NVD Vulnerabilities

Severity Distribution

Publication Trend

Vulnerability Database

CVE ID Description Published Base Score Attack Vector Severity Actions
CVE-2026-54216 Tobit Laboratories AG TeamDavid's Webbox application contains a reflected cross-site scripting (XSS) vulnerability. By sending a specially crafted li... 2026-08-07 5.3 NETWORK MEDIUM NVD
CVE-2026-54215 Tobit Laboratories AG TeamDavid's Webbox contains an open redirect vulnerability via the “replyUrl” parameter. An attacker can exploit this vulnerab... 2026-08-07 5.3 NETWORK MEDIUM NVD
CVE-2026-54214 Tobit Laboratories AG TeamDavid's Webbox application is vulnerable to HTTP header injection through the “cType” URL parameter, which allows arbitrary... 2026-08-07 5.3 NETWORK MEDIUM NVD
CVE-2026-54213 Tobit Laboratories AG TeamDavid's Webbox application exposes a functionality that allows the server to be shut down when a specific endpoint (/intern... 2026-08-07 9.2 NETWORK CRITICAL NVD
CVE-2026-54212 Tobit Laboratories AG TeamDavid's Webbox application implements an API endpoint that is vulnerable to a buffer overflow condition. By submitting a sp... 2026-08-07 9.5 NETWORK CRITICAL NVD
CVE-2026-54211 Tobit Laboratories AG TeamDavid's Webbox application’s endpoint “//serverClient_close.html” is vulnerable to a buffer overflow vulnerability in multi... 2026-08-07 9.5 NETWORK CRITICAL NVD
CVE-2026-54210 Tobit Laboratories AG TeamDavid's Webbox application implements various file upload functionalities that are vulnerable to a buffer overflow conditio... 2026-08-07 9.5 NETWORK CRITICAL NVD
CVE-2026-54209 Tobit Laboratories AG TeamDavid's Webbox application handles password changes using a function triggered by including the string "(editini)" in the f... 2026-08-07 8.9 NETWORK HIGH NVD
CVE-2026-54208 Tobit Laboratories AG TeamDavid's Webbox application is vulnerable to arbitrary file write, allowing an unauthenticated attacker to create or write i... 2026-08-07 8.5 NETWORK HIGH NVD
CVE-2026-54207 Tobit Laboratories AG TeamDavid's Webbox 's move archive functionality (“!ArcEntryMove”) accepts an arbitrary path, which can be set to network locat... 2026-08-07 6.3 NETWORK MEDIUM NVD
CVE-2026-54206 Tobit Laboratories AG TeamDavid's Webbox 's sending email, fax, SMS, etc. functionality accepts a @@INCLUDE command, which can be set to network loca... 2026-08-07 6.3 NETWORK MEDIUM NVD
CVE-2026-54205 Tobit Laboratories AG TeamDavid's Webbox 's link storing functionality (//ServerClient_celink.htm) accepts a “pathname” parameter, which can be set t... 2026-08-07 6.3 NETWORK MEDIUM NVD
CVE-2026-54204 Tobit Laboratories AG TeamDavid's Webbox 's search functionality accepts a “pathnameroot” parameter, which can be set to network locations using UNC ... 2026-08-07 7.7 NETWORK HIGH NVD
CVE-2026-54203 Memory Leak to an Unauthorized Actor vulnerability in Tobit Laboratories AG TeamDavid's Webbox allows reading of sensitive information. When accessing... 2026-08-07 9.2 NETWORK CRITICAL NVD
CVE-2026-54202 Tobit Laboratories AG TeamDavid's Webbox is vulnerable to a path traversal vulnerability in the archive creation functionality. Because the archive ... 2026-08-07 8.5 NETWORK HIGH NVD