Vulnerabilidades em Tobit Laboratories AG

22 resultados
Análise Vexday

A Tobit Laboratories apresenta um cenário de risco elevado caracterizado por 22 vulnerabilidades catalogadas, todas publicadas nos últimos 90 dias, incluindo 5 com severidade crítica. Embora nenhuma vulnerabilidade esteja sob exploração ativa documentada no KEV, a concentração recente de problemas de validação de entrada (CWE-20) indica um padrão de fraqueza sistemática que exige atenção imediata nas aplicações da empresa em ambiente produtivo.

CVE-2026-54210CRITICALTeamDavid: Buffer Overflow in file names of file upload functionalitiesEPSS 0.5%CVE-2026-54212CRITICALTeamDavid: Buffer Overflow in JSON-parsingEPSS 0.5%CVE-2026-54213CRITICALTeamDavid: Denial of Service via endpoint 'internalRestart'EPSS 0.4%CVE-2026-54211CRITICALTeamDavid: Buffer Overflow in multiple form data parametersEPSS 0.4%CVE-2026-54208HIGHTeamDavid: Arbitrary File Write leading to Stored XSSEPSS 0.4%CVE-2026-12071MEDIUMTeamDavid: Header Injection leading to Open Redirect via URL-encoded charactersEPSS 0.3%CVE-2026-54214MEDIUMTeamDavid: Header Injection through the 'cType' URL parameterEPSS 0.3%CVE-2026-54204HIGHTeamDavid: Server-Side Request Forgery (SSRF) via 'pathnameroot' parameter in search functionalityEPSS 0.3%CVE-2026-54201MEDIUMTeamDavid: Missing AuthorizationEPSS 0.3%CVE-2026-54203CRITICALTeamDavid: Memory Leak leaking sensitive informationEPSS 0.3%CVE-2026-54202HIGHTeamDavid: Path Traversal in the archive creation functionalityEPSS 0.3%CVE-2026-54209HIGHTeamDavid: Buffer Overflow in 'editini' functionEPSS 0.3%CVE-2026-54216MEDIUMTeamDavid: Reflected Cross Site Scripting (XSS) via the 'EntryInfo' parameterEPSS 0.3%CVE-2026-54207MEDIUMTeamDavid: Server-Side Request Forgery (SSRF) via 'pathname' parameter in move archive functionalityEPSS 0.3%CVE-2026-54205MEDIUMTeamDavid: Server-Side Request Forgery (SSRF) via 'pathname' parameter in link storing functionalityEPSS 0.3%CVE-2026-54206MEDIUMTeamDavid: Server-Side Request Forgery (SSRF) via 'pathname' parameter in sending functionalityEPSS 0.3%CVE-2026-54215MEDIUMTeamDavid: Open Redirect via the 'replyUrl' parameterEPSS 0.3%CVE-2026-54218HIGHTeamDavid: Weak Cryptography and Insecure Password StorageEPSS 0.3%CVE-2026-54199MEDIUMTeamDavid: Header Injection through request body in link storing functionalityEPSS 0.3%CVE-2026-54217MEDIUMTeamDavid: Stored XSS in web applicationEPSS 0.3%