Vulnerabilities

Summary — last 7 days

New vulnerabilities2,739▲ 32 vs. last week
Critical / high1,474▲ 364 vs. last week
New active exploitation (KEV)7▼ 3 vs. last week
Unscored (no CVSS)62▼ 464 vs. last week
–

32 results, sorted by published date (most recent first)

CVEStatusSeverityEPSS Active exploitationAffected technologiesPublished ▼Modified Description
AnalyzedHigh (7.8)0.19%—Openrobotics Robot Operating System7/17/20256/17/2026
A code execution vulnerability has been identified in the Robot Operating System (ROS) 'rosbag' tool, affecting ROS distributions Noetic Ninjemys and earlier. The vulnerability arises from the use of the eval() function to process unsanitized, user-supplied input in the 'rosbag filter' command. This flaw enables…
AnalyzedHigh (7.8)0.19%—Openrobotics Robot Operating System7/17/20256/17/2026
A code injection vulnerability has been discovered in the Robot Operating System (ROS) 'rostopic' command-line tool, affecting ROS distributions Noetic Ninjemys and earlier. The vulnerability lies in the 'echo' verb, which allows a user to introspect a ROS topic and accepts a user-provided Python expression via the…
AnalyzedHigh (7.8)0.19%—Openrobotics Robot Operating System7/17/20256/17/2026
A code injection vulnerability has been discovered in the Robot Operating System (ROS) 'rostopic' command-line tool, affecting ROS distributions Noetic Ninjemys and earlier. The vulnerability lies in the 'hz' verb, which reports the publishing rate of a topic and accepts a user-provided Python expression via the…
AnalyzedHigh (7.8)0.18%—Openrobotics Robot Operating System7/17/20256/17/2026
A code injection vulnerability has been identified in the Robot Operating System (ROS) 'roslaunch' command-line tool, affecting ROS distributions Noetic Ninjemys and earlier. The vulnerability arises from the use of the eval() method to process user-supplied, unsanitized parameter values within the substitution args…
AnalyzedHigh (7.8)0.18%—Openrobotics Robot Operating System7/17/20256/17/2026
A code execution vulnerability has been discovered in the Robot Operating System (ROS) 'rosparam' tool, affecting ROS distributions Noetic Ninjemys and earlier. The vulnerability stems from the use of the eval() function to process unsanitized, user-supplied parameter values via special converters for angle…
AnalyzedCritical (9.8)0.39%—Openrobotics Robot Operating System4/2/20256/17/2026
A YAML deserialization vulnerability was found in the Robot Operating System (ROS) 'dynparam', a command-line tool for getting, setting, and deleting parameters of a dynamically configurable node, affecting ROS distributions Noetic and earlier. The issue is caused by the use of the yaml.load() function in the 'set'…
AnalyzedHigh (7.5)0.59%—Openrobotics Robot Operating System12/6/20246/17/2026
Open Robotics Robotic Operating System 2 ROS2 navigation2 v.humble was discovered to contain a NULL pointer dereference via the component nav2_smac_planner().
AnalyzedHigh (7.5)0.59%—Openrobotics Robot Operating System12/6/20246/17/2026
Open Robotics Robotic Operating System 2 ROS2 navigation2 v.humble was discovered to contain a NULL pointer dereference via the component nav2_navfn_planner().
AnalyzedHigh (7.5)0.59%—Openrobotics Robot Operating System12/6/20246/17/2026
Open Robotics Robotic Operating System 2 ROS2 navigation2 v.humble was discovered to contain a NULL pointer dereference via the component smoothPlan().
AnalyzedHigh (7.5)0.59%—Openrobotics Robot Operating System12/6/20246/17/2026
Open Robotics Robotic Operating System 2 ROS2 navigation2 v.humble was discovered to contain a NULL pointer dereference via the component computeControl().
AnalyzedCritical (9.8)0.60%—Openrobotics Robot Operating System12/6/20246/17/2026
Open Robotics Robotic Operating System 2 ROS2 navigation2 v.humble was discovered to contain a segmentation violation via the component theta_star::ThetaStar::isUnsafeToPlan().
AnalyzedCritical (9.8)0.48%—Openrobotics Robot Operating System12/6/20246/17/2026
Insecure Permissions vulnerability in Open Robotics Robotic Operating System 2 ROS2 navigation2 v.humble allows an attacker to execute arbitrary code via a crafted script to the nav2_costmap_2d.
