Kicad is an open-source electronic design automation platform that, despite a narrow product scope, occupies a critical role in hardware design workflows across academia, hobbyist electronics, and professional circuit-board development. Its vulnerability exposure centers on memory-safety issues including out-of-bounds writes and stack-based buffer overflows, which are characteristic of large C++ codebases handling complex file parsing and graphics rendering. Live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Kicad over time
Signals from CVEs in this vendor scope (4 CVEs).
4 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2022-23804HIGH A stack-based buffer overflow vulnerability exists in the Gerber Viewer gerber and excellon ReadIJCoord coordinate parsing functionality of KiCad EDA 6.0.1 and master commit de006f | Feb 16, 2022 | 7.8 | 27 | NO | NO |
CVE-2022-23947HIGH A stack-based buffer overflow vulnerability exists in the Gerber Viewer gerber and excellon DCodeNumber parsing functionality of KiCad EDA 6.0.1 and master commit de006fc010. A spe | Feb 4, 2022 | 7.8 | 27 | NO | NO |
CVE-2022-23946HIGH A stack-based buffer overflow vulnerability exists in the Gerber Viewer gerber and excellon GCodeNumber parsing functionality of KiCad EDA 6.0.1 and master commit de006fc010. A spe | Feb 4, 2022 | 7.8 | 26 | NO | NO |
CVE-2022-23803HIGH A stack-based buffer overflow vulnerability exists in the Gerber Viewer gerber and excellon ReadXYCoord coordinate parsing functionality of KiCad EDA 6.0.1 and master commit de006f | Feb 16, 2022 | 7.8 | 20 | NO | NO |
Signals from CVEs in this vendor scope (4 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Kicad.
Media articles that mention a CVE ID that affects a product developed by Kicad — matched by CVE ID, not by vendor name.