Exposure monitor

Vulnerabilities

Automotive Vulnerabilities. Hunted worldwide every 24 hours, across πŸ‡ΊπŸ‡ΈπŸ‡¨πŸ‡³πŸ‡―πŸ‡΅πŸ‡°πŸ‡·πŸ‡ΉπŸ‡ΌπŸ‡©πŸ‡ͺπŸ‡«πŸ‡·πŸ‡¨πŸ‡­πŸ‡¦πŸ‡ΉπŸ‡³πŸ‡±πŸ‡§πŸ‡ͺπŸ‡΅πŸ‡±πŸ‡¨πŸ‡¦πŸ‡±πŸ‡ΊπŸ‡ͺπŸ‡Ί. Stay ahead.

1962advisories found
Clear filters
Results
cvelistv5high

cve-2026-74660

cvelistv5high

cve-2026-74656

This advisory addresses a use-after-free vulnerability in the Linux kernel's IPv4 routing code, specifically in the function fib_nhc_update_mtu(). An attacker could potentially exploit this flaw to cause memory corruption or a system crash, though the advisory does not state a specific severity rating. This could be relevant where Linux-based systems are deployed in automotive environments, such as infotainment or telematics units, but the advisory does not confirm any automotive impact. Confirm applicability through the product SBOM or dependency inventory.

cvelistv5high

cve-2026-74649

The advisory addresses a missing shared-key authentication challenge length check in the rtl8723bs Wi-Fi driver, which could allow an attacker to exploit this flaw. The technical impact is not detailed in the advisory, and no severity rating is provided. This could be relevant where the rtl8723bs driver is deployed in automotive systems, such as in infotainment or telematics units, but the advisory does not confirm automotive use. Confirm applicability through the product SBOM or dependency inventory.

cvelistv5high

cve-2026-74648

The advisory addresses a vulnerability in the Linux kernel's rtl8723bs driver, specifically a missing validation of monitor transmit frame lengths. An attacker could exploit this flaw to cause undefined behavior or a system crash, with the severity not explicitly stated in the provided text. This could be relevant where the rtl8723bs driver is deployed in automotive systems, such as for Wi-Fi connectivity in infotainment or telematics units, but the advisory does not confirm automotive use. Confirm applicability through the product SBOM or dependency inventory.

cvelistv5high

cve-2026-74640

cvelistv5high

cve-2026-74639

cvelistv5high

cve-2026-74637

This advisory addresses a use-after-free vulnerability in the Linux kernel's performance event subsystem, specifically when a group leader is detached from its sibling events. An attacker could potentially exploit this flaw to cause memory corruption, leading to system instability or privilege escalation. The severity is not explicitly stated in the advisory. This could be relevant where the Linux kernel is deployed in automotive systems, such as in infotainment or control units. Confirm applicability through the product SBOM or dependency inventory.

cvelistv5high

cve-2026-74629

cvelistv5high

cve-2026-74589

This advisory addresses a use-after-free vulnerability in the Linux kernel's BPF sockmap functionality, which could allow an attacker to exploit a flaw in the send verdict path. The technical impact is that an attacker could potentially cause memory corruption or a system crash, with the severity not explicitly stated in the provided text. This could be relevant where the Linux kernel is deployed in automotive systems, such as in infotainment or telematics units, but the advisory does not confirm automotive use; confirm applicability through the product SBOM or dependency inventory.

cvelistv5high

cve-2026-74587

This advisory addresses a use-after-free vulnerability in the Linux kernel's SCTP networking component, specifically involving cached ASCONF chunks. An attacker could potentially exploit this flaw to cause memory corruption or a system crash, with the severity not explicitly stated in the provided text. This could be relevant where the Linux kernel with SCTP is deployed in automotive systems, such as for in-vehicle networking or telematics, but the advisory does not confirm automotive use. Confirm applicability through the product SBOM or dependency inventory.

