Exposure monitor
Vulnerabilities
Automotive Vulnerabilities. Hunted worldwide every 24 hours, across 🇺🇸🇨🇳🇯🇵🇰🇷🇹🇼🇩🇪🇫🇷🇨🇭🇦🇹🇳🇱🇧🇪🇵🇱🇨🇦🇱🇺🇪🇺. Stay ahead.
1962advisories found
csaf_abbhigh · 7.8
9akk108472a9037
This vulnerability affects industrial control systems deployed in automotive manufacturing plants and assembly lines, specifically ABB Ability zenon software that bundles an outdated MongoDB database component. An attacker with network access could exploit known security flaws to access sensitive information, crash the system, or disrupt production line availability. While no active exploitation has been reported, the severity is significant because the outdated component is publicly known to be vulnerable and could allow unauthorized data theft or denial of service in manufacturing environments.
fkie_nvdhigh · 7.8
cve-2026-5056
GStreamer is a multimedia framework used in automotive infotainment systems for audio and video playback, and this vulnerability allows an attacker to remotely execute arbitrary code by sending a specially crafted media file that triggers a stack-based buffer overflow during parsing. An attacker could exploit this to take control of the infotainment system, potentially compromising vehicle functions or accessing sensitive data, and the severity is high due to the risk of remote code execution without authentication.
fkie_nvdhigh · 7.8
cve-2026-51273
This vulnerability affects the ESP32 chipset, which is widely used in automotive infotainment systems, telematics units, and aftermarket audio devices for Bluetooth and Wi-Fi audio streaming. An attacker could exploit a heap-based buffer overflow in the ID3 tag parsing function by sending a malicious audio file, potentially allowing them to execute arbitrary code, crash the device, or access sensitive data. This is a critical security issue that could compromise vehicle audio systems and connected services.
csaf_lenzesehigh · 7.8
vde-2026-077
This vulnerability affects industrial control systems deployed in automotive manufacturing plants and assembly lines, specifically Lenze Controllers and Servo Drives used in production equipment. A low-privileged attacker with local access can bypass the signature check on a file that enables SSH service access, potentially gaining full administrative control over the device and compromising the confidentiality, integrity, and availability of the manufacturing system. Lenze has released firmware updates to fix the issue, and as a temporary mitigation, operators should delete any activation files from the SD card and restrict physical and network access to the devices.
fkie_nvdhigh · 7.8
cve-2026-24238
NVIDIA TensorRT is a deep learning inference engine used in automotive AI systems for ADAS, autonomous driving perception, and in-cabin monitoring. This vulnerability could allow an attacker to execute arbitrary code by exploiting improper array index validation, potentially compromising vehicle safety functions. The severity is high, as successful exploitation could lead to full system compromise in vehicles using TensorRT for real-time AI processing.
fkie_nvdhigh · 7.8
cve-2026-24268
NVIDIA TensorRT is a deep learning inference engine used in automotive AI systems for ADAS, autonomous driving perception, and in-cabin monitoring. This heap-based buffer overflow vulnerability could allow an attacker to execute arbitrary code on the vehicle's AI compute platform, potentially compromising safety-critical functions. The severity is high, as it could lead to full system compromise if exploited.
fkie_nvdhigh · 7.8
cve-2026-24272
NVIDIA TensorRT is a deep learning inference engine used in automotive AI systems for ADAS, autonomous driving perception, and driver monitoring. This vulnerability could allow an attacker to trigger a heap-based buffer overflow, potentially leading to remote code execution on the vehicle's AI compute platform. The severity is high, as it could compromise safety-critical functions if exploited.
nvdhigh · 7.6
cve-2026-42804
A stack-based buffer overflow exists in the Bosch Sensortec BHI360 SensorAPI C-Library (versions up to and including commit d6b200416a), where the FIFO debug message parser trusts an attacker-supplied length byte and copies too many bytes into a fixed 17-byte stack buffer without bounds checking. An attacker with local or physical access, such as through a malicious sensor, counterfeit hardware module, or bus man-in-the-middle, could inject a crafted debug frame to corrupt stack memory and potentially execute arbitrary code on the host microcontroller or SoC, or cause a system crash. This could be relevant where the BHI360 SensorAPI is deployed in automotive systems, so confirm applicability through the product SBOM or dependency inventory.
