Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| EVerest | everest-core | < 2026.02.0 | - |
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-22790 | 8.8 HIGH | EVerest's unchecked SLAC payload length causes stack overflow in HomeplugMessage::setup_pa |
| CVE-2026-22593 | 8.4 HIGH | EVerest has off-by-one stack buffer overflow in IsoMux certificate filename parsing |
| CVE-2026-23995 | 8.4 HIGH | EVerest has stack buffer overflow in ifreq.ifr_name when interface name exceeds IFNAMSIZ |
| CVE-2026-33009 | 8.2 HIGH | EVerest: MQTT Switch-Phases Command Data Race Causing Charger State Corruptio |
| CVE-2026-26008 | 7.5 HIGH | EVerest has OOB via EVSE ID Indexing Mismatch in OCPP 2.0.1 UpdateAllowedEnergyTransferMod |
| CVE-2026-26074 | 7.0 HIGH | EVerest: OCPP201 startup event_queue lock mismatch leads to std::map/std::queue data race |
| CVE-2026-26073 | 5.9 MEDIUM | EVerest: OCPP 1.6 heap corruption caused by lock-free insertion in event_queue |
| CVE-2026-27813 | 5.3 MEDIUM | EVerest has use-after-free in auth timeout timer via race condition |
| CVE-2026-33015 | 5.2 MEDIUM | EVerest has RemoteStop Bypass via BCB Toggle Session Restart |
| CVE-2026-33014 | 5.2 MEDIUM | EVerest has Delayed Authorization Response Bypasses Termination After RemoteStop |
| CVE-2026-29044 | 5.0 MEDIUM | EVerest: Charging Continues When WithdrawAuthorization Is Processed Before TransactionStar |
| CVE-2026-26070 | 4.6 MEDIUM | EVerest: OCPP 2.0.1 EV SoC Update Race Causes Charge Point Crash |
| CVE-2026-27814 | 4.2 MEDIUM | EVerest EvseManager phase-switch path has unsynchronized shared-state access race conditio |
| CVE-2026-26072 | 4.2 MEDIUM | EVerest has race-condition-induced std::map corruption in OCPP 1.6 evse_soc_map |
| CVE-2026-27816 | EVerest's ISO15118 update_energy_transfer_modes overflow can corrupt EVSE state | |
| CVE-2026-27828 | EVerest: ISO15118 session_setup use-after-free can crash EVSE process | |
| CVE-2026-27815 | EVerest: ISO15118 session_setup payment options overflow can corrupt EVSE state |
No comments yet