Loading market data...

CVE Feed

Latest vulnerabilities from the National Vulnerability Database.

49232
Total
3944
Critical
14598
High
14363
Medium
CVE ID Severity Score Description Published
CVE-2026-54211 UNKNOWN Tobit Laboratories AG TeamDavid's Webbox application’s endpoint “//serverClient_close.html” is vulnerable to a buffer overflow vulnerability in multiple form data parameters. By submitting excessively long values … Aug 07, 2026
CVE-2026-54210 UNKNOWN Tobit Laboratories AG TeamDavid's Webbox application implements various file upload functionalities that are vulnerable to a buffer overflow condition. By specifying an excessively long filename … Aug 07, 2026
CVE-2026-54209 UNKNOWN Tobit Laboratories AG TeamDavid's Webbox application handles password changes using a function triggered by including the string "(editini)" in the file path, writing the new … Aug 07, 2026
CVE-2026-54208 UNKNOWN Tobit Laboratories AG TeamDavid's Webbox application is vulnerable to arbitrary file write, allowing an unauthenticated attacker to create or write into existing files on the … Aug 07, 2026
CVE-2026-54207 UNKNOWN Tobit Laboratories AG TeamDavid's Webbox 's move archive functionality (“!ArcEntryMove”) accepts an arbitrary path, which can be set to network locations using UNC paths (e.g., … Aug 07, 2026
CVE-2026-54206 UNKNOWN Tobit Laboratories AG TeamDavid's Webbox 's sending email, fax, SMS, etc. functionality accepts a @@INCLUDE command, which can be set to network locations using UNC … Aug 07, 2026
CVE-2026-54205 UNKNOWN Tobit Laboratories AG TeamDavid's Webbox 's link storing functionality (//ServerClient_celink.htm) accepts a “pathname” parameter, which can be set to network locations using UNC paths (e.g., … Aug 07, 2026
CVE-2026-54204 UNKNOWN Tobit Laboratories AG TeamDavid's Webbox 's search functionality accepts a “pathnameroot” parameter, which can be set to network locations using UNC paths (e.g., “\\Server\Share”). The … Aug 07, 2026
CVE-2026-54203 UNKNOWN Memory Leak to an Unauthorized Actor vulnerability in Tobit Laboratories AG TeamDavid's Webbox allows reading of sensitive information. When accessing the URL “/.well-known/mta-sts.”, the application … Aug 07, 2026
CVE-2026-54202 UNKNOWN Tobit Laboratories AG TeamDavid's Webbox is vulnerable to a path traversal vulnerability in the archive creation functionality. Because the archive path is user-controlled and insufficiently … Aug 07, 2026
CVE-2026-54201 UNKNOWN Tobit Laboratories AG TeamDavid's Webbox does not enforce authentication or authorization checks when serving these log files. As a result, attackers can obtain sensitive error … Aug 07, 2026
CVE-2026-54200 UNKNOWN Tobit Laboratories AG TeamDavid's Webbox is vulnerable to a local file inclusion vulnerability in the send email, fax, SMS, etc. functionality. By specifying an '@@attach' … Aug 07, 2026
CVE-2026-54199 UNKNOWN Tobit Laboratories AG TeamDavid's Webbox is vulnerable to HTTP header injection through the request body in the application's link storing functionality (//ServerClient_celink.htm), which is appended … Aug 07, 2026
CVE-2026-12071 UNKNOWN The Webbox of TeamDavid by Tobit Laboratories AG constructs redirect URLs using user-supplied input, which is appended to the redirect target in a 302 HTTP … Aug 07, 2026
CVE-2026-12070 UNKNOWN Tobit Laboratories AG TeamDavid's Webbox is vulnerable to an arbitrary file deletion vulnerability in the send email, fax, SMS, etc. functionality. By specifying an @@COMMENTFILE … Aug 07, 2026
CVE-2026-9169 HIGH 8.8 DLL Search Order Hijacking in LUCID Vision Labs Arena SDK 1.0.80.49 on Windows allows a local attacker to execute arbitrary code with the privileges of … Aug 07, 2026
CVE-2026-66493 UNKNOWN Joomla Extension - phoca.cz - Path Traversal vulnerability in Phoca Commander 1.0.0-6.1.3 - Improper limitation of paths for delete, copy and move actions lead to … Aug 07, 2026
CVE-2026-66492 UNKNOWN Joomla Extension - phoca.cz - Path Traversal vulnerability in Phoca Commander 1.0.0-6.1.3 - Improper limitation of paths in the file upload action lead to path … Aug 07, 2026
CVE-2026-66491 UNKNOWN Joomla Extension - phoca.cz - Arbitrary File Read in Phoca Commander 1.0.0-6.1.3 - Improper limitation of paths in the getSource function lead to an arbitrary … Aug 07, 2026
CVE-2026-49008 MEDIUM 6.5 By accessing unencrypted information in the device firmware, an attacker can obtain credentials related to the integrity verification of a specific application function on the … Aug 07, 2026
CVE-2026-18938 MEDIUM 6.2 A flaw was found in p11-kit. A local attacker, or one with equivalent access to a reachable RPC channel, could exploit an integer overflow vulnerability. … Aug 07, 2026
CVE-2026-49007 HIGH 7.5 By accessing unencrypted information in the device firmware, an attacker can obtain the initial login credentials for the device's web interface. Aug 07, 2026
CVE-2026-49006 MEDIUM 5.3 By accessing unencrypted information in the device firmware, an attacker can obtain credentials related to TLS transmission. Aug 07, 2026
CVE-2026-19079 MEDIUM 4.4 A TOCTOU (Time-of-Check-Time-of-Use) race condition vulnerability was found in the fixfiles script in policycoreutils. When running fixfiles relabel or fixfiles restore, the script used find … Aug 07, 2026
CVE-2026-16027 MEDIUM 5.4 Server-Side request forgery (SSRF) vulnerability in Revenue Administration Türkiye's E-Signature allows Server Side Request Forgery. This issue affects Türkiye's E-Signature: from 2.4.4.0 before 2.5.1.0. Aug 07, 2026