cvelistv5high · 7.6
cve-2026-85197
A heap use-after-free vulnerability exists in libsoup's HTTP/2 client code, where a malicious server or man-in-the-middle attacker can trigger memory corruption by sending a GOAWAY frame while a file is being uploaded, potentially leading to information disclosure or arbitrary code execution. The flaw affects Red Hat Enterprise Linux versions 6 through 10. This could be relevant where libsoup is deployed in automotive systems, such as in GNOME-based infotainment or telematics applications, but the advisory does not confirm automotive use. Confirm applicability through the product SBOM or dependency inventory.
csaf_siemenshigh · 7.6
ssa-682041
The advisory describes a cross-site scripting vulnerability in the si-map component of the @siemens/maps-ng package, where an attacker can craft a malicious URL that executes arbitrary script code in a victim's browser when a map pin is hovered over. The affected component is a software package for rendering maps, and while it is not explicitly stated to be used in vehicles, this could be relevant where the package is deployed in automotive systems. Confirm applicability through the product SBOM or dependency inventory.
cvelistv5high · 7.6
cve-2026-80186
A vulnerability exists in BlueZ, the Linux Bluetooth protocol stack, where a remote attacker within Bluetooth range can send a specially crafted packet that overflows a buffer during device discovery. This can crash the Bluetooth service, causing a denial of service, and may allow the attacker to execute arbitrary code. This could be relevant where BlueZ is deployed in automotive systems for Bluetooth connectivity; confirm applicability through the product SBOM or dependency inventory.
cvelistv5high · 7.6
cve-2026-10685
This vulnerability affects the Bluetooth stack used in automotive hands-free calling, media streaming, and phone-as-a-key systems, specifically within the Zephyr RTOS that powers vehicle ECUs and telematics units. An attacker within Bluetooth range can trigger a use-after-free condition by sending a crafted error response during a GATT subscription, potentially causing memory corruption, system crashes, or arbitrary code execution in the vehicle’s Bluetooth host. This is a high-severity issue that could lead to denial of service or remote compromise of connected vehicle systems, and the fix requires updating the Zephyr Bluetooth stack to reorder callback handling.
fkie_nvdhigh · 7.6
cve-2026-16313
This vulnerability affects the Linux-based operating systems used in vehicle infotainment systems, telematics units, and diagnostic tools that rely on SCSI device management. An attacker who can connect a malicious USB or SCSI storage device to a vehicle system could inject arbitrary commands into the udev database, potentially executing code as root when the device is removed. This is a critical severity issue that could allow full system compromise of the affected automotive component.
csaf_cisahigh · 7.5
icsa-26-260-01
The Bransys ELD is affected by vulnerabilities including hardcoded MQTT and FTP credentials and cleartext transmission of sensitive information, which could allow an attacker to gain unauthorized read access to real-time telemetry data and firmware across affected devices. The advisory classifies this under the Transportation Systems sector, indicating a direct automotive/road-transport connection. CISA has not reported any known public exploitation of these vulnerabilities at this time. Confirm applicability through the product SBOM or dependency inventory.
nvdhigh · 7.5
cve-2026-63126
Wire is a data-format library used to encode and decode protocol buffer messages, and versions before 6.4.5 and 7.0.0-alpha04 fail to properly validate attacker-supplied length values, allowing malformed input to cause crashes or excessive memory use. An attacker who can send crafted protobuf data could trigger a denial of service, though the advisory states there is no known impact on confidentiality, integrity, or code execution. This could be relevant where Wire is deployed in automotive systems; confirm applicability through the product SBOM or dependency inventory.
nvdhigh · 7.5
cve-2026-85234
A flaw in tftp-hpa's in.tftpd remap engine can cause out-of-bounds read and write operations when it processes a specially crafted inverse remap rule with a non-empty custom error message. A remote, unauthenticated attacker could send a crafted request to crash the daemon, resulting in a denial of service. This could be relevant where tftp-hpa is deployed in automotive systems; confirm applicability through the product SBOM or dependency inventory.
cvelistv5high · 7.5
cve-2026-15891
Zephyr's MQTT-SN client contains a NULL pointer dereference that crashes or panics the device when a connected gateway stops responding to keepalive messages, a condition a malicious or compromised gateway can trigger remotely over unauthenticated UDP. The impact is a remotely triggerable denial of service affecting availability only, with no attacker-controlled data written. This could be relevant where Zephyr is deployed in automotive systems; confirm applicability through the product SBOM or dependency inventory.
