Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
49232
Total
3944
Critical
14598
High
14363
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2026-54211 | UNKNOWN | — | Tobit Laboratories AG TeamDavid's Webbox application’s endpoint “//serverClient_close.html” is vulnerable to a buffer overflow vulnerability in multiple form data parameters. By submitting excessively long values … | Aug 07, 2026 |
| CVE-2026-54210 | UNKNOWN | — | Tobit Laboratories AG TeamDavid's Webbox application implements various file upload functionalities that are vulnerable to a buffer overflow condition. By specifying an excessively long filename … | Aug 07, 2026 |
| CVE-2026-54209 | UNKNOWN | — | Tobit Laboratories AG TeamDavid's Webbox application handles password changes using a function triggered by including the string "(editini)" in the file path, writing the new … | Aug 07, 2026 |
| CVE-2026-54208 | UNKNOWN | — | Tobit Laboratories AG TeamDavid's Webbox application is vulnerable to arbitrary file write, allowing an unauthenticated attacker to create or write into existing files on the … | Aug 07, 2026 |
| CVE-2026-54207 | UNKNOWN | — | Tobit Laboratories AG TeamDavid's Webbox 's move archive functionality (“!ArcEntryMove”) accepts an arbitrary path, which can be set to network locations using UNC paths (e.g., … | Aug 07, 2026 |
| CVE-2026-54206 | UNKNOWN | — | Tobit Laboratories AG TeamDavid's Webbox 's sending email, fax, SMS, etc. functionality accepts a @@INCLUDE command, which can be set to network locations using UNC … | Aug 07, 2026 |
| CVE-2026-54205 | UNKNOWN | — | Tobit Laboratories AG TeamDavid's Webbox 's link storing functionality (//ServerClient_celink.htm) accepts a “pathname” parameter, which can be set to network locations using UNC paths (e.g., … | Aug 07, 2026 |
| CVE-2026-54204 | UNKNOWN | — | Tobit Laboratories AG TeamDavid's Webbox 's search functionality accepts a “pathnameroot” parameter, which can be set to network locations using UNC paths (e.g., “\\Server\Share”). The … | Aug 07, 2026 |
| CVE-2026-54203 | UNKNOWN | — | Memory Leak to an Unauthorized Actor vulnerability in Tobit Laboratories AG TeamDavid's Webbox allows reading of sensitive information. When accessing the URL “/.well-known/mta-sts.”, the application … | Aug 07, 2026 |
| CVE-2026-54202 | UNKNOWN | — | Tobit Laboratories AG TeamDavid's Webbox is vulnerable to a path traversal vulnerability in the archive creation functionality. Because the archive path is user-controlled and insufficiently … | Aug 07, 2026 |
| CVE-2026-54201 | UNKNOWN | — | Tobit Laboratories AG TeamDavid's Webbox does not enforce authentication or authorization checks when serving these log files. As a result, attackers can obtain sensitive error … | Aug 07, 2026 |
| CVE-2026-54200 | UNKNOWN | — | Tobit Laboratories AG TeamDavid's Webbox is vulnerable to a local file inclusion vulnerability in the send email, fax, SMS, etc. functionality. By specifying an '@@attach' … | Aug 07, 2026 |
| CVE-2026-54199 | UNKNOWN | — | Tobit Laboratories AG TeamDavid's Webbox is vulnerable to HTTP header injection through the request body in the application's link storing functionality (//ServerClient_celink.htm), which is appended … | Aug 07, 2026 |
| CVE-2026-12071 | UNKNOWN | — | The Webbox of TeamDavid by Tobit Laboratories AG constructs redirect URLs using user-supplied input, which is appended to the redirect target in a 302 HTTP … | Aug 07, 2026 |
| CVE-2026-12070 | UNKNOWN | — | Tobit Laboratories AG TeamDavid's Webbox is vulnerable to an arbitrary file deletion vulnerability in the send email, fax, SMS, etc. functionality. By specifying an @@COMMENTFILE … | Aug 07, 2026 |
| CVE-2026-9169 | HIGH | 8.8 | DLL Search Order Hijacking in LUCID Vision Labs Arena SDK 1.0.80.49 on Windows allows a local attacker to execute arbitrary code with the privileges of … | Aug 07, 2026 |
| CVE-2026-66493 | UNKNOWN | — | Joomla Extension - phoca.cz - Path Traversal vulnerability in Phoca Commander 1.0.0-6.1.3 - Improper limitation of paths for delete, copy and move actions lead to … | Aug 07, 2026 |
| CVE-2026-66492 | UNKNOWN | — | Joomla Extension - phoca.cz - Path Traversal vulnerability in Phoca Commander 1.0.0-6.1.3 - Improper limitation of paths in the file upload action lead to path … | Aug 07, 2026 |
| CVE-2026-66491 | UNKNOWN | — | Joomla Extension - phoca.cz - Arbitrary File Read in Phoca Commander 1.0.0-6.1.3 - Improper limitation of paths in the getSource function lead to an arbitrary … | Aug 07, 2026 |
| CVE-2026-49008 | MEDIUM | 6.5 | By accessing unencrypted information in the device firmware, an attacker can obtain credentials related to the integrity verification of a specific application function on the … | Aug 07, 2026 |
| CVE-2026-18938 | MEDIUM | 6.2 | A flaw was found in p11-kit. A local attacker, or one with equivalent access to a reachable RPC channel, could exploit an integer overflow vulnerability. … | Aug 07, 2026 |
| CVE-2026-49007 | HIGH | 7.5 | By accessing unencrypted information in the device firmware, an attacker can obtain the initial login credentials for the device's web interface. | Aug 07, 2026 |
| CVE-2026-49006 | MEDIUM | 5.3 | By accessing unencrypted information in the device firmware, an attacker can obtain credentials related to TLS transmission. | Aug 07, 2026 |
| CVE-2026-19079 | MEDIUM | 4.4 | A TOCTOU (Time-of-Check-Time-of-Use) race condition vulnerability was found in the fixfiles script in policycoreutils. When running fixfiles relabel or fixfiles restore, the script used find … | Aug 07, 2026 |
| CVE-2026-16027 | MEDIUM | 5.4 | Server-Side request forgery (SSRF) vulnerability in Revenue Administration Türkiye's E-Signature allows Server Side Request Forgery. This issue affects Türkiye's E-Signature: from 2.4.4.0 before 2.5.1.0. | Aug 07, 2026 |