CVE Vulnerability Database

Search and browse 376,580 CVE records with CVSS scores, EPSS exploit predictions, and CISA KEV status.

CVE IDSeverityCVSSDescription
CVE-2026-54209HIGH8.9Tobit Laboratories AG TeamDavid's Webbox application handles password changes using a function triggered by including t...
CVE-2026-54208HIGH8.5Tobit Laboratories AG TeamDavid's Webbox application is vulnerable to arbitrary file write, allowing an unauthenticated...
CVE-2026-54207MEDIUM6.3Tobit Laboratories AG TeamDavid's Webbox 's move archive functionality (“!ArcEntryMove”) accepts an arbitrary path, whi...
CVE-2026-54206MEDIUM6.3Tobit Laboratories AG TeamDavid's Webbox 's sending email, fax, SMS, etc. functionality accepts a @@INCLUDE command, wh...
CVE-2026-54205MEDIUM6.3Tobit Laboratories AG TeamDavid's Webbox 's link storing functionality (//ServerClient_celink.htm) accepts a “pathname”...
CVE-2026-54204HIGH7.7Tobit Laboratories AG TeamDavid's Webbox 's search functionality accepts a “pathnameroot” parameter, which can be set t...
CVE-2026-54203CRITICAL9.2Memory Leak to an Unauthorized Actor vulnerability in Tobit Laboratories AG TeamDavid's Webbox allows reading of sensiti...
CVE-2026-54202HIGH8.5Tobit Laboratories AG TeamDavid's Webbox is vulnerable to a path traversal vulnerability in the archive creation funct...
CVE-2026-54201MEDIUM6.9Tobit Laboratories AG TeamDavid's Webbox does not enforce authentication or authorization checks when serving these lo...
CVE-2026-54200HIGH8.4Tobit Laboratories AG TeamDavid's Webbox is vulnerable to a local file inclusion vulnerability in the send email, fax,...
CVE-2026-54199MEDIUM5.3Tobit Laboratories AG TeamDavid's Webbox is vulnerable to HTTP header injection through the request body in the applic...
CVE-2026-12071MEDIUM5.3The Webbox of TeamDavid by Tobit Laboratories AG constructs redirect URLs using user-supplied input, which is appended ...
CVE-2026-12070HIGH8.4Tobit Laboratories AG TeamDavid's Webbox is vulnerable to an arbitrary file deletion vulnerability in the send email, ...
CVE-2026-9169HIGH8.8DLL Search Order Hijacking in LUCID Vision Labs Arena SDK 1.0.80.49 on Windows allows a local attacker to execute arbitr...
CVE-2026-66493MEDIUM6.4Joomla Extension - phoca.cz - Path Traversal vulnerability in Phoca Commander 1.0.0-6.1.3 - Improper limitation of paths...
CVE-2026-66492MEDIUM6.1Joomla Extension - phoca.cz - Path Traversal vulnerability in Phoca Commander 1.0.0-6.1.3 - Improper limitation of paths...
CVE-2026-66491HIGH8.2Joomla Extension - phoca.cz - Arbitrary File Read in Phoca Commander 1.0.0-6.1.3 - Improper limitation of paths in the g...
CVE-2026-49008MEDIUM6.5By accessing unencrypted information in the device firmware, an attacker can obtain credentials related to the integrity...
CVE-2026-18938MEDIUM6.2A flaw was found in p11-kit. A local attacker, or one with equivalent access to a reachable RPC channel, could exploit a...
CVE-2026-49007HIGH7.5By accessing unencrypted information in the device firmware, an attacker can obtain the initial login credentials for th...
CVE-2026-49006MEDIUM5.3By accessing unencrypted information in the device firmware, an attacker can obtain credentials related to TLS transmiss...
CVE-2026-19079MEDIUM4.4A TOCTOU (Time-of-Check-Time-of-Use) race condition vulnerability was found in the fixfiles script in policycoreutils. W...
CVE-2026-16027MEDIUM5.4Server-Side request forgery (SSRF) vulnerability in Revenue Administration Türkiye's E-Signature allows Server Side Requ...
CVE-2026-15239MEDIUM5.3The Simple CAPTCHA with Cloudflare Turnstile WordPress plugin before 1.42.0 does not bind its Turnstile validation cache...
CVE-2026-15211MEDIUM5.9The Subscriptions for WooCommerce WordPress plugin before 2.0.1 does not validate the payment amount or bind the PayPal ...