Everest

Vendor:

First CVE: Jan 21, 2026 · Active for under a year

29
Total CVEs
More Total CVEs than 96% of tracked products
29.0
Avg CVEs / Year
Higher CVE frequency than 99% of tracked products
6.3
Avg CVSS
Higher Avg CVSS than 26% of tracked products
0.0%
KEV Rate
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact Everest over time

Volume of CVEsAvg CVSS Base Score
First CVE
Jan 21, 2026
6 months ago
Most Recent CVE
Mar 26, 2026
120 days ago

CVE Severity & Scoring

Everest29 CVEs
All CVEs352,231 CVEs
MediumHighCritical
Attack Vector
Local3 (10.3%)
Network9 (31.0%)
Unknown0 (0.0%)
Physical7 (24.1%)
Adjacent Network10 (34.5%)
Attack Complexity
Low19 (65.5%)
High10 (34.5%)
Unknown0 (0.0%)
User Interaction
None28 (96.6%)
Unknown0 (0.0%)
Required1 (3.4%)
Privileges Required
Low2 (6.9%)
High1 (3.4%)
None26 (89.7%)
Unknown0 (0.0%)

Top CVEs

Signals from CVEs in this product scope (29 CVEs).

29 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
EVerest is an EV charging software stack. Prior to version 2026.02.0, `HomeplugMessage::setup_payload` trusts `len` after an `assert`; in release builds the check is removed, so ov
Mar 26, 20268.830NONO
EVerest is an EV charging software stack. Prior to version 2025.10.0, an integer overflow occurring in `SdpPacket::parse_header()` allows the current buffer length to be set to 7 a
Jan 21, 20268.330NONO
EVerest is an EV charging software stack. Prior to versions to 2026.02.0, ISO15118_chargerImpl::handle_update_energy_transfer_modes copies a variable-length list into a fixed-size
Mar 26, 20269.128NONO
EVerest is an EV charging software stack. Prior to versions to 2026.02.0, ISO15118_chargerImpl::handle_session_setup copies a variable-length payment_options list into a fixed-size
Mar 26, 20269.128NONO
EVerest is an EV charging software stack. Prior to version 2025.10.0, once the module receives a SDP request, it creates a whole new set of objects like `Session`, `IConnection` wh
Jan 21, 20267.428NONO
EVerest is an EV charging software stack. Prior to version 2026.02.0, stack-based buffer overflow in CAN interface initialization: passing an interface name longer than IFNAMSIZ (1
Mar 26, 20267.827NONO
EVerest is an EV charging software stack. Prior to version 2026.02.0, an off-by-one check in IsoMux certificate filename handling causes a stack-based buffer overflow when a filena
Mar 26, 20267.827NONO
EVerest is an EV charging software stack. Prior to version 2025.10.0, the use of the `assert` function to handle errors frequently causes the module to crash. This is particularly
Jan 21, 20267.427NONO
EVerest is an EV charging software stack. Versions prior to 2026.02.0 have an out-of-bounds access (std::vector) that leads to possible remote crash/memory corruption. This is beca
Mar 26, 20267.526NONO
EVerest is an EV charging software stack. Versions prior to 2026.02.0 have a data race leading to C++ UB (potential memory corruption). This is triggered by an MQTT `everest_extern
Mar 26, 20266.524NONO

Exploit Exposure

Signals from CVEs in this product scope (29 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

Signals from CVEs in this product scope (29 CVEs).

Media Mentions

Signals from CVEs in this product scope (29 CVEs).

Top CNAs Publishing CVEs For Everest

Top CWEs

Versions

No cataloged versions.