AnalyzedCritical (9.8)0.70%—Openrobotics Robot Operating System12/6/20246/17/2026
Insecure Permissions vulnerability in Open Robotics Robotic Operating System 2 ROS2 navigation2 v.humble allows an attacker to execute arbitrary code via a crafted script to the executor_thread_.
AnalyzedCritical (9.8)0.48%—Openrobotics Robot Operating System12/6/20246/17/2026
Insecure Permissions vulnerability in Open Robotics Robotic Operating System 2 ROS2 navigation2 v.humble allows an attacker to execute arbitrary code via a crafted script to the nav2_regulated_pure_pursuit_controller.
AnalyzedCritical (9.8)0.70%—Openrobotics Robot Operating System12/6/20246/17/2026
Insecure Permissions vulnerability in Open Robotics Robotic Operating System 2 ROS2 navigation2 v.humble allows an attacker to execute arbitrary code via a crafted script to the nav2_mppi_controller.
AnalyzedCritical (9.8)0.70%—Openrobotics Robot Operating System12/6/20246/17/2026
Insecure Permissions vulnerability in Open Robotics Robotic Operating System 2 ROS2 navigation2 v.humble allows an attacker to execute arbitrary code via a crafted script to the nav2_dwb_controller.
AnalyzedCritical (9.8)0.70%—Openrobotics Robot Operating System12/6/20246/17/2026
Insecure Permissions vulnerability in Open Robotics Robotic Operating System 2 ROS2 navigation2 v.humble allows an attacker to execute arbitrary code via a crafted script to the nav2__amcl.
AnalyzedCritical (9.8)0.70%—Openrobotics Robot Operating System12/6/20246/17/2026
Insecure Permissions vulnerability in Open Robotics Robotic Operating System 2 ROS2 navigation2 v.humble allows an attacker to execute arbitrary code via the dyn_param_handler_ component.
AnalyzedCritical (9.8)0.59%—Openrobotics Robot Operating System12/6/20246/17/2026
Open Robotics Robotic Operating System 2 (ROS2) and Nav2 humble versions were discovered to contain a use-after-free via the nav2_amcl process. This vulnerability is triggered via remotely sending a request to change the value of dynamic-parameter `/amcl do_beamskip`.
AnalyzedCritical (9.8)0.59%—Openrobotics Robot Operating System12/6/20246/17/2026
Open Robotics Robotic Operating System 2 (ROS2) and Nav2 humble versions were discovered to contain a use-after-free via the nav2_amcl process. This vulnerability is triggered via remotely sending a request for change the value of dynamic-parameter `/amcl z_short`.
AnalyzedCritical (9.8)0.59%—Openrobotics Robot Operating System12/6/20246/17/2026
Open Robotics Robotic Operating System 2 (ROS2) and Nav2 humble versions were discovered to contain a use-after-free via the nav2_amcl process. This vulnerability is triggered via remotely sending a request for change the value of dynamic-parameter`/amcl z_max` .
AnalyzedCritical (9.8)0.55%—Openrobotics Robot Operating System12/6/20246/17/2026
Open Robotics Robotic Operating System 2 (ROS2) and Nav2 humble versions were discovered to contain a use-after-free via the nav2_amcl process. This vulnerability is triggered via remotely sending a request to change the value of dynamic-parameter`/amcl laser_model_type` .
AnalyzedCritical (9.8)0.55%—Openrobotics Robot Operating System12/6/20246/17/2026
Open Robotics Robotic Operating System 2 (ROS2) and Nav2 humble versions were discovered to contain a use-after-free via the nav2_amcl process. This vulnerability is triggered via remotely sending a request to change the value of dynamic-parameter`/amcl odom_frame_id` .
AnalyzedCritical (9.8)0.59%—Openrobotics Robot Operating System12/6/20246/17/2026
Open Robotics Robotic Operating System 2 (ROS2) and Nav2 humble version was discovered to contain a heap overflow in the nav2_amcl process. This vulnerability is triggered via sending a crafted message to the component /initialpose.
AnalyzedCritical (9.8)0.60%—Openrobotics Robot Operating System12/6/20246/17/2026
Open Robotics Robotic Operating System 2 (ROS2) and Nav2 humble versions were discovered to contain a use-after-free via the nav2_amcl process. This vulnerability is triggered via remotely sending a request for change the value of dynamic-parameter`/amcl z_rand ` .