Steve Community maintains a narrowly scoped set of products centered on the STEVE and OCPP JAXB components, which serve specific roles in electric-vehicle charging infrastructure and related protocol implementations. The vulnerability footprint for this vendor is limited in volume; treat this as a compact profile rather than a broad trend line, with current severity, exploitation, and exposure counts shown alongside this summary.
The number and severity of CVEs published that impact products developed by Steve Community over time
Signals from CVEs in this vendor scope (5 CVEs).
5 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2024-25407HIGH SteVe v3.6.0 was discovered to use predictable transaction ID's when receiving a StartTransaction request. This vulnerability can allow attackers to cause a Denial of Service (DoS) | Feb 13, 2024 | 7.5 | 21 | NO | NO |
CVE-2023-52096HIGH SteVe Community ocpp-jaxb before 0.0.8 generates invalid timestamps such as ones with month 00 in certain situations (such as when an application receives a StartTransaction Open C | Dec 26, 2023 | 7.5 | 21 | NO | NO |
CVE-2026-28230MEDIUM SteVe is an open-source EV charging station management system. In versions up to and including 3.11.0, when a charger sends a StopTransaction message, SteVe looks up the transactio | Feb 26, 2026 | 6.3 | 20 | NO | NO |
CVE-2024-21550MEDIUM SteVe is an open platform that implements different version of the OCPP protocol for Electric Vehicle charge points, acting as a central server for management of registered charge | Aug 12, 2024 | 6.1 | 19 | NO | NO |
CVE-2024-44843MEDIUM An issue in the web socket handshake process of SteVe v3.7.1 allows attackers to bypass authentication and execute arbitrary coammands via supplying crafted OCPP requests. | Apr 15, 2025 | 5.9 | 17 | NO | NO |
Signals from CVEs in this vendor scope (5 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Steve Community.
Media articles that mention a CVE ID that affects a product developed by Steve Community — matched by CVE ID, not by vendor name.