8.4

CVSS3.1

CVE-2025-68137 - EVerest's Integer Overflow and Signed to Unsigned conversion lead to either stack buffer overflow o…

EVerest is an EV charging software stack. Prior to version 2025.10.0, an integer overflow occurring in `SdpPacket::parse_header()` allows the current buffer length to be set to 7 after a complete header of size 8 has been read. The remaining length to read is computed using the current length subtr…

📅 Published: Jan. 21, 2026, 7:20 p.m. 🔄 Last Modified: Feb. 6, 2026, 9:21 p.m.

7.4

CVSS3.1

CVE-2025-68136 - EVerest's inadequate session handling can lead to memory-related errors or exhaustion of the operat…

EVerest is an EV charging software stack. Prior to version 2025.10.0, once the module receives a SDP request, it creates a whole new set of objects like `Session`, `IConnection` which open new TCP socket for the ISO15118-20 communications and registers callbacks for the created file descriptor, wit…

📅 Published: Jan. 21, 2026, 7:18 p.m. 🔄 Last Modified: Feb. 6, 2026, 9:21 p.m.

6.9

CVSS4.0

CVE-2025-13465 - Prototype Pollution Vulnerability in Lodash _.unset and _.omit functions

Lodash versions 4.0.0 through 4.17.22 are vulnerable to prototype pollution in the _.unset and _.omit functions. An attacker can pass crafted paths which cause Lodash to delete methods from global prototypes. The issue permits deletion of properties but does not allow overwriting their original be…

📅 Published: Jan. 21, 2026, 7:05 p.m. 🔄 Last Modified: Feb. 17, 2026, 5:10 p.m.

6.5

CVSS3.1

CVE-2025-68135 - EVerest's inadequate exception handling leads to denial of service

EVerest is an EV charging software stack. Prior to version 2025.10.0, C++ exceptions are not properly handled for and by the `TbdController` loop, leading to its caller and itself to silently terminates. Thus, this leads to a denial of service as it is responsible of SDP and ISO15118-20 servers. Ve…

📅 Published: Jan. 21, 2026, 6:56 p.m. 🔄 Last Modified: Feb. 6, 2026, 9:21 p.m.

7.4

CVSS3.1

CVE-2025-68134 - EVerest's use of assert functions can potentially lead to denial of service

EVerest is an EV charging software stack. Prior to version 2025.10.0, the use of the `assert` function to handle errors frequently causes the module to crash. This is particularly critical because the manager shuts down all other modules and exits when any one of them terminates, leading to a denia…

📅 Published: Jan. 21, 2026, 6:32 p.m. 🔄 Last Modified: Feb. 6, 2026, 9:21 p.m.

2.4

CVSS4.0

CVE-2025-68132 - EVerest has out-of-bounds read in DZG_GSH01 SLIP CRC parser that can crash powermeter driver

EVerest is an EV charging software stack. Prior to version 2025.12.0, `is_message_crc_correct` in the DZG_GSH01 powermeter SLIP parser reads `vec[vec.size()-1]` and `vec[vec.size()-2]` without checking that at least two bytes are present. Malformed SLIP frames on the serial link can reach `is_messa…

📅 Published: Jan. 21, 2026, 6:28 p.m. 🔄 Last Modified: Feb. 6, 2026, 9:21 p.m.

8.7

CVSS4.0

CVE-2026-23754 - D-Link D-View 8 IDOR Allows Credential Disclosure and Account Takeover

D-Link D-View 8 versions 2.0.1.107 and below contain an improper access control vulnerability in backend API endpoints. Any authenticated user can supply an arbitrary user_id value to retrieve sensitive credential data belonging to other users, including super administrators. The exposed credential…

📅 Published: Jan. 21, 2026, 6:02 p.m. 🔄 Last Modified: April 18, 2026, 4:15 a.m.

8.4

CVSS4.0

CVE-2026-23755 - D-Link D-View 8 Installer DLL Preloading via Uncontrolled Search Path

D-Link D-View 8 versions 2.0.1.107 and below contain an uncontrolled search path vulnerability in the installer. When executed with elevated privileges via UAC, the installer attempts to load version.dll from its execution directory, allowing DLL preloading. An attacker can supply a malicious versi…

📅 Published: Jan. 21, 2026, 6:02 p.m. 🔄 Last Modified: April 18, 2026, 4:15 a.m.

5.4

CVSS4.0

CVE-2021-47870 - GetSimple CMS My SMTP Contact Plugin 1.1.2 - Stored XSS

GetSimple CMS My SMTP Contact Plugin 1.1.2 suffers from a Stored Cross-Site Scripting (XSS) vulnerability. The plugin attempts to sanitize user input using htmlspecialchars(), but this can be bypassed by passing dangerous characters as escaped hex bytes. This allows attackers to inject arbitrary cl…

📅 Published: Jan. 21, 2026, 5:32 p.m. 🔄 Last Modified: April 7, 2026, 2:06 p.m.

8.5

CVSS4.0

CVE-2021-47860 - GetSimple CMS Custom JS 0.1 - CSRF to XSS to RCE

GetSimple CMS Custom JS 0.1 plugin contains a cross-site request forgery vulnerability that allows unauthenticated attackers to inject arbitrary client-side code into administrator browsers. Attackers can craft a malicious website that triggers a cross-site scripting payload to execute remote code …

📅 Published: Jan. 21, 2026, 5:29 p.m. 🔄 Last Modified: April 7, 2026, 2:06 p.m.
Total resulsts: 346120
Page 1733 of 34,612
« previous page » next page
Filters