vciy

CVEs we hold for Everest-core

Records whose assigning authority named Everest-core as the affected vendor. Newest identifiers first, capped at 200.

CVE-2026-33015EVerest has RemoteStop Bypass via BCB Toggle Session Restarteverest-core
CVE-2026-33014EVerest has Delayed Authorization Response Bypasses Termination After RemoteStopeverest-core
CVE-2026-33009EVerest: MQTT Switch-Phases Command Data Race Causing Charger State Corruptioeverest-core
CVE-2026-29044EVerest: Charging Continues When WithdrawAuthorization Is Processed Before TransactionStartedeverest-core
CVE-2026-27828EVerest: ISO15118 session_setup use-after-free can crash EVSE processeverest-core
CVE-2026-27816EVerest's ISO15118 update_energy_transfer_modes overflow can corrupt EVSE stateeverest-core
CVE-2026-27815EVerest: ISO15118 session_setup payment options overflow can corrupt EVSE stateeverest-core
CVE-2026-27814EVerest EvseManager phase-switch path has unsynchronized shared-state access race conditioneverest-core
CVE-2026-27813EVerest has use-after-free in auth timeout timer via race conditioneverest-core
CVE-2026-26074EVerest: OCPP201 startup event_queue lock mismatch leads to std::map/std::queue data raceeverest-core
CVE-2026-26073EVerest: OCPP 1.6 heap corruption caused by lock-free insertion in event_queueeverest-core
CVE-2026-26072EVerest has race-condition-induced std::map corruption in OCPP 1.6 evse_soc_mapeverest-core
CVE-2026-26071EVerest: OCPP 2.0.1 EVCCID Data Race Leads to Heap Use‑After‑Freeeverest-core
CVE-2026-26070EVerest: OCPP 2.0.1 EV SoC Update Race Causes Charge Point Crasheverest-core
CVE-2026-26008EVerest has OOB via EVSE ID Indexing Mismatch in OCPP 2.0.1 UpdateAllowedEnergyTransferModeseverest-core
CVE-2026-24003EvseV2G has sequence state validation bypasseverest-core
CVE-2026-23995EVerest has stack buffer overflow in ifreq.ifr_name when interface name exceeds IFNAMSIZeverest-core
CVE-2026-23955EVerest vulnerable to concatenation of strings literal and integerseverest-core
CVE-2026-22790EVerest's unchecked SLAC payload length causes stack overflow in HomeplugMessage::setup_payloadeverest-core
CVE-2026-22593EVerest has off-by-one stack buffer overflow in IsoMux certificate filename parsingeverest-core
CVE-2025-68141EVerest vulnerable to null pointer dereference during DC_ChargeLoopRes document deserializationeverest-core
CVE-2025-68140EVerest allows null session ID to bypass session ID verificationeverest-core
CVE-2025-68139In EVerest, by default, the EV is responsible for closing the connection if the module encounters an error during…everest-core
CVE-2025-68138EVerest affected by memory exhaustion in libocppeverest-core
CVE-2025-68137EVerest's Integer Overflow and Signed to Unsigned conversion lead to either stack buffer overflow or infinite loopeverest-core
CVE-2025-68136EVerest's inadequate session handling can lead to memory-related errors or exhaustion of the operating system’s file…everest-core
CVE-2025-68135EVerest's inadequate exception handling leads to denial of serviceeverest-core
CVE-2025-68134EVerest's use of assert functions can potentially lead to denial of serviceeverest-core
CVE-2025-68133EVerest's unlimited connections can lead to DoS through operating system resource exhaustioneverest-core
CVE-2025-68132EVerest has out-of-bounds read in DZG_GSH01 SLIP CRC parser that can crash powermeter drivereverest-core
CVE-2024-37310EVerest has an integer overflow in the "v2g_incoming_v2gtp" functioneverest-core

31 records, read from the index as it stood on 20 Sep 2026. Every row opens the record it names, and every value on that record opens its own receipt.

Everything on this page is free. Public data. Withholding it protects nothing.