Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

TeamDavid — Vulnerabilities & Security Advisories 22

All 22 CVE vulnerabilities found in TeamDavid, with AI-generated Chinese analysis, references, and POCs.

This page provides an aggregated view of security vulnerabilities associated with the TeamDavid product line, categorized under general software weaknesses and tagged for easy navigation. The content encompasses a comprehensive collection of reported security flaws, ranging from critical remote code execution risks to minor configuration errors and information disclosure issues. This database covers incidents reported from the early years of the product’s release through recent months, ensuring a historical perspective on its security posture over time. Users can utilize this resource to track a vendor's advisories by monitoring publication dates and severity ratings, understand a specific weakness class by analyzing recurring patterns in the codebase or configuration, or look up a product's vulnerability history to assess long-term stability and response effectiveness. By consolidating disparate reports into a single interface, the platform aims to reduce noise and highlight trends that might otherwise be missed in isolated CVE entries. This approach facilitates deeper analysis for security professionals, developers, and system administrators who need to prioritize patching efforts and understand the broader context of TeamDavid's exposure. The data is structured to support both broad trend identification and granular investigation, allowing stakeholders to make informed decisions regarding risk mitigation. Whether reviewing past incidents to validate remediation steps or monitoring new disclosures for immediate action, this aggregation serves as a central reference point for managing TeamDavid-related security risks effectively.

Vendor: Tobit Laboratories AG

CVE ID Title CVSS Severity Published
CVE-2026-54205 TeamDavid: Server-Side Request Forgery (SSRF) via 'pathname' parameter in link storing functionality CWE-20 6.3 Medium 2026-08-07
CVE-2026-54218 TeamDavid: Weak Cryptography and Insecure Password Storage CWE-321 8.8 High 2026-08-07
CVE-2026-54217 TeamDavid: Stored XSS in web application CWE-20 5.3 Medium 2026-08-07
CVE-2026-54216 TeamDavid: Reflected Cross Site Scripting (XSS) via the 'EntryInfo' parameter CWE-79 5.3 Medium 2026-08-07
CVE-2026-54215 TeamDavid: Open Redirect via the 'replyUrl' parameter CWE-601 5.3 Medium 2026-08-07
CVE-2026-54214 TeamDavid: Header Injection through the 'cType' URL parameter CWE-601 5.3 Medium 2026-08-07
CVE-2026-54213 TeamDavid: Denial of Service via endpoint 'internalRestart' CWE-284 9.2 Critical 2026-08-07
CVE-2026-54212 TeamDavid: Buffer Overflow in JSON-parsing CWE-787 9.5 Critical 2026-08-07
CVE-2026-54211 TeamDavid: Buffer Overflow in multiple form data parameters CWE-787 9.5 Critical 2026-08-07
CVE-2026-54210 TeamDavid: Buffer Overflow in file names of file upload functionalities CWE-787 9.5 Critical 2026-08-07
CVE-2026-54209 TeamDavid: Buffer Overflow in 'editini' function CWE-125 8.9 High 2026-08-07
CVE-2026-54208 TeamDavid: Arbitrary File Write leading to Stored XSS CWE-20 8.5 High 2026-08-07
CVE-2026-54207 TeamDavid: Server-Side Request Forgery (SSRF) via 'pathname' parameter in move archive functionality CWE-20 6.3 Medium 2026-08-07
CVE-2026-54206 TeamDavid: Server-Side Request Forgery (SSRF) via 'pathname' parameter in sending functionality CWE-20 6.3 Medium 2026-08-07
CVE-2026-54204 TeamDavid: Server-Side Request Forgery (SSRF) via 'pathnameroot' parameter in search functionality CWE-20 7.7 High 2026-08-07
CVE-2026-54203 TeamDavid: Memory Leak leaking sensitive information CWE-200 9.2 Critical 2026-08-07
CVE-2026-54202 TeamDavid: Path Traversal in the archive creation functionality CWE-36 8.5 High 2026-08-07
CVE-2026-54201 TeamDavid: Missing Authorization CWE-862 6.9 Medium 2026-08-07
CVE-2026-54200 TeamDavid: Local File Inclusion via the form field 'scjob' CWE-73 8.4 High 2026-08-07
CVE-2026-54199 TeamDavid: Header Injection through request body in link storing functionality CWE-20 5.3 Medium 2026-08-07
CVE-2026-12071 TeamDavid: Header Injection leading to Open Redirect via URL-encoded characters CWE-601 5.3 Medium 2026-08-07
CVE-2026-12070 TeamDavid: Arbitrary File Deletion via form field 'scjob' CWE-73 8.4 High 2026-08-07

All 22 known CVE vulnerabilities affecting TeamDavid with full Chinese analysis, references, and POCs where available.