Vulnerabilidades em Tobit Laboratories AG
22 resultadosAnálise Vexday
A Tobit Laboratories apresenta um cenário de risco elevado caracterizado por 22 vulnerabilidades catalogadas, todas publicadas nos últimos 90 dias, incluindo 5 com severidade crítica. Embora nenhuma vulnerabilidade esteja sob exploração ativa documentada no KEV, a concentração recente de problemas de validação de entrada (CWE-20) indica um padrão de fraqueza sistemática que exige atenção imediata nas aplicações da empresa em ambiente produtivo.
CVE-2026-12070HIGHTeamDavid: Arbitrary File Deletion via form field 'scjob'EPSS —CVE-2026-54215MEDIUMTeamDavid: Open Redirect via the 'replyUrl' parameterEPSS —CVE-2026-54216MEDIUMTeamDavid: Reflected Cross Site Scripting (XSS) via the 'EntryInfo' parameterEPSS —CVE-2026-54210CRITICALTeamDavid: Buffer Overflow in file names of file upload functionalitiesEPSS —CVE-2026-54200HIGHTeamDavid: Local File Inclusion via the form field 'scjob'EPSS —CVE-2026-54199MEDIUMTeamDavid: Header Injection through request body in link storing functionalityEPSS —CVE-2026-54218HIGHTeamDavid: Weak Cryptography and Insecure Password StorageEPSS —CVE-2026-54213CRITICALTeamDavid: Denial of Service via endpoint 'internalRestart'EPSS —CVE-2026-54209HIGHTeamDavid: Buffer Overflow in 'editini' functionEPSS —CVE-2026-54203CRITICALTeamDavid: Memory Leak leaking sensitive informationEPSS —CVE-2026-54217MEDIUMTeamDavid: Stored XSS in web applicationEPSS —CVE-2026-54204HIGHTeamDavid: Server-Side Request Forgery (SSRF) via 'pathnameroot' parameter in search functionalityEPSS —CVE-2026-54214MEDIUMTeamDavid: Header Injection through the 'cType' URL parameterEPSS —CVE-2026-54212CRITICALTeamDavid: Buffer Overflow in JSON-parsingEPSS —CVE-2026-54205MEDIUMTeamDavid: Server-Side Request Forgery (SSRF) via 'pathname' parameter in link storing functionalityEPSS —CVE-2026-12071MEDIUMTeamDavid: Header Injection leading to Open Redirect via URL-encoded charactersEPSS —CVE-2026-54201MEDIUMTeamDavid: Missing AuthorizationEPSS —CVE-2026-54207MEDIUMTeamDavid: Server-Side Request Forgery (SSRF) via 'pathname' parameter in move archive functionalityEPSS —CVE-2026-54206MEDIUMTeamDavid: Server-Side Request Forgery (SSRF) via 'pathname' parameter in sending functionalityEPSS —CVE-2026-54202HIGHTeamDavid: Path Traversal in the archive creation functionalityEPSS —