Yocto
Vendor:
First CVE: Oct 7, 2022 · Active for 3 years
114
Total CVEs
More Total CVEs than 99% of tracked products
22.8
Avg CVEs / Year
Higher CVE frequency than 99% of tracked products
6.2
Avg CVSS
Higher Avg CVSS than 25% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Yocto over time
Volume of CVEsAvg CVSS Base Score
First CVE
Oct 7, 2022
3 years ago
Most Recent CVE
Mar 9, 2026
137 days ago
CVE Severity & Scoring
Yocto114 CVEs
82%
14%
All CVEs352,294 CVEs
45%
40%
11%
LowMediumHighCritical
Attack Vector
Local85 (74.6%)
Network16 (14.0%)
Unknown0 (0.0%)
Physical9 (7.9%)
Adjacent Network4 (3.5%)
Attack Complexity
Low107 (93.9%)
High7 (6.1%)
Unknown0 (0.0%)
User Interaction
None93 (81.6%)
Unknown0 (0.0%)
Required21 (18.4%)
Privileges Required
Low5 (4.4%)
High78 (68.4%)
None31 (27.2%)
Unknown0 (0.0%)
Top CVEs
Signals from CVEs in this product scope (114 CVEs).
114 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2024-20148CRITICAL In wlan STA FW, there is a possible out of bounds write due to improper input validation. This could lead to remote (proximal/adjacent) code execution with no additional execution | Jan 6, 2025 | 9.8 | 27 | NO | NO |
CVE-2025-61611HIGH In modem, there is a possible improper input validation. This could lead to remote denial of service with no additional execution privileges needed.. | Mar 9, 2026 | 7.5 | 26 | NO | NO |
CVE-2025-20705HIGH In monitor_hang, there is a possible memory corruption due to use after free. This could lead to local escalation of privilege if a malicious actor has already obtained the System | Sep 1, 2025 | 7.8 | 26 | NO | NO |
CVE-2024-20080CRITICAL In gnss service, there is a possible escalation of privilege due to improper certificate validation. This could lead to remote escalation of privilege with no additional execution | Jul 1, 2024 | 9.8 | 26 | NO | NO |
CVE-2025-20747MEDIUM In gnss service, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local escalation of privilege if a malicious actor has already obtaine | Nov 4, 2025 | 6.7 | 24 | NO | NO |
CVE-2025-20696MEDIUM In DA, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege, if an attacker has physical access to the device, wi | Aug 4, 2025 | 6.8 | 24 | NO | NO |
CVE-2024-20146HIGH In wlan STA driver, there is a possible out of bounds write due to improper input validation. This could lead to remote (proximal/adjacent) code execution with no additional execut | Jan 6, 2025 | 8.1 | 24 | NO | NO |
CVE-2024-20104HIGH In da, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User | Nov 4, 2024 | 8.4 | 24 | NO | NO |
CVE-2024-20040HIGH In wlan firmware, there is a possible out of bounds write due to improper input validation. This could lead to remote escalation of privilege with no additional execution privilege | Apr 1, 2024 | 8.8 | 24 | NO | NO |
CVE-2024-25626CRITICAL Yocto Project is an open source collaboration project that helps developers create custom Linux-based systems regardless of the hardware architecture. In Yocto Projects Bitbake bef | Feb 19, 2024 | 9.8 | 24 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (114 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%
Social Chatter
Signals from CVEs in this product scope (114 CVEs).
Media Mentions
Signals from CVEs in this product scope (114 CVEs).
Top CNAs Publishing CVEs For Yocto
Top CWEs
Versions
| Version | CVE Count | Avg CVSS | Avg EPSS | KEV | Exploits |
|---|---|---|---|---|---|
| 5.0 | 7 | 6.9 | 0.2% | 0 | 0 |
| 4.0 | 86 | 6.4 | 0.2% | 0 | 0 |
| 3.3 | 39 | 6.0 | 0.1% | 0 | 0 |
| 3.1 | 13 | 5.7 | 0.2% | 0 | 0 |
| 2.6 | 20 | 6.1 | 0.1% | 0 | 0 |