Yocto

Vendor:

First CVE: Oct 7, 2022 · Active for 3 years

114
Total CVEs
More Total CVEs than 99% of tracked products
22.8
Avg CVEs / Year
Higher CVE frequency than 99% of tracked products
6.2
Avg CVSS
Higher Avg CVSS than 25% of tracked products
0.0%
KEV Rate
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact Yocto over time

Volume of CVEsAvg CVSS Base Score
First CVE
Oct 7, 2022
3 years ago
Most Recent CVE
Mar 9, 2026
137 days ago

CVE Severity & Scoring

Yocto114 CVEs
All CVEs352,294 CVEs
LowMediumHighCritical
Attack Vector
Local85 (74.6%)
Network16 (14.0%)
Unknown0 (0.0%)
Physical9 (7.9%)
Adjacent Network4 (3.5%)
Attack Complexity
Low107 (93.9%)
High7 (6.1%)
Unknown0 (0.0%)
User Interaction
None93 (81.6%)
Unknown0 (0.0%)
Required21 (18.4%)
Privileges Required
Low5 (4.4%)
High78 (68.4%)
None31 (27.2%)
Unknown0 (0.0%)

Top CVEs

Signals from CVEs in this product scope (114 CVEs).

114 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
In wlan STA FW, there is a possible out of bounds write due to improper input validation. This could lead to remote (proximal/adjacent) code execution with no additional execution
Jan 6, 20259.827NONO
In modem, there is a possible improper input validation. This could lead to remote denial of service with no additional execution privileges needed..
Mar 9, 20267.526NONO
In monitor_hang, there is a possible memory corruption due to use after free. This could lead to local escalation of privilege if a malicious actor has already obtained the System
Sep 1, 20257.826NONO
In gnss service, there is a possible escalation of privilege due to improper certificate validation. This could lead to remote escalation of privilege with no additional execution
Jul 1, 20249.826NONO
In gnss service, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local escalation of privilege if a malicious actor has already obtaine
Nov 4, 20256.724NONO
In DA, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege, if an attacker has physical access to the device, wi
Aug 4, 20256.824NONO
In wlan STA driver, there is a possible out of bounds write due to improper input validation. This could lead to remote (proximal/adjacent) code execution with no additional execut
Jan 6, 20258.124NONO
In da, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User
Nov 4, 20248.424NONO
In wlan firmware, there is a possible out of bounds write due to improper input validation. This could lead to remote escalation of privilege with no additional execution privilege
Apr 1, 20248.824NONO
Yocto Project is an open source collaboration project that helps developers create custom Linux-based systems regardless of the hardware architecture. In Yocto Projects Bitbake bef
Feb 19, 20249.824NONO

Exploit Exposure

Signals from CVEs in this product scope (114 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

Signals from CVEs in this product scope (114 CVEs).

Media Mentions

Signals from CVEs in this product scope (114 CVEs).

Top CNAs Publishing CVEs For Yocto

Top CWEs

Versions

VersionCVE CountAvg CVSSAvg EPSSKEVExploits
5.076.90.2%00
4.0866.40.2%00
3.3396.00.1%00
3.1135.70.2%00
2.6206.10.1%00