Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2748▲ 37 respecto a la semana anterior
Críticas / altas1479▲ 369 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)64▼ 462 respecto a la semana anterior
53 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Baja (2.1) | 0.34% | — | Elixir-tesla Tesla | 2/6/2026 | 24/9/2026 | Improper Encoding or Escaping of Output vulnerability in elixir-tesla tesla allows multipart part header injection via unescaped Content-Disposition parameter values. Tesla.Multipart.part_headers_for_disposition/1 interpolates each disposition parameter as #{k}="#{v}" with no validation of CR (\r), LF (\n), or… | |
| Modificada | Alta (8.2) | 0.63% | — | Elixir-tesla Tesla | 2/6/2026 | 24/9/2026 | Allocation of Resources Without Limits or Throttling vulnerability in elixir-tesla tesla allows denial of service via atom table exhaustion in Tesla.Adapter.Mint. Tesla.Adapter.Mint.open_conn/2 converts the URL scheme of every outgoing request to a BEAM atom via String.to_atom(uri.scheme) with no allow-list… | |
| Modificada | Baja (2.1) | 0.35% | — | Elixir-tesla Tesla | 2/6/2026 | 24/9/2026 | Improper Neutralization of CRLF Sequences in HTTP Headers ('HTTP Request/Response Splitting') vulnerability in elixir-tesla tesla allows HTTP header injection via Tesla.Multipart.add_content_type_param/2. Tesla.Multipart.add_content_type_param/2 appends caller-supplied strings to the multipart content_type_params list… | |
| Modificada | Alta (8.2) | 0.67% | — | Elixir-tesla Tesla | 2/6/2026 | 24/9/2026 | Improper Handling of Case Sensitivity vulnerability in elixir-tesla tesla allows credential leakage to a third-party origin on cross-origin redirects. Tesla.Middleware.FollowRedirects strips security-sensitive headers on cross-origin redirects using a case-sensitive string comparison against a lowercase filter list… | |
| Modificada | Alta (8.2) | 0.70% | — | Elixir-tesla Tesla | 2/6/2026 | 24/9/2026 | Improper Handling of Highly Compressed Data (Data Amplification) vulnerability in elixir-tesla tesla allows a denial of service via decompression bomb in HTTP response bodies. When Tesla.Middleware.DecompressResponse or Tesla.Middleware.Compression is included in a Tesla middleware pipeline, HTTP response bodies are… | |
| Aplazada | Alta (8.6) | 0.45% | — | Tesla Telematics Control UnitAIGoogle Android Debug BridgeAI | 7/10/2025 | 17/6/2026 | Tesla Telematics Control Unit (TCU) firmware prior to v2025.14 contains an authentication bypass vulnerability. The TCU runs the Android Debug Bridge (adbd) as root and, despite a “lockdown” check that disables adb shell, still permits adb push/pull and adb forward. Because adbd is privileged and the device’s USB port… | |
| Aplazada | Media (4.7) | 0.22% | — | Tesla Model 3AI | 4/9/2025 | 17/6/2026 | Securing externally available CAN wires can easily allow physical access to the CAN bus, allowing possible injection of specially formed CAN messages to control remote start functions of the vehicle. Testing completed on Tesla Model 3 vehicles with software version v11.1 (2023.20.9 ee6de92ddac5). This issue affects… | |
| Analizada | Media (6.8) | 0.36% | — | Tesla Wall Connector Firmware | 30/7/2025 | 17/6/2026 | Tesla Wall Connector Firmware Downgrade Vulnerability. This vulnerability allows physically present attackers to execute arbitrary code on affected installations of Tesla Wall Connector devices. Authentication is not required to exploit this vulnerability. The specific flaw exists within the firmware upgrade feature.… | |
| Analizada | Alta (8.8) | 0.32% | — | Tesla Wall Connector Firmware | 30/7/2025 | 17/6/2026 | Tesla Wall Connector Content-Length Header Improper Input Validation Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of Tesla Wall Connector devices. Authentication is not required to exploit this vulnerability. The specific… | |
| Analizada | Alta (7.5) | 0.38% | — | Tesla Model 3 Firmware | 30/4/2025 | 17/6/2026 | Tesla Model 3 VCSEC Integer Overflow Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code on affected Tesla Model 3 vehicles. Authentication is not required to exploit this vulnerability. The specific flaw exists within the VCSEC module. By manipulating… | |
| Analizada | Alta (7.8) | 0.53% | — | Tesla Model S Firmware | 30/4/2025 | 17/6/2026 | Tesla Model S Iris Modem ql_atfwd Command Injection Code Execution Vulnerability. This vulnerability allows local attackers to execute arbitrary code on affected Tesla Model S vehicles. An attacker must first obtain the ability to execute code on the target system in order to exploit this vulnerability. The specific… | |
| Analizada | Alta (7.8) | 0.19% | — | Tesla Model S Firmware | 30/4/2025 | 17/6/2026 | Tesla Model S oFono AT Command Heap-based Buffer Overflow Code Execution Vulnerability. This vulnerability allows local attackers to execute arbitrary code on affected Tesla Model S vehicles. An attacker must first obtain the ability to execute code on the target modem in order to exploit this vulnerability. The… | |
