Exposure monitor
Vulnerabilities
Automotive Vulnerabilities. Hunted worldwide every 24 hours, across πΊπΈπ¨π³π―π΅π°π·πΉπΌπ©πͺπ«π·π¨ππ¦πΉπ³π±π§πͺπ΅π±π¨π¦π±πΊπͺπΊ. Stay ahead.
1962advisories found
nvdhigh Β· 7.1
cve-2026-52851
Traccar, an open source GPS tracking system, has a flaw before version 6.14.0 where a logged-in user with write access can send a crafted request to the permissions endpoint that lets them extract sensitive database contents, including administrator email addresses, password hashes, and salts, or delete permission records. The issue is fixed in version 6.14.0. This could be relevant where Traccar is deployed in automotive or fleet-tracking systems, since it handles vehicle location data. Confirm applicability through the product SBOM or dependency inventory.
nvdhigh Β· 7.1
cve-2026-73175
Advantech EKI-1242EIMS firmware V1.06.01 contains an uncontrolled resource consumption flaw in its OPC UA gateway component, which an adjacent unauthenticated attacker can exploit by opening multiple anonymous sessions to exhaust the server session pool and cause a complete denial of service for all legitimate OPC UA clients. This could be relevant where the Advantech EKI-1242EIMS is deployed in automotive systems. Confirm applicability through the product SBOM or dependency inventory.
cvelistv5high Β· 7.1
cve-2026-90648
The WebAssembly wabt tool's wasm2c component, through version 1.0.41, fails to check a memory allocation result, which on some 32-bit platforms can let an attacker read and write host process memory and potentially execute arbitrary code, escaping the sandbox wasm2c is meant to provide. This could be relevant where wasm2c is deployed in automotive systems, since it is used as an in-process sandboxing boundary by RLBox and WasmBoxC, including in Firefox for isolating untrusted font, media, and XML input. Confirm applicability through the product SBOM or dependency inventory.
nvdhigh Β· 7.1
cve-2026-78807
A flaw in wpa_supplicant versions before 2.12 lets a local attacker bypass proper network context and AKMP matching for PMKSA caching because of missing validation in the driver-based PMKSA selection path in wpa.c. This could be relevant where wpa_supplicant is deployed in automotive systems, since it is a common Wi-Fi supplicant in embedded and in-vehicle connectivity stacks. Confirm applicability through the product SBOM or dependency inventory.
csaf_cisahigh Β· 7.1
icsa-26-211-07
This vulnerability affects the CC-Link IE TSN industrial communication protocol used in automotive manufacturing plants and assembly lines for real-time control of robots, conveyors, and other production equipment. An attacker on the same network segment could tamper with control data or cause a denial-of-service condition by sending specially crafted packets, potentially disrupting vehicle production or causing equipment to malfunction. The vulnerability is rated as high severity and affects critical manufacturing infrastructure deployed worldwide.
cvelistv5high Β· 7.1
cve-2026-66720
This vulnerability affects the IEC 61850 GOOSE protocol used in substation automation and electric vehicle charging infrastructure for real-time communication between grid equipment and charging stations. An attacker can send a specially crafted network message with a malformed timestamp to trigger a crash in the receiving system, causing a denial-of-service condition that could disrupt charging operations or grid communication. The vulnerability is rated as high severity because it requires no authentication and can be exploited remotely over the network.
cvelistv5high Β· 7.1
cve-2026-66369
This vulnerability affects the GOOSE protocol parser used in IEC 61850-based substation automation systems, which are deployed in electric vehicle charging infrastructure and automotive manufacturing plant power distribution networks. An unauthenticated attacker can send a single malicious Layer-2 multicast frame to trigger an out-of-bounds read, causing the subscriber process to crash and resulting in a denial-of-service condition. The severity is high because it requires no authentication and can disrupt critical industrial control systems in automotive production environments.
