Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2970▼ 106 respecto a la semana anterior
Críticas / altas1447▲ 86 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
110 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Media (5.9) | 0.37% | — | Linuxfoundation Everest | 26/3/2026 | 17/6/2026 | EVerest is an EV charging software stack. Versions prior to 2026.02.0 have a data race leading to possible `std::queue`/`std::deque` corruption. The trigger is powermeter public key update and EV session/error events (while OCPP not started). This results in a TSAN data race report and an ASAN/UBSAN misaligned address… | |
| Analizada | Media (4.2) | 0.14% | — | Linuxfoundation Everest | 26/3/2026 | 17/6/2026 | EVerest is an EV charging software stack. Versions prior to 2026.02.0 have a data race leading to `std::map<std::optional>` concurrent access (container/optional corruption possible). The trigger is EV SoC update with powermeter periodic update and unplugging/SessionFinished status. Version 2026.02.0 patches the issue. | |
| Analizada | Media (4.2) | 0.14% | — | Linuxfoundation Everest | 26/3/2026 | 17/6/2026 | EVerest is an EV charging software stack. Versions prior to 2026.02.0 have a data race leading to `std::string` concurrent access. with heap-use-after-free possible. This is triggered by EVCCID update (EV/ISO15118) and OCPP session/authorization events. Version 2026.02.0 contains a patch. | |
| Analizada | Media (4.2) | 0.15% | — | Linuxfoundation Everest | 26/3/2026 | 17/6/2026 | EVerest is an EV charging software stack. Versions prior to 2026.02.0 have a data race leading to `std::map<std::optional>` concurrent access (container/optional corruption possible). The trigger is an EV SoC update with powermeter periodic update and unplugging/SessionFinished state. Version 2026.2.0 contains a patch. | |
| Analizada | Alta (7.5) | 0.46% | — | Linuxfoundation Everest | 26/3/2026 | 17/6/2026 | EVerest is an EV charging software stack. Versions prior to 2026.02.0 have an out-of-bounds access (std::vector) that leads to possible remote crash/memory corruption. This is because the CSMS sends UpdateAllowedEnergyTransferModes over the network. Version 2026.2.0 contains a patch. | |
| Analizada | Alta (7.8) | 0.21% | — | Linuxfoundation Everest | 26/3/2026 | 17/6/2026 | EVerest is an EV charging software stack. Prior to version 2026.02.0, stack-based buffer overflow in CAN interface initialization: passing an interface name longer than IFNAMSIZ (16) to CAN open routines overflows `ifreq.ifr_name`, corrupting adjacent stack data and enabling potential code execution. A malicious or… | |
| Analizada | Alta (8.8) | 0.53% | — | Linuxfoundation Everest | 26/3/2026 | 17/6/2026 | EVerest is an EV charging software stack. Prior to version 2026.02.0, `HomeplugMessage::setup_payload` trusts `len` after an `assert`; in release builds the check is removed, so oversized SLAC payloads are `memcpy`'d into a ~1497-byte stack buffer, corrupting the stack and enabling remote code execution from… | |
| Analizada | Alta (7.8) | 0.14% | — | Linuxfoundation Everest | 26/3/2026 | 17/6/2026 | EVerest is an EV charging software stack. Prior to version 2026.02.0, an off-by-one check in IsoMux certificate filename handling causes a stack-based buffer overflow when a filename length equals `MAX_FILE_NAME_LENGTH` (100). A crafted filename in the certificate directory can overflow `file_names[idx]`, corrupting… | |
| Aplazada | Alta (8.1) | 0.37% | 💥 PoC | Wpeverest User RegistrationAI | 25/3/2026 | 17/6/2026 | Incorrect Privilege Assignment vulnerability in wpeverest User Registration user-registration allows Privilege Escalation.This issue affects User Registration: from n/a through <= 4.4.9. | |
| Aplazada | Alta (7.1) | 0.25% | — | Wpeverest Everest Forms PROAI | 19/3/2026 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WPEverest Everest Forms Pro allows Stored XSS.This issue affects Everest Forms Pro: from n/a through 1.9.10. | |
| Aplazada | Media (5.3) | 0.23% | — | Wpeverest Everest FormsAI | 19/2/2026 | 17/6/2026 | Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in wpeverest Everest Forms everest-forms allows Code Injection.This issue affects Everest Forms: from n/a through <= 3.4.1. | |
| Analizada | Media (5.3) | 0.28% | — | Linuxfoundation Everest | 26/1/2026 | 17/6/2026 | EVerest is an EV charging software stack. In versions up to and including 2025.12.1, it is possible to bypass the sequence state verification including authentication, and send requests that transition to forbidden states relative to the current one, thereby updating the current context with illegitimate data.cThanks… | |
