Exposure monitor

Vulnerabilities

Automotive Vulnerabilities. Hunted worldwide every 24 hours, across πŸ‡ΊπŸ‡ΈπŸ‡¨πŸ‡³πŸ‡―πŸ‡΅πŸ‡°πŸ‡·πŸ‡ΉπŸ‡ΌπŸ‡©πŸ‡ͺπŸ‡«πŸ‡·πŸ‡¨πŸ‡­πŸ‡¦πŸ‡ΉπŸ‡³πŸ‡±πŸ‡§πŸ‡ͺπŸ‡΅πŸ‡±πŸ‡¨πŸ‡¦πŸ‡±πŸ‡ΊπŸ‡ͺπŸ‡Ί. Stay ahead.

1962advisories found
Clear filters
Results
cvelistv5low

cve-2026-80551

The advisory addresses a vulnerability in the Linux kernel's s390/vfio_ccw component, which handles I/O for virtualized channel subsystems on IBM mainframes. An attacker could potentially exploit inconsistent data reads to cause a security issue, though the advisory does not specify a severity rating. This could be relevant where the Linux kernel with s390/vfio_ccw is deployed in automotive systems, such as in backend infrastructure, but the advisory does not confirm any automotive use. Confirm applicability through the product SBOM or dependency inventory.

cvelistv5low

cve-2026-80547

The advisory addresses a fix in the Linux kernel for the s390/vfio_ccw component, which manages channel I/O for virtualized devices on IBM mainframes. The vulnerability involves a lack of locking for the CRW (Channel Report Word) region, which relies on asynchronous hardware events, potentially allowing an attacker to read inconsistent or corrupted data. This could be relevant where s390/vfio_ccw is deployed in automotive systems, such as in backend infrastructure or specialized embedded controllers, but the advisory does not confirm automotive use. Confirm applicability through the product SBOM or dependency inventory.

cvelistv5low

cve-2026-74722

This advisory addresses a memory leak in the btrfs filesystem, specifically in the function btrfs_do_encoded_write(). An attacker could potentially exploit this flaw to cause a denial of service by exhausting system memory. The severity is not explicitly stated in the advisory. This could be relevant where btrfs is deployed in automotive systems, such as in infotainment or telematics units using Linux. Confirm applicability through the product SBOM or dependency inventory.

cvelistv5low

cve-2026-74717

This advisory addresses a bug in the Linux kernel's mlx5 network driver, specifically in its firmware tracer component, where an error during creation is not properly handled and could return an incorrect value. An attacker could potentially exploit this flaw to cause a system crash or other undefined behavior, though the advisory does not state a specific severity rating. This could be relevant where the mlx5 driver is deployed in automotive systems, such as in vehicles using certain network hardware, but the advisory does not confirm automotive use; confirm applicability through the product SBOM or dependency inventory.

cvelistv5low

cve-2026-74704

This advisory addresses a vulnerability in the Linux kernel's network scheduler component, specifically the sch_cake packet scheduler, where a WARN_ON(1) assertion can be triggered by malformed packets in the ACK filter. An attacker could exploit this to cause a kernel warning, potentially leading to a denial-of-service condition by disrupting network packet processing. The severity is not explicitly stated in the advisory, but the issue affects the Linux kernel, which could be relevant where sch_cake is deployed in automotive systems, such as in-vehicle networking or telematics; confirm applicability through the product SBOM or dependency inventory.

cvelistv5low

cve-2026-74699

cvelistv5low

cve-2026-74685

cvelistv5low

cve-2026-74679

This advisory addresses a Linux kernel vulnerability in the USB gadget function driver f_ncm, specifically involving the use of an unsigned integer for the ndp_index parameter. An attacker could potentially exploit this issue to cause undefined behavior or a security issue in systems using this driver. This could be relevant where the Linux USB gadget f_ncm driver is deployed in automotive systems, such as for USB-based connectivity in infotainment or telematics units. Confirm applicability through the product SBOM or dependency inventory.

cvelistv5low

cve-2026-74653

This advisory addresses a fix in the Linux kernel for the serial 8250 driver, specifically clearing a stuck empty-FIFO RX-timeout condition on the LPC32xx platform. An attacker could potentially exploit this bug to disrupt serial communication, though the advisory does not state a severity rating. This could be relevant where the LPC32xx serial driver is deployed in automotive systems, such as in embedded control units, but the advisory does not confirm automotive use. Confirm applicability through the product SBOM or dependency inventory.

cvelistv5low

cve-2026-74619

This advisory addresses a Linux kernel issue where a warning is suppressed when a mount operation is completed from a different user namespace. An attacker could potentially exploit this to perform unauthorized mount operations, leading to system instability or privilege escalation. The severity is not explicitly stated in the provided text. This could be relevant where the Linux kernel is deployed in automotive systems, such as in-vehicle infotainment or control units. Confirm applicability through the product SBOM or dependency inventory.

cvelistv5low

cve-2026-74603

This advisory addresses a fix in the Linux kernel for a board ID over-read issue in the ptp: ocp component. An attacker could potentially exploit this flaw to read beyond the intended memory boundary, leading to information disclosure. The severity is not explicitly stated in the advisory. This could be relevant where the ptp: ocp component is deployed in automotive systems, such as in time-synchronization hardware for vehicle networks. Confirm applicability through the product SBOM or dependency inventory.

cvelistv5low

cve-2026-74604

This advisory describes a revert of a coding style cleanup in the Linux kernel's thermal and hardware monitoring drivers, with no specific vulnerability or security impact stated. The affected component is a generic kernel driver that could be used in various systems, but the advisory does not confirm any automotive deployment. This could be relevant where Linux kernel thermal drivers are deployed in automotive systems; confirm applicability through the product SBOM or dependency inventory.

certfr_avisunknown

certfr-2026-avi-0989

Not generated β€” advisory text was unavailable or too brief.

csaf_microsoftunknown

cve-2026-64573

Not generated β€” advisory text was unavailable or too brief.

csaf_microsoftunknown

cve-2026-64574

Not generated β€” advisory text was unavailable or too brief.

cvelistv5unknown

cve-2026-68081

Not generated β€” advisory text was unavailable or too brief.

certfr_avisunknown

certfr-2026-avi-0981

Not generated β€” advisory text was unavailable or too brief.

certfr_avisunknown

certfr-2026-avi-0982

Not generated β€” advisory text was unavailable or too brief.

certfr_avisunknown

certfr-2026-avi-0985

Not generated β€” advisory text was unavailable or too brief.

NVDunknown

CVE-2026-16578

CVE-2026-16578 is a missing authorization vulnerability in the Admin Safety Guard WordPress plugin, allowing unauthenticated attackers to enumerate all registered users and their sensitive details. In automotive contexts, this could expose customer and employee information, undermining security and privacy compliance. Immediate patching to version 1.4.0 or later is recommended.

Admin Safety Guard Admin Safety Guard β€” Login Security, Limit Logins, 2FA & Brute Force Protection
githubunknown

ghsa-28fc-4vwx-pr32

Not generated β€” advisory text was unavailable or too brief.

githubunknown

ghsa-2x99-3h9h-f4c9

Not generated β€” advisory text was unavailable or too brief.

githubunknown

ghsa-3qwv-9mh7-f8fm

Not generated β€” advisory text was unavailable or too brief.

githubunknown

ghsa-4vgx-hp6g-jmm8

Not generated β€” advisory text was unavailable or too brief.

githubunknown

ghsa-5rg4-8h2h-x94w

Not generated β€” advisory text was unavailable or too brief.