nvdhigh Β· 7.1
cve-2026-66364
This vulnerability affects the IEC 61850 GOOSE protocol implementation used in substation automation and electric vehicle charging infrastructure for real-time communication between protection relays and control systems. An unauthenticated attacker on the local network can send a single malicious multicast frame that causes the protocol parser to read one byte beyond its buffer, crashing the subscriber process and causing a denial-of-service condition. This is a high-severity issue because it can disrupt critical power grid and EV charging operations without any authentication required.
cvelistv5high Β· 7.1
cve-2026-65421
This vulnerability affects the IEC 61850 communication protocol used in electric vehicle charging stations and smart grid infrastructure for vehicle-to-grid energy management. An attacker can send a specially crafted message to crash the MMS service, causing a denial-of-service condition that could disrupt charging operations or grid communication. This is a high-severity issue that could impact the availability of EV charging infrastructure and related energy management systems.
cvelistv5high Β· 7.1
cve-2026-63550
This vulnerability affects the IEC 61850 communication protocol stack used in electric vehicle charging stations, substation automation, and grid-connected energy management systems within automotive manufacturing plants. An attacker can send a specially crafted message over TCP port 102 to trigger a heap out-of-bounds read, causing the MMS handling process to crash and resulting in a denial-of-service condition. This is a high-severity issue that could disrupt charging infrastructure or factory automation systems, though it requires network access to the affected device.
fkie_nvdhigh Β· 7.1
cve-2026-50103
This vulnerability affects the GOOSE protocol parser used in substation automation systems that may be deployed in electric vehicle charging infrastructure and smart grid connectivity for fleet depots. A network-adjacent attacker could crash a subscribing application by sending a specially crafted GOOSE frame with a malformed TLV value, causing a denial of service. The severity is high because it can disrupt critical communication between charging stations and grid management systems.
nvdhigh Β· 7.0
cve-2026-93015
BlueKitchen BTstack through 1.8.2 contains an out-of-bounds write in its A2DP stream endpoint discovery, where a bonded peer can report more endpoints than the fixed table holds, corrupting adjacent static objects and crashing the process or severing event delivery. This could be relevant where BTstack is deployed in automotive systems, for example in Bluetooth audio or telematics components. Confirm applicability through the product SBOM or dependency inventory.
nvdhigh Β· 7.0
cve-2026-78409
util-linux, a set of system utilities, contains a vulnerability in its X-mount.subdir option on Linux 6.15 and later. A local unprivileged user with an authorized mount entry could exploit this flaw to attach a host path at the intended mountpoint, potentially escaping the intended directory boundaries. This could be relevant where util-linux is deployed in automotive systems, such as in embedded Linux environments; confirm applicability through the product SBOM or dependency inventory.
cvelistv5high Β· 7.0
cve-2026-40272
QNX is the real-time operating system deployed in vehicle ECUs, ADAS controllers, and body control modules. A vulnerability in the libtraceparser library could allow an attacker with a corrupted kernel trace file to execute arbitrary code or crash processes on QNX systems. This is a critical issue that could affect vehicle safety and reliability if exploited.
cvelistv5high Β· 6.3
cve-2026-84303
A security advisory for gRPC-Go describes a vulnerability in its xDS RBAC HTTP filter, where an attacker can bypass access controls by using mixed-case characters in HTTP headers, exploiting a validation evasion issue related to gRFC A41. The technical impact is that unauthorized requests could pass through the filter, potentially allowing actions that should be blocked. This could be relevant where gRPC-Go is deployed in automotive systems, such as in vehicle-to-cloud communication or telematics services, but the advisory does not confirm automotive use; confirm applicability through the product SBOM or dependency inventory.
nvdhigh
cve-2026-93201
The Linux kernel's dm-pcache device-mapper target fails to validate a cache segment ID taken from on-disk metadata before using it to index an internal array, allowing an out-of-bounds read and write. An attacker who can supply the cache device at table load time, which requires CAP_SYS_ADMIN privileges, could exploit this to corrupt memory. This could be relevant where dm-pcache is deployed in automotive systems; confirm applicability through the product SBOM or dependency inventory.