| Analizada | Alta (7) | 0.17% | — | Tesla Model S Firmware | 30/4/2025 | 17/6/2026 | Tesla Model S oFono Unnecessary Privileges Sandbox Escape Vulnerability. This vulnerability allows local attackers to escape the sandbox on affected Tesla Model S vehicles. An attacker must first obtain the ability to execute code within the sandbox on the target system in order to exploit this vulnerability. The… | |
| Analizada | Media (5) | 0.22% | — | Tesla Model S Firmware | 30/4/2025 | 17/6/2026 | Tesla Model S Iris Modem Race Condition Firewall Bypass Vulnerability. This vulnerability allows network-adjacent attackers to bypass the firewall on the Iris modem in affected Tesla Model S vehicles. Authentication is not required to exploit this vulnerability. The specific flaw exists within the firewall service.… | |
| Analizada | Alta (7.8) | 0.18% | — | Tesla Model S Firmware | 30/4/2025 | 17/6/2026 | Tesla Model S Iris Modem QCMAP_ConnectionManager Improper Input Validation Sandbox Escape Vulnerability. This vulnerability allows local attackers to escape the sandbox on affected affected Tesla Model S vehicles. An attacker must first obtain the ability to execute low-privileged code on the target system in order to… | |
| Aplazada | Media (4.8) | 0.40% | — | TeslaloggerAI | 29/10/2024 | 17/6/2026 | Cross Site Scripting vulnerability in TeslaLogger Admin Panel before v.1.59.6 allows a remote attacker to execute arbitrary code via the New Journey field. | |
| Analizada | Alta (7.5) | 0.40% | — | Tesla Model 3 Firmware | 3/5/2024 | 17/6/2026 | Tesla Model 3 bsa_server BIP Heap-based Buffer Overflow Arbitrary Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code on affected Tesla Model 3 vehicles. An attacker must first obtain the ability to pair a malicious Bluetooth device with the target system in… | |
| Analizada | Alta (8.8) | 0.43% | — | Tesla Model 3 Firmware | 3/5/2024 | 17/6/2026 | Tesla Model 3 Gateway Firmware Signature Validation Bypass Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code on affected Tesla Model 3 vehicles. An attacker must first obtain the ability to execute privileged code on the Tesla infotainment system in order to exploit this… | |
| Analizada | Alta (7) | 0.22% | — | Tesla Model 3 Firmware | 3/5/2024 | 17/6/2026 | Tesla Model 3 bcmdhd Out-Of-Bounds Write Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected Tesla Model 3 vehicles. An attacker must first obtain the ability to execute code on the wifi subsystem in order to exploit this vulnerability. The specific… | |
| Analizada | Crítica (9.8) | 0.86% | — | Teslamate | 27/3/2024 | 17/6/2026 | In TeslaMate before 1.27.2, there is unauthorized access to port 4000 for remote viewing and operation of user data. After accessing the IP address for the TeslaMate instance, an attacker can switch the port to 3000 to enter Grafana for remote operations. At that time, the default username and password can be used to… | |
| Modificada | Media (5.3) | 0.53% | — | Teslamate | 18/5/2023 | 17/6/2026 | An issue in Teslamate v1.27.1 allows attackers to obtain sensitive information via directly accessing the teslamate link. | |
| Modificada | Alta (7.8) | 0.31% | — | Tesla Model 3 Firmware | 29/3/2023 | 17/6/2026 | This vulnerability allows local attackers to escalate privileges on affected Tesla vehicles. An attacker must first obtain the ability to execute privileged code on the target system in order to exploit this vulnerability. The specific flaw exists within the bcmdhd driver. The issue results from the lack of proper… | |
| Modificada | Alta (7.8) | 0.36% | — | Tesla Model 3 Firmware | 29/3/2023 | 17/6/2026 | This vulnerability allows local attackers to escalate privileges on affected Tesla vehicles. An attacker must first obtain the ability to execute privileged code on the target system in order to exploit this vulnerability. The specific flaw exists within the handling of the wowlan_config data structure. The issue… | |
| Modificada | Media (6.4) | 0.44% | — | Tesla Model 3 FirmwareTesla Model S FirmwareTesla Model X FirmwareTesla Model Y Firmware | 29/3/2023 | 17/6/2026 | This vulnerability allows physical attackers to execute arbitrary code on affected Tesla vehicles. Authentication is not required to exploit this vulnerability. The specific flaw exists within the ice_updater update mechanism. The issue results from the lack of proper validation of user-supplied firmware. An attacker… | |
| Modificada | Media (5.3) | 0.63% | — | Tesla Model 3 FirmwareTesla | 16/9/2022 | 17/6/2026 | Tesla Model 3 V11.0(2022.4.5.1 6b701552d7a6) Tesla mobile app v4.23 is vulnerable to Authentication Bypass by spoofing. Tesla Model 3's Phone Key authentication is vulnerable to Man-in-the-middle attacks in the BLE channel. It allows attackers to open a door and drive the car away by leveraging access to a legitimate… |