| Aplazada | Media (4.3) | 0.19% | — | Wpeverest User-registrationAI | 22/1/2026 | 17/6/2026 | Missing Authorization vulnerability in wpeverest User Registration user-registration allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects User Registration: from n/a through <= 4.4.9. | |
| Aplazada | Alta (8.2) | 0.36% | — | Wpeverest User RegistrationAI | 22/1/2026 | 17/6/2026 | Missing Authorization vulnerability in wpeverest User Registration user-registration allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects User Registration: from n/a through <= 4.4.6. | |
| Analizada | Media (4.2) | 0.19% | — | Linuxfoundation Everest | 21/1/2026 | 17/6/2026 | EVerest is an EV charging software stack. Prior to version 2025.9.0, in several places, integer values are concatenated to literal strings when throwing errors. This results in pointers arithmetic instead of printing the integer value as expected, like most of interpreted languages. This can be used by malicious… | |
| Analizada | Alta (7.4) | 0.27% | — | Linuxfoundation Everest | 21/1/2026 | 17/6/2026 | EVerest is an EV charging software stack. Prior to version 2025.10.0, during the deserialization of a `DC_ChargeLoopRes` message that includes Receipt as well as TaxCosts, the vector `<DetailedTax>tax_costs` in the target `Receipt` structure is accessed out of bounds. This occurs in the method `template <> void… | |
| Analizada | Media (4.3) | 0.15% | — | Linuxfoundation Everest | 21/1/2026 | 17/6/2026 | EVerest is an EV charging software stack. Prior to version 2025.9.0, once the validity of the received V2G message has been verified, it is checked whether the submitted session ID matches the registered one. However, if no session has been registered, the default value is 0. Therefore, a message submitted with a… | |
| Analizada | Media (4.3) | 0.16% | — | Linuxfoundation Everest | 21/1/2026 | 17/6/2026 | EVerest is an EV charging software stack. In all versions up to and including 2025.12.1, the default value for `terminate_connection_on_failed_response` is `False`, which leaves the responsibility for session and connection termination to the EV. In this configuration, any errors encountered by the module are logged… | |
| Analizada | Alta (8.3) | 1.3% | 💥 Exploit | Linuxfoundation Everest | 21/1/2026 | 17/6/2026 | EVerest is an EV charging software stack. Prior to version 2025.10.0, an integer overflow occurring in `SdpPacket::parse_header()` allows the current buffer length to be set to 7 after a complete header of size 8 has been read. The remaining length to read is computed using the current length subtracted by the header… | |
| Analizada | Alta (7.4) | 0.29% | — | Linuxfoundation Everest | 21/1/2026 | 17/6/2026 | EVerest is an EV charging software stack. Prior to version 2025.10.0, once the module receives a SDP request, it creates a whole new set of objects like `Session`, `IConnection` which open new TCP socket for the ISO15118-20 communications and registers callbacks for the created file descriptor, without closing and… | |
| Analizada | Media (6.5) | 0.32% | — | Linuxfoundation Everest | 21/1/2026 | 17/6/2026 | EVerest is an EV charging software stack. Prior to version 2025.10.0, C++ exceptions are not properly handled for and by the `TbdController` loop, leading to its caller and itself to silently terminates. Thus, this leads to a denial of service as it is responsible of SDP and ISO15118-20 servers. Version 2025.10.0… | |
| Analizada | Alta (7.4) | 0.17% | — | Linuxfoundation Everest | 21/1/2026 | 17/6/2026 | EVerest is an EV charging software stack. Prior to version 2025.10.0, the use of the `assert` function to handle errors frequently causes the module to crash. This is particularly critical because the manager shuts down all other modules and exits when any one of them terminates, leading to a denial of service. In a… | |
| Analizada | Baja (2.4) | 0.28% | — | Linuxfoundation Everest | 21/1/2026 | 17/6/2026 | EVerest is an EV charging software stack. Prior to version 2025.12.0, `is_message_crc_correct` in the DZG_GSH01 powermeter SLIP parser reads `vec[vec.size()-1]` and `vec[vec.size()-2]` without checking that at least two bytes are present. Malformed SLIP frames on the serial link can reach `is_message_crc_correct` with… | |
| Analizada | Alta (7.4) | 0.39% | — | Linuxfoundation Everest | 21/1/2026 | 17/6/2026 | EVerest is an EV charging software stack. In versions 2025.9.0 and below, an attacker can exhaust the operating system's memory and cause the module to terminate by initiating an unlimited number of TCP connections that never proceed to ISO 15118-2 communication. This is possible because a new thread is started for… | |
| Modificada | Alta (8.1) | 0.19% | — | Everestthemes Everest Backup | 31/12/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in everestthemes Everest Backup everest-backup allows Path Traversal.This issue affects Everest Backup: from n/a through <= 2.3.11. |