CVE Vulnerability Database
Search and browse 376,580 CVE records with CVSS scores, EPSS exploit predictions, and CISA KEV status.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-54209 | HIGH | 8.9 | 0.4% | Aug 7, 2026 | Tobit Laboratories AG TeamDavid's Webbox application handles password changes using a function triggered by including t... |
| CVE-2026-54208 | HIGH | 8.5 | 0.5% | Aug 7, 2026 | Tobit Laboratories AG TeamDavid's Webbox application is vulnerable to arbitrary file write, allowing an unauthenticated... |
| CVE-2026-54207 | MEDIUM | 6.3 | 0.5% | Aug 7, 2026 | Tobit Laboratories AG TeamDavid's Webbox 's move archive functionality (“!ArcEntryMove”) accepts an arbitrary path, whi... |
| CVE-2026-54206 | MEDIUM | 6.3 | 0.3% | Aug 7, 2026 | Tobit Laboratories AG TeamDavid's Webbox 's sending email, fax, SMS, etc. functionality accepts a @@INCLUDE command, wh... |
| CVE-2026-54205 | MEDIUM | 6.3 | — | Aug 7, 2026 | Tobit Laboratories AG TeamDavid's Webbox 's link storing functionality (//ServerClient_celink.htm) accepts a “pathname”... |
| CVE-2026-54204 | HIGH | 7.7 | 0.6% | Aug 7, 2026 | Tobit Laboratories AG TeamDavid's Webbox 's search functionality accepts a “pathnameroot” parameter, which can be set t... |
| CVE-2026-54203 | CRITICAL | 9.2 | 0.3% | Aug 7, 2026 | Memory Leak to an Unauthorized Actor vulnerability in Tobit Laboratories AG TeamDavid's Webbox allows reading of sensiti... |
| CVE-2026-54202 | HIGH | 8.5 | 0.3% | Aug 7, 2026 | Tobit Laboratories AG TeamDavid's Webbox is vulnerable to a path traversal vulnerability in the archive creation funct... |
| CVE-2026-54201 | MEDIUM | 6.9 | 0.3% | Aug 7, 2026 | Tobit Laboratories AG TeamDavid's Webbox does not enforce authentication or authorization checks when serving these lo... |
| CVE-2026-54200 | HIGH | 8.4 | 0.2% | Aug 7, 2026 | Tobit Laboratories AG TeamDavid's Webbox is vulnerable to a local file inclusion vulnerability in the send email, fax,... |
| CVE-2026-54199 | MEDIUM | 5.3 | 0.3% | Aug 7, 2026 | Tobit Laboratories AG TeamDavid's Webbox is vulnerable to HTTP header injection through the request body in the applic... |
| CVE-2026-12071 | MEDIUM | 5.3 | 0.3% | Aug 7, 2026 | The Webbox of TeamDavid by Tobit Laboratories AG constructs redirect URLs using user-supplied input, which is appended ... |
| CVE-2026-12070 | HIGH | 8.4 | 0.2% | Aug 7, 2026 | Tobit Laboratories AG TeamDavid's Webbox is vulnerable to an arbitrary file deletion vulnerability in the send email, ... |
| CVE-2026-9169 | HIGH | 8.8 | 0.1% | Aug 7, 2026 | DLL Search Order Hijacking in LUCID Vision Labs Arena SDK 1.0.80.49 on Windows allows a local attacker to execute arbitr... |
| CVE-2026-66493 | MEDIUM | 6.4 | 0.3% | Aug 7, 2026 | Joomla Extension - phoca.cz - Path Traversal vulnerability in Phoca Commander 1.0.0-6.1.3 - Improper limitation of paths... |
| CVE-2026-66492 | MEDIUM | 6.1 | 0.4% | Aug 7, 2026 | Joomla Extension - phoca.cz - Path Traversal vulnerability in Phoca Commander 1.0.0-6.1.3 - Improper limitation of paths... |
| CVE-2026-66491 | HIGH | 8.2 | 0.3% | Aug 7, 2026 | Joomla Extension - phoca.cz - Arbitrary File Read in Phoca Commander 1.0.0-6.1.3 - Improper limitation of paths in the g... |
| CVE-2026-49008 | MEDIUM | 6.5 | 0.2% | Aug 7, 2026 | By accessing unencrypted information in the device firmware, an attacker can obtain credentials related to the integrity... |
| CVE-2026-18938 | MEDIUM | 6.2 | 0.1% | Aug 7, 2026 | A flaw was found in p11-kit. A local attacker, or one with equivalent access to a reachable RPC channel, could exploit a... |
| CVE-2026-49007 | HIGH | 7.5 | 0.3% | Aug 7, 2026 | By accessing unencrypted information in the device firmware, an attacker can obtain the initial login credentials for th... |
| CVE-2026-49006 | MEDIUM | 5.3 | 0.1% | Aug 7, 2026 | By accessing unencrypted information in the device firmware, an attacker can obtain credentials related to TLS transmiss... |
| CVE-2026-19079 | MEDIUM | 4.4 | 0.1% | Aug 7, 2026 | A TOCTOU (Time-of-Check-Time-of-Use) race condition vulnerability was found in the fixfiles script in policycoreutils. W... |
| CVE-2026-16027 | MEDIUM | 5.4 | 0.2% | Aug 7, 2026 | Server-Side request forgery (SSRF) vulnerability in Revenue Administration Türkiye's E-Signature allows Server Side Requ... |
| CVE-2026-15239 | MEDIUM | 5.3 | 0.1% | Aug 7, 2026 | The Simple CAPTCHA with Cloudflare Turnstile WordPress plugin before 1.42.0 does not bind its Turnstile validation cache... |
| CVE-2026-15211 | MEDIUM | 5.9 | 0.1% | Aug 7, 2026 | The Subscriptions for WooCommerce WordPress plugin before 2.0.1 does not validate the payment amount or bind the PayPal ... |
