Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

MEDIUM 5.3 CVE-2026-54217 Tobit Laboratories AG TeamDavid's Webbox application is vulnerable to a stored XSS vulnerability. An attacker can send an email containing malicious… No fix yet Fix from $1,6002026-08-07 MEDIUM 5.3 CVE-2026-54216 Tobit Laboratories AG TeamDavid's Webbox application contains a reflected cross-site scripting (XSS) vulnerability. By sending a specially crafted l… No fix yet Fix from $1,6002026-08-07 MEDIUM 5.3 CVE-2026-54215 Tobit Laboratories AG TeamDavid's Webbox contains an open redirect vulnerability via the “replyUrl” parameter. An attacker can exploit this vulnera… No fix yet Fix from $1,6002026-08-07 MEDIUM 5.3 CVE-2026-54214 Tobit Laboratories AG TeamDavid's Webbox application is vulnerable to HTTP header injection through the “cType” URL parameter, which allows arbitrar… No fix yet Fix from $1,6002026-08-07 CRITICAL 9.2 CVE-2026-54213 Tobit Laboratories AG TeamDavid's Webbox application exposes a functionality that allows the server to be shut down when a specific endpoint (/inter… No fix yet Fix from $2,3002026-08-07 CRITICAL 9.5 CVE-2026-54212 Tobit Laboratories AG TeamDavid's Webbox application implements an API endpoint that is vulnerable to a buffer overflow condition. By submitting a s… No fix yet Fix from $2,3002026-08-07 CRITICAL 9.5 CVE-2026-54211 Tobit Laboratories AG TeamDavid's Webbox application’s endpoint “//serverClient_close.html” is vulnerable to a buffer overflow vulnerability in mult… No fix yet Fix from $2,3002026-08-07 CRITICAL 9.5 CVE-2026-54210 Tobit Laboratories AG TeamDavid's Webbox application implements various file upload functionalities that are vulnerable to a buffer overflow conditi… No fix yet Fix from $2,3002026-08-07 HIGH 8.9 CVE-2026-54209 Tobit Laboratories AG TeamDavid's Webbox application handles password changes using a function triggered by including the string "(editini)" in the … No fix yet Fix from $1,9502026-08-07 HIGH 8.5 CVE-2026-54208 Tobit Laboratories AG TeamDavid's Webbox application is vulnerable to arbitrary file write, allowing an unauthenticated attacker to create or write … No fix yet Fix from $1,9502026-08-07 MEDIUM 6.3 CVE-2026-54207 Tobit Laboratories AG TeamDavid's Webbox 's move archive functionality (“!ArcEntryMove”) accepts an arbitrary path, which can be set to network loca… No fix yet Fix from $1,6002026-08-07 MEDIUM 6.3 CVE-2026-54206 Tobit Laboratories AG TeamDavid's Webbox 's sending email, fax, SMS, etc. functionality accepts a @@INCLUDE command, which can be set to network loc… No fix yet Fix from $1,6002026-08-07 MEDIUM 6.3 CVE-2026-54205 Tobit Laboratories AG TeamDavid's Webbox 's link storing functionality (//ServerClient_celink.htm) accepts a “pathname” parameter, which can be set … No fix yet Fix from $1,6002026-08-07 HIGH 7.7 CVE-2026-54204 Tobit Laboratories AG TeamDavid's Webbox 's search functionality accepts a “pathnameroot” parameter, which can be set to network locations using UNC… No fix yet Fix from $1,9502026-08-07 CRITICAL 9.2 CVE-2026-54203 Memory Leak to an Unauthorized Actor vulnerability in Tobit Laboratories AG TeamDavid's Webbox allows reading of sensitive information. When accessin… No fix yet Fix from $2,3002026-08-07 HIGH 8.5 CVE-2026-54202 Tobit Laboratories AG TeamDavid's Webbox is vulnerable to a path traversal vulnerability in the archive creation functionality. Because the archive… No fix yet Fix from $1,9502026-08-07 MEDIUM 6.9 CVE-2026-54201 Tobit Laboratories AG TeamDavid's Webbox does not enforce authentication or authorization checks when serving these log files. As a result, attacke… No fix yet Fix from $1,6002026-08-07 HIGH 8.4 CVE-2026-54200 Tobit Laboratories AG TeamDavid's Webbox is vulnerable to a local file inclusion vulnerability in the send email, fax, SMS, etc. functionality. By … No fix yet Fix from $1,9502026-08-07 MEDIUM 5.3 CVE-2026-54199 Tobit Laboratories AG TeamDavid's Webbox is vulnerable to HTTP header injection through the request body in the application's link storing function… No fix yet Fix from $1,6002026-08-07 MEDIUM 5.3 CVE-2026-12071 The Webbox of TeamDavid by Tobit Laboratories AG constructs redirect URLs using user-supplied input, which is appended to the redirect target in a 3… No fix yet Fix from $1,6002026-08-07 HIGH 8.4 CVE-2026-12070 Tobit Laboratories AG TeamDavid's Webbox is vulnerable to an arbitrary file deletion vulnerability in the send email, fax, SMS, etc. functionality.… No fix yet Fix from $1,9502026-08-07 HIGH 8.8 CVE-2026-9169 DLL Search Order Hijacking in LUCID Vision Labs Arena SDK 1.0.80.49 on Windows allows a local attacker to execute arbitrary code with the privileges … No fix yet Fix from $1,9502026-08-07 MEDIUM 6.4 CVE-2026-66493 Joomla Extension - phoca.cz - Path Traversal vulnerability in Phoca Commander 1.0.0-6.1.3 - Improper limitation of paths for delete, copy and move ac… No fix yet Fix from $1,6002026-08-07 MEDIUM 6.1 CVE-2026-66492 Joomla Extension - phoca.cz - Path Traversal vulnerability in Phoca Commander 1.0.0-6.1.3 - Improper limitation of paths in the file upload action le… No fix yet Fix from $1,6002026-08-07 HIGH 8.2 CVE-2026-66491 Joomla Extension - phoca.cz - Arbitrary File Read in Phoca Commander 1.0.0-6.1.3 - Improper limitation of paths in the getSource function lead to an … No fix yet Fix from $1,9502026-08-07 MEDIUM 6.5 CVE-2026-49008 By accessing unencrypted information in the device firmware, an attacker can obtain credentials related to the integrity verification of a specific a… No fix yet Fix from $1,6002026-08-07 MEDIUM 6.2 CVE-2026-18938 A flaw was found in p11-kit. A local attacker, or one with equivalent access to a reachable RPC channel, could exploit an integer overflow vulnerabil… No fix yet Fix from $1,6002026-08-07 HIGH 7.5 CVE-2026-49007 By accessing unencrypted information in the device firmware, an attacker can obtain the initial login credentials for the device's web interface. No fix yet Fix from $1,9502026-08-07 MEDIUM 5.3 CVE-2026-49006 By accessing unencrypted information in the device firmware, an attacker can obtain credentials related to TLS transmission. No fix yet Fix from $1,6002026-08-07 MEDIUM 5.4 CVE-2026-16027 Server-Side request forgery (SSRF) vulnerability in Revenue Administration Türkiye's E-Signature allows Server Side Request Forgery. This issue affe… No fix yet Fix from $1,6002026-08-07