Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2567▼ 298 respecto a la semana anterior
Críticas / altas1351▲ 99 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 7 respecto a la semana anterior
Sin puntuar (sin CVSS)62▼ 466 respecto a la semana anterior
–

8 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
Pendiente de análisisCrítica (9.8)0.51%—OcppAI25/8/202628/9/2026
The OCPP 1.6 client in subsys/net/lib/ocpp/ocpp_j.c contains a stack buffer overflow in parse_getconfig_msg(). When handling a GetConfiguration request from the central system, the handler copied the attacker-controlled JSON "key" string into the caller's fixed 50-byte stack buffer (skey[CISTR50], declared in…
AplazadaMedia (4.4)0.12%—Estonian Information System Authority LibdigidocppAIEstonian Information System Authority Digidoc4AIEstonian Information System Authority Digidoc ON AndroidAIEstonian Information System Authority Digidoc ON IOSAI10/8/20261/9/2026
Improper verification of cryptographic signature and Improper Check for Unusual or Exceptional Conditions vulnerability in Estonian Information System Authority (RIA) libdigidocpp, DigiDoc4, DigiDoc on Android, and DigiDoc on iOS. This issue affects libdigidocpp: from 4.1.0 before 4.2.1; DigiDoc4: from 4.7.0 before…
AplazadaCrítica (9.3)0.75%—Charx Ocpp AgentAI30/7/202631/7/2026
Due to missing authentication the CHARX OCPP Agent service allows an unauthenticated remote attacker to reconfigure the backend connection. This can lead to Denial-of-Service and confidential data being disclosed to the attacker.
AnalizadaMedia (4.7)0.18%—Linuxfoundation Libocpp21/1/202617/6/2026
EVerest is an EV charging software stack, and EVerest libocpp is a C++ implementation of the Open Charge Point Protocol. In libocpp prior to version 0.30.1, pointers returned by the `strdup` calls are never freed. At each connection attempt, the newly allocated memory area will be leaked, potentially causing memory…
AplazadaMedia (5.3)0.25%—Open Charge Alliance OcppAIOpen Charge Alliance Ocpp V1.6AI7/1/202617/6/2026
As the service interaction is performed without authentication, an attacker with some knowledge of the protocol could obtain information about the charger via OCPP v1.6.
AplazadaBaja (3.1)0.17%—Linuxfoundation LibocppAI15/9/202517/6/2026
libocpp before 0.28.0 allows a denial of service (EVerest crash) because a secondary exception is thrown during error message generation.
AplazadaBaja (3.1)0.24%—Everest LibocppAI15/9/202517/6/2026
The OCPP implementation in libocpp before 0.26.2 allows a denial of service (EVerest crash) via JSON input larger than 255 characters, because a CiString<255> object is created with StringTooLarge set to Throw.
ModificadaAlta (7.5)0.62%—Steve-community Ocpp-jaxb26/12/202317/6/2026
SteVe Community ocpp-jaxb before 0.0.8 generates invalid timestamps such as ones with month 00 in certain situations (such as when an application receives a StartTransaction Open Charge Point Protocol message with a timestamp parameter of 1000000). This may lead to a SQL exception in applications, and may undermine…