Vulnerabilidades em Tobit Laboratories AG

22 resultados
Análise Vexday

A Tobit Laboratories apresenta um cenário de risco elevado caracterizado por 22 vulnerabilidades catalogadas, todas publicadas nos últimos 90 dias, incluindo 5 com severidade crítica. Embora nenhuma vulnerabilidade esteja sob exploração ativa documentada no KEV, a concentração recente de problemas de validação de entrada (CWE-20) indica um padrão de fraqueza sistemática que exige atenção imediata nas aplicações da empresa em ambiente produtivo.

CVE-2026-12070HIGHTeamDavid: Arbitrary File Deletion via form field 'scjob'EPSS CVE-2026-54215MEDIUMTeamDavid: Open Redirect via the 'replyUrl' parameterEPSS CVE-2026-54216MEDIUMTeamDavid: Reflected Cross Site Scripting (XSS) via the 'EntryInfo' parameterEPSS CVE-2026-54210CRITICALTeamDavid: Buffer Overflow in file names of file upload functionalitiesEPSS CVE-2026-54200HIGHTeamDavid: Local File Inclusion via the form field 'scjob'EPSS CVE-2026-54199MEDIUMTeamDavid: Header Injection through request body in link storing functionalityEPSS CVE-2026-54218HIGHTeamDavid: Weak Cryptography and Insecure Password StorageEPSS CVE-2026-54213CRITICALTeamDavid: Denial of Service via endpoint 'internalRestart'EPSS CVE-2026-54209HIGHTeamDavid: Buffer Overflow in 'editini' functionEPSS CVE-2026-54203CRITICALTeamDavid: Memory Leak leaking sensitive informationEPSS CVE-2026-54217MEDIUMTeamDavid: Stored XSS in web applicationEPSS CVE-2026-54204HIGHTeamDavid: Server-Side Request Forgery (SSRF) via 'pathnameroot' parameter in search functionalityEPSS CVE-2026-54214MEDIUMTeamDavid: Header Injection through the 'cType' URL parameterEPSS CVE-2026-54212CRITICALTeamDavid: Buffer Overflow in JSON-parsingEPSS CVE-2026-54205MEDIUMTeamDavid: Server-Side Request Forgery (SSRF) via 'pathname' parameter in link storing functionalityEPSS CVE-2026-12071MEDIUMTeamDavid: Header Injection leading to Open Redirect via URL-encoded charactersEPSS CVE-2026-54201MEDIUMTeamDavid: Missing AuthorizationEPSS CVE-2026-54207MEDIUMTeamDavid: Server-Side Request Forgery (SSRF) via 'pathname' parameter in move archive functionalityEPSS CVE-2026-54206MEDIUMTeamDavid: Server-Side Request Forgery (SSRF) via 'pathname' parameter in sending functionalityEPSS CVE-2026-54202HIGHTeamDavid: Path Traversal in the archive creation functionalityEPSS