cvelistv5high

cve-2026-74583

This advisory addresses a use-after-free vulnerability in the Linux kernel's network traffic classifier (cls_route), where an attacker could potentially exploit the flaw to cause memory corruption or a system crash. The affected component is part of the Linux kernel, which could be relevant where this kernel is deployed in automotive systems, such as in-vehicle infotainment or telematics units. Confirm applicability through the product SBOM or dependency inventory.

certfr_avishigh

certfr-2026-avi-1066

certfr_avishigh

certfr-2026-avi-1065

certfr_avishigh

certfr-2026-avi-1064

certfr_avishigh

certfr-2026-avi-1069

certfr_avishigh

certfr-2026-avi-1068

cvelistv5high

cve-2026-76023

cvelistv5high

cve-2026-74578

cvelistv5medium Β· 6.9

cve-2026-85517

The advisory describes a vulnerability in the Vehicle Management System version 1.0, specifically involving its SQL database backup file. An attacker can remotely access this file to disclose sensitive information. The severity is not explicitly rated, but the exploit has been published, and the affected product is directly related to automotive vehicle management.

cvelistv5medium Β· 6.9

cve-2026-82550

Linux Foundation Magma version 1.9.0 contains a security flaw in its NGSetupRequest Handler, specifically involving improper input validation of the NG-IoT-DefaultPagingDRX argument, which could be exploited remotely by an attacker. The vulnerability has been publicly disclosed, and the project has not yet responded to the issue report. This could be relevant where Magma is deployed in automotive or road-transport systems, as it is a network core platform, but the advisory does not confirm automotive use; confirm applicability through the product SBOM or dependency inventory.

cvelistv5medium Β· 6.9

cve-2026-82547

Linux Foundation Magma 1.9.0 contains a vulnerability in its Registration Complete Message Handler, specifically in the file tasks/amf/amf_fsm.cpp, which involves improper authentication. An attacker can exploit this remotely, and the exploit has been publicly disclosed, potentially allowing unauthorized access or actions. This could be relevant where Magma is deployed in automotive systems, such as in fleet or telematics networks, but the advisory does not confirm automotive use; confirm applicability through the product SBOM or dependency inventory.

cvelistv5medium Β· 6.9

cve-2026-62381

luci-lib-px5g, a component of the OpenWrt LuCI web interface, contains a heap-based buffer overflow in its certificate-signing code when handling a 2040-bit RSA key, causing a one-byte write beyond the allocated memory. An attacker could potentially exploit this through the Lua interface, though remote exploitability depends on how the application embeds it. This could be relevant where OpenWrt LuCI is deployed in automotive systems, such as routers or gateways in vehicles; confirm applicability through the product SBOM or dependency inventory.

nvdmedium Β· 6.9

cve-2026-74871

openssl_encrypt versions before 1.4.6 have a key derivation flaw in sequential XOR mode where the last stage cancels out, allowing attackers to bypass memory-hard key derivation and crack passwords offline at SHA-256 speed instead of the intended cost. This could be relevant where openssl_encrypt is deployed in automotive systems, such as for securing embedded data or communications, but the advisory does not confirm automotive use. Confirm applicability through the product SBOM or dependency inventory.

fkie_nvdmedium Β· 6.9

cve-2026-53551

This vulnerability affects the 5G core network infrastructure used in automotive telematics and connected vehicle services, specifically the free5GC Authentication Server Function (AUSF) that handles subscriber authentication for cellular connectivity. An unauthenticated attacker can send malformed authentication requests containing null bytes, causing the system to crash with HTTP 500 errors and leak internal stack traces, which can be exploited at scale to deny service to all vehicles attempting to authenticate on the network. The severity is high because it enables a denial-of-service attack on the entire subscriber base, though it is fixed in version 1.4.5 and requires immediate patching of affected 5G core deployments.

cvelistv5medium Β· 6.9

cve-2026-56758

This vulnerability affects the IEC 61850 communication protocol library used in electric vehicle charging stations, substation automation, and smart grid systems that manage vehicle-to-grid energy transfer. An attacker could send a specially crafted connection request to trigger an out-of-bounds read, potentially causing a denial of service or leaking sensitive memory contents from the device. The severity is high because it could disrupt charging infrastructure or grid communication systems that vehicles rely on for energy management.