 16, 20268.123NONO
View all 26 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products26 CVEs
50%
38%
12%
Severity distribution among all CVEs352,231 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local5 (19.2%)
Network10 (38.5%)
Unknown0 (0.0%)
Physical2 (7.7%)
Adjacent Network9 (34.6%)
Attack Complexity
Low20 (76.9%)
High6 (23.1%)
Unknown0 (0.0%)
User Interaction
None22 (84.6%)
Unknown0 (0.0%)
Required4 (15.4%)
Privileges Required
Low8 (30.8%)
High1 (3.8%)
None17 (65.4%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (26 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Dronecode.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Dronecode — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Dronecode's Products

View all 4 CNAs →

Top CWEs