Home
Home
Trends
Trends
Vulnerabilities
Vulnerabilities
News
News
Researchers
Researchers
Why dbugs?
Why dbugs?
Settings

Ox882

#21727of 55,137
11.8Total CVSS
Vulnerabilities · 2
Medium
2
PT-2026-67446
5.3
2026-08-03
Newtype · Webeip · CVE-2026-18610
A vulnerability was detected in NewType WebEIP up to 3.0. This affects an unknown part of the file /EIP Com FileList.aspx. The manipulation results in improper authentication. It is possible to launch the attack remotely. The exploit is now public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
PT-2026-47176
6.5
2026-06-07
Tiobon · Tiobon Employee Self-Service System · CVE-2026-11453
**Name of the Vulnerable Software and Affected Versions** Tiobon Employee Self-Service System versions prior to 7.3 **Description** A SQL injection issue exists in the Login Endpoint component within the '/Blog/BlogSearch.aspx' endpoint. Remote attackers can exploit this by manipulating the `Keyword` argument. SQL injection is a technique where malicious SQL statements are inserted into entry fields for execution, potentially allowing unauthorized access to the database. **Recommendations** At the moment, there is no information about a newer version that contains a fix for this vulnerability. Avoid using the `Keyword` argument in the '/Blog/BlogSearch.aspx' endpoint to minimize the risk of exploitation.