nvdhigh
cve-2026-93200
A use-after-free vulnerability exists in the Linux kernel's I3C master subsystem, where sysfs attribute callbacks can dereference a freed master->this pointer after device detach, potentially allowing an attacker to access freed memory. The flaw has been resolved by keeping master->this alive until the master device is fully released. This could be relevant where the Linux I3C master subsystem is deployed in automotive systems. Confirm applicability through the product SBOM or dependency inventory.
nvdhigh
cve-2026-93196
A use-after-free vulnerability in the Linux kernel's virtio_pmem driver, part of the NVDIMM persistent memory subsystem, allows a race condition where a request is freed while still reachable through the virtqueue, causing a crash or potential memory corruption. This could be relevant where the Linux kernel and virtio_pmem are deployed in automotive systems, though the advisory does not confirm any automotive deployment. Confirm applicability through the product SBOM or dependency inventory.
nvdhigh
cve-2026-93194
The Linux kernel's Rockchip DisplayPort driver fails to release core resources such as the DisplayPort AUX channel when the driver is unbound, which can cause memory leaks and use-after-free errors. An attacker able to trigger this condition could potentially exploit the resulting memory corruption, though the advisory does not assign a specific severity rating. This could be relevant where the Rockchip DRM/DisplayPort driver is deployed in automotive systems, for example in display or infotainment controllers. Confirm applicability through the product SBOM or dependency inventory.
nvdhigh
cve-2026-93190
A flaw in the Linux kernel's ChromeOS EC USB Type-C driver lets a malicious or non-compliant embedded controller send an oversized count that causes a memory copy to write past a fixed-size stack array, potentially corrupting memory or crashing the system. The advisory does not state a severity rating. This could be relevant where this ChromeOS EC Type-C driver is deployed in automotive systems, though the advisory does not confirm any automotive use. Confirm applicability through the product SBOM or dependency inventory.
nvdhigh
cve-2026-93189
A use-after-free flaw in the Linux kernel's HID core affects certain HID drivers, including several hardware-monitoring drivers and some HID device drivers, where a driver's error-handling path can free a data structure while reports are still being processed. An attacker able to trigger this race could cause a use-after-free, which may lead to memory corruption or a system crash. The advisory does not state a numeric severity score. This could be relevant where the Linux kernel and affected HID drivers are deployed in automotive systems. Confirm applicability through the product SBOM or dependency inventory.
nvdhigh
cve-2026-93144
The Linux kernel has a vulnerability in its BPF subsystem where a validation gap allowed write access through untrusted BTF pointers, bypassing the intended read-only policy. An attacker could potentially exploit this to perform unauthorized writes that the kernel was supposed to block. The advisory does not state a severity rating. This could be relevant where the Linux kernel is deployed in automotive systems. Confirm applicability through the product SBOM or dependency inventory.
nvdhigh
cve-2026-93137
A use-after-free vulnerability in the Linux kernel's BPF subsystem allows an attacker to potentially access freed memory when a BPF program inspects the memory map of another task that is exiting concurrently. This could lead to memory corruption or a system crash, though the advisory does not state a specific severity rating. This could be relevant where the Linux kernel is deployed in automotive systems, such as in ECUs, infotainment units, or telematics gateways. Confirm applicability through the product SBOM or dependency inventory.
nvdhigh
cve-2026-93135
A flaw in the Linux kernel's BPF subsystem can cause a kernel panic or instruction alignment fault when a BPF program using inlined helpers runs without JIT compilation available, such as when JIT is disabled or fails due to memory pressure. The issue affects architectures including LoongArch, ARM64, and RISC-V, and the fix ensures such programs are rejected rather than executed unsafely. This could be relevant where the Linux kernel is deployed in automotive systems, so confirm applicability through the product SBOM or dependency inventory.
nvdhigh
cve-2026-93127
The Linux kernel's BPF verifier contains a flaw where a sign-extending stack load can share a scalar ID with a zero-extending load of the same slot, causing the verifier to track an incorrect value and potentially allow an out-of-bounds access. This could be relevant where the Linux kernel's BPF subsystem is deployed in automotive systems, for example in embedded or telematics components. Confirm applicability through the product SBOM or dependency inventory.