5

CVSS3.1

CVE-2026-29044 - EVerest: Charging Continues When WithdrawAuthorization Is Processed Before TransactionStarted

EVerest is an EV charging software stack. Prior to version 2026.02.0, when WithdrawAuthorization is processed before the TransactionStarted event, AuthHandler determines `transaction_active=false` and only calls `withdraw_authorization_callback`. This path ultimately calls `Charger::deauthorize()`,…

πŸ“… Published: March 26, 2026, 4:37 p.m. πŸ”„ Last Modified: March 31, 2026, 8:08 p.m.

8.7

CVSS4.0

CVE-2026-32846 - OpenClaw Media Parsing Path Traversal to Arbitrary File Read

OpenClaw through 2026.3.23 (fixed in commit 4797bbc) contains a path traversal vulnerability in media parsing that allows attackers to read arbitrary files by bypassing path validation in the isLikelyLocalPath() and isValidMedia() functions. Attackers can exploit incomplete validation and the allow…

πŸ“… Published: March 26, 2026, 4:36 p.m. πŸ”„ Last Modified: April 2, 2026, 7:58 a.m.

5.5

CVSS4.0

CVE-2026-27828 - EVerest: ISO15118 session_setup use-after-free can crash EVSE process

EVerest is an EV charging software stack. Prior to version 2026.02.0, ISO15118_chargerImpl::handle_session_setup uses v2g_ctx after it has been freed when ISO15118 initialization fails (e.g., no IPv6 link-local address). The EVSE process can be crashed remotely by an attacker with MQTT access who i…

πŸ“… Published: March 26, 2026, 4:34 p.m. πŸ”„ Last Modified: March 31, 2026, 8:08 p.m.

5.5

CVSS4.0

CVE-2026-27816 - EVerest's ISO15118 update_energy_transfer_modes overflow can corrupt EVSE state

EVerest is an EV charging software stack. Prior to versions to 2026.02.0, ISO15118_chargerImpl::handle_update_energy_transfer_modes copies a variable-length list into a fixed-size array of length 6 without bounds checking. With schema validation disabled by default, oversized MQTT Cmd payloads can …

πŸ“… Published: March 26, 2026, 4:32 p.m. πŸ”„ Last Modified: March 31, 2026, 8:08 p.m.

5.5

CVSS4.0

CVE-2026-27815 - EVerest: ISO15118 session_setup payment options overflow can corrupt EVSE state

EVerest is an EV charging software stack. Prior to versions to 2026.02.0, ISO15118_chargerImpl::handle_session_setup copies a variable-length payment_options list into a fixed-size array of length 2 without bounds checking. With schema validation disabled by default, oversized MQTT Cmd payloads can…

πŸ“… Published: March 26, 2026, 4:30 p.m. πŸ”„ Last Modified: March 31, 2026, 8:08 p.m.

6.8

CVSS3.1

CVE-2026-3112 - Arbitrary File Read via Advanced Logging Support Packet

Mattermost versions 11.4.x <= 11.4.0, 11.3.x <= 11.3.1, 11.2.x <= 11.2.3, 10.11.x <= 10.11.11 fail to validate Advanced Logging file target paths which allows system administrators to read arbitrary host files via malicious AdvancedLoggingJSON configuration in support packet generation. Mattermost …

πŸ“… Published: March 26, 2026, 4:29 p.m. πŸ”„ Last Modified: March 30, 2026, 8:57 p.m.

2.2

CVSS3.1

CVE-2026-3109 - Missing timestamp validation in Zoom webhook handler

Mattermost Plugins versions <=11.4 10.11.11.0 fail to validate webhook request timestamps which allows an attacker to corrupt Zoom meeting state in Mattermost via replayed webhook requests. Mattermost Advisory ID: MMSA-2026-00584

πŸ“… Published: March 26, 2026, 4:28 p.m. πŸ”„ Last Modified: March 30, 2026, 1:26 p.m.

4.2

CVSS3.1

CVE-2026-27814 - EVerest EvseManager phase-switch path has unsynchronized shared-state access race condition

EVerest is an EV charging software stack. Versions prior to 2026.02.0 have a data race (C++ UB) triggered by an A 1-phase ↔ 3-phase switch request (`ac_switch_three_phases_while_charging`) during charging/waiting executes concurrently with the state machine loop. Version 2026.02.0 contains a patch.

πŸ“… Published: March 26, 2026, 4:27 p.m. πŸ”„ Last Modified: March 31, 2026, 8:08 p.m.

5.3

CVSS3.1

CVE-2026-27813 - EVerest has use-after-free in auth timeout timer via race condition

EVerest is an EV charging software stack. Versions prior to 2026.02.0 have a data race leading to use-after-free. This is triggered by EV plug-in/unplug and RFID/RemoteStart/OCPP authorization events (or delayed authorization response). Version 2026.2.0 contains a patch.

πŸ“… Published: March 26, 2026, 4:23 p.m. πŸ”„ Last Modified: March 31, 2026, 8:08 p.m.

4.3

CVSS3.1

CVE-2026-3115 - Guest users can view group member IDs without respecting view restrictions

Mattermost versions 11.2.x <= 11.2.2, 10.11.x <= 10.11.10, 11.4.x <= 11.4.0, 11.3.x <= 11.3.1 fail to apply view restrictions when retrieving group member IDs, which allows authenticated guest users to enumerate user IDs outside their allowed visibility scope via the group retrieval endpoint.. Matt…

πŸ“… Published: March 26, 2026, 4:23 p.m. πŸ”„ Last Modified: March 30, 2026, 8:57 p.m.
Total resulsts: 349182
Page 855 of 34,919
Β« previous page Β» next page
Filters