Loading HuntDB...

Tobesoft

10 Products 16 CVEs

CVE Severity Distribution (All Time)

Critical
0
High
14
Medium
1
Low
0

Timeline Overview

Last 30 Days 0 CVEs
Last 6 Months 0 CVEs
Last Year 0 CVEs

Recent CVEs

View all
CVE-2021-26612 HIGH 3 years, 9 months ago

An improper input validation leading to arbitrary file creation was discovered in copy method of Nexacro platform. Remote attackers use copy method t…

CVE-2021-26607 HIGH 3 years, 10 months ago

An Improper input validation in execDefaultBrowser method of NEXACRO17 allows a remote attacker to execute arbitrary command on affected systems.

CVE-2020-7874 HIGH 4 years ago

Download of code without integrity check vulnerability in NEXACRO14 Runtime ActiveX control of tobesoft Co., Ltd allows the attacker to cause an arbi…

CVE-2020-7866 HIGH 4 years, 1 month ago

When using XPLATFORM 9.2.2.270 or earlier versions ActiveX component, arbitrary commands can be executed due to improper input validation

CVE-2020-7857 HIGH 4 years, 4 months ago

A vulnerability of XPlatform could allow an unauthenticated attacker to execute arbitrary command. This vulnerability exists due to insufficient vali…

CVE-2020-7853 MEDIUM 4 years, 5 months ago

An outbound read/write vulnerability exists in XPLATFORM that does not check offset input ranges, allowing out-of-range data to be read. An attacker …

CVE-2020-7841 HIGH 4 years, 9 months ago

Improper input validation vulnerability exists in TOBESOFT XPLATFORM which could cause arbitrary .hta file execution when the command string is begun…

CVE-2020-7825 HIGH 5 years, 1 month ago

A vulnerability exists that could allow the execution of operating system commands on systems running MiPlatform 2019.05.16 and earlier. An attacker …

CVE-2020-7815 HIGH 5 years, 2 months ago

XPLATFORM v9.2.260 and eariler versions contain a vulnerability that could allow remote files to be downloaded by setting the arguments to the vulner…

CVE-2020-7820 HIGH 5 years, 2 months ago

Nexacro14/17 ExtCommonApiV13 Library under 2019.9.6 version contain a vulnerability that could allow remote attacker to execute arbitrary code by set…