Home
Home
Trends
Trends
Vulnerabilities
Vulnerabilities
News
News
Researchers
Researchers
Why dbugs?
Why dbugs?
Settings

Olivier Becker

#21922of 56,338
12.4Total CVSS
Vulnerabilities · 2
Medium
1
High
1
PT-2026-68893
5.3
2026-08-07
Teamdavid · Teamdavid · CVE-2026-12071
**Name of the Vulnerable Software and Affected Versions** TeamDavid versions prior to Rollout 525 **Description** The Webbox component constructs redirect URLs using user-supplied input appended to the redirect target in a 302 HTTP response. An attacker can use URL-encoded characters, such as `%2e` (representing a dot), to manipulate the URL portion following the top-level domain (TLD). This allows the redirection of users to a malicious domain if a similar registerable TLD exists. Additionally, the use of URL-encoded line feeds enables the insertion of arbitrary response headers in the server's HTTP response, a technique known as header injection. **Recommendations** Update TeamDavid to a version later than Rollout 524.
PT-2026-50652
7.1
2026-06-18
Seppmail · Seppmail · CVE-2026-8811
**Name of the Vulnerable Software and Affected Versions** SEPPmail versions prior to 15.0.5 **Description** Improper handling of attachment filenames during encrypted PDF generation allows an attacker to perform path traversal, which is a technique used to access files and directories that are stored outside the web root folder. This can result in the creation of new files outside the intended directory, potentially placing them in web-accessible locations. **Recommendations** Update to version 15.0.5.