Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| EVerest | everest-core | < 2026.02.0 | - |
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-22790 | 8.8 HIGH | EVerest's unchecked SLAC payload length causes stack overflow in HomeplugMessage::setup_pa |
| CVE-2026-23995 | 8.4 HIGH | EVerest has stack buffer overflow in ifreq.ifr_name when interface name exceeds IFNAMSIZ |
| CVE-2026-22593 | 8.4 HIGH | EVerest has off-by-one stack buffer overflow in IsoMux certificate filename parsing |
| CVE-2026-33009 | 8.2 HIGH | EVerest: MQTT Switch-Phases Command Data Race Causing Charger State Corruptio |
| CVE-2026-26008 | 7.5 HIGH | EVerest has OOB via EVSE ID Indexing Mismatch in OCPP 2.0.1 UpdateAllowedEnergyTransferMod |
| CVE-2026-26074 | 7.0 HIGH | EVerest: OCPP201 startup event_queue lock mismatch leads to std::map/std::queue data race |
| CVE-2026-26073 | 5.9 MEDIUM | EVerest: OCPP 1.6 heap corruption caused by lock-free insertion in event_queue |
| CVE-2026-27813 | 5.3 MEDIUM | EVerest has use-after-free in auth timeout timer via race condition |
| CVE-2026-33014 | 5.2 MEDIUM | EVerest has Delayed Authorization Response Bypasses Termination After RemoteStop |
| CVE-2026-33015 | 5.2 MEDIUM | EVerest has RemoteStop Bypass via BCB Toggle Session Restart |
| CVE-2026-29044 | 5.0 MEDIUM | EVerest: Charging Continues When WithdrawAuthorization Is Processed Before TransactionStar |
| CVE-2026-26071 | 4.2 MEDIUM | EVerest: OCPP 2.0.1 EVCCID Data Race Leads to Heap Use‑After‑Free |
| CVE-2026-27814 | 4.2 MEDIUM | EVerest EvseManager phase-switch path has unsynchronized shared-state access race conditio |
| CVE-2026-26072 | 4.2 MEDIUM | EVerest has race-condition-induced std::map corruption in OCPP 1.6 evse_soc_map |
| CVE-2026-27815 | EVerest: ISO15118 session_setup payment options overflow can corrupt EVSE state | |
| CVE-2026-27816 | EVerest's ISO15118 update_energy_transfer_modes overflow can corrupt EVSE state | |
| CVE-2026-27828 | EVerest: ISO15118 session_setup use-after-free can crash EVSE process |
No comments yet