cvelistv5high · 7.5
cve-2026-90678
HAProxy versions 3.3.0 through 3.4.4 and 3.5-dev1 through 3.5-dev5 contain a flaw that can occur when HAProxy is built with QUIC support and configured with an HTTP/3 frontend that forwards traffic to a backend over HTTP/1.1 using chunked transfer coding on a reused connection. Under those conditions, a remote unauthenticated attacker can cause HTTP request smuggling on reused backend connections, potentially bypassing frontend rules such as path-based deny rules and causing other clients' requests, including Authorization headers, to be lost; exploitation is not deterministic but can be retried freely. This could be relevant where HAProxy is deployed in automotive systems, for example as a load balancer or gateway in connected-vehicle, fleet, or EV-charging backends. Confirm applicability through the product SBOM or dependency inventory.
nvdhigh · 7.5
cve-2026-45765
Suricata, a network intrusion detection and prevention system, has a flaw in its DNP3 protocol handling that could let crafted network traffic cause excessive memory use and potentially a denial of service. The issue is fixed in versions 7.0.16 and 8.0.5, and disabling DNP3 or limiting reassembly depth can work around it. This could be relevant where Suricata is deployed in automotive systems, for example in vehicle network monitoring or automotive manufacturing environments. Confirm applicability through the product SBOM or dependency inventory.
csaf_opensusehigh · 7.5
rhsa-2026:65763
This advisory covers multiple vulnerabilities in GLib, a core software library. The most serious issue allows an unauthenticated attacker to send excessively long data streams to the GDBus component, causing denial of service through memory and CPU exhaustion, potentially crashing or hanging the system. Other flaws involve minor out-of-bounds reads that can cause small information disclosures or denial of service, and one issue allows a malicious D-Bus server to trick a client into reading arbitrary files. GLib is a general-purpose library, so this could be relevant where GLib is deployed in automotive systems; confirm applicability through the product SBOM or dependency inventory.
csaf_nozominetworkshigh · 7.5
nn-2026:20-01
The advisory describes a high-severity vulnerability in the Smart Polling feature of Nozomi Networks' Guardian/CMC products (before version 26.3.0) and Arc (before version 2.7.0). This feature establishes encrypted connections to target devices but fails to validate the remote host's certificate or host key, and there is no option to enable such validation. An attacker could potentially exploit this by impersonating a target device during these connections, undermining the security of the encrypted communication. Since these are industrial cybersecurity monitoring products used in operational technology environments, this could be relevant where they are deployed in automotive manufacturing or related industrial settings; confirm applicability through the product SBOM or dependency inventory.
cvelistv5high · 7.5
cve-2026-79377
A heap overflow vulnerability exists in the a2dp_decoder_sbc.cpp component of Bestechnic BES2300 Bluetooth Audio SoC firmware v3.x and earlier, which an attacker could exploit by sending a crafted L2CAP packet to cause a Denial of Service (DoS). The advisory does not confirm automotive deployment, but this could be relevant where the BES2300 SoC is used in automotive Bluetooth audio systems. Confirm applicability through the product SBOM or dependency inventory.
nvdhigh · 7.5
cve-2026-85516
The advisory reports a SQL injection vulnerability in the Vehicle Management System version 1.0 from code-projects, specifically in the file /busprofile.php. An attacker can remotely manipulate the "busid" argument to inject malicious SQL code, and the exploit has been publicly disclosed. The advisory does not state a severity rating, but the technical impact is that an attacker could potentially access or alter database information through this flaw.
cvelistv5high · 7.5
cve-2026-55784
free5GC is an open-source implementation of the 5G core network, and in version 1.4.4 and earlier, its AUSF component has a vulnerability where concurrent authentication requests for the same subscriber can overwrite the stored authentication context. An attacker with access to the AUSF interface could exploit this to cause authentication failures for a targeted subscriber, denying them service. This could be relevant where free5GC is deployed in automotive systems, such as for vehicle-to-network communications; confirm applicability through the product SBOM or dependency inventory.
cvelistv5high · 7.5
cve-2026-78002
A flaw in rsyslog allows an unauthenticated remote attacker to trigger a heap buffer overflow in the RainerScript replace() function by sending specially crafted syslog messages, leading to memory corruption and a denial of service. This affects multiple Red Hat Enterprise Linux versions. This could be relevant where rsyslog is deployed in automotive systems, as it is a generic logging component; confirm applicability through the product SBOM or dependency inventory.