TOBESOFT records
18 published records for vendor tobesoft.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 10
- With a fix record
- 0%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-20 Improper Input Validation7
- CWE-494 Download of Code Without Integrity Check4
- CWE-345 Insufficient Verification of Data Authenticity1
- CWE-416 Use After Free1
- CWE-470 Use of Externally-Controlled Input to Select Classes or Code ('Unsafe Reflection')1
- CWE-125 Out-of-bounds Read1
The weakness classes this vendor ships most often: where to look.
CWEAll records
18 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
40Plan | CVE-2020-7825No exploit | A vulnerability exists that could allow the execution of operating system commands on systems running MiPlatform 2019.05.16 and earlier.tobesoft · miplatform · CWE-78 | Critical9.8 | — | 2.1% | Jul 17, 2020 |
40Plan | CVE-2021-26607No exploit | TOBESOFT NEXACRO17 arbitrary command execution vulnerabilitytobesoft · nexacro · CWE-20 | Critical9.8 | — | 1.9% | Oct 26, 2021 |
39Monitor | CVE-2021-26612No exploit | tobesoft Nexacro platform arbitrary file creation vulnerabilitytobesoft · nexacro · CWE-20 | Critical9.8 | — | 1.2% | Nov 30, 2021 |
39Monitor | CVE-2020-7815No exploit | XPLATFORM v9.2.260 and eariler versions contain a vulnerability that could allow remote files to be downloaded by setting the arguments to ttobesoft · xplatform | Critical9.8 | — | 1.2% | Jul 10, 2020 |
39Monitor | CVE-2020-7857No exploit | A vulnerability of XPlatform could allow an unauthenticated attacker to execute arbitrary command.tobesoft · xplatform · CWE-470 | Critical9.8 | — | 1.0% | Apr 20, 2021 |
39Monitor | CVE-2020-7866No exploit | Tobesoft XPLATFORM Arbitrary Command Execution Vulnerabilitytobesoft · xplatform · CWE-20 | Critical9.8 | — | 1.0% | Jul 20, 2021 |
39Monitor | CVE-2020-7853No exploit | TOBESOFT XPLATFORM Out-of-Bounds Read/Write Vulnerabilitiestobesoft · xplatform · CWE-125 | Critical9.8 | — | 0.8% | Mar 24, 2021 |
39Monitor | CVE-2020-7806No exploit | Tobesoft Xplatform ActiveX File Download Vulnerabilitytobesoft · xplatform · CWE-494 | Critical9.8 | — | 0.7% | May 6, 2020 |
39Monitor | CVE-2019-19167No exploit | Tobesoft Nexacro14 ActiveX File Download Vulnerabilitytobesoft · nexacro · CWE-494 | Critical9.8 | — | 0.7% | May 6, 2020 |
35Monitor | CVE-2020-7841No exploit | TOBESOFT XPLATFORM arbitrary hta file execution vulnerabilitytobesoft · xplatform · CWE-20 | High8.8 | — | 1.6% | Nov 17, 2020 |
35Monitor | CVE-2021-26629No exploit | tobesoft XPLATFORM Path Traversal Vulnerabilitytobesoft · xplatform · CWE-22 | High8.8 | — | 1.6% | Apr 26, 2022 |
35Monitor | CVE-2021-26626No exploit | tobesoft XPLATFORM Arbitrary file execution Vulnerabilitytobesoft · xplatform · CWE-20 | High8.8 | — | 1.3% | Apr 19, 2022 |
35Monitor | CVE-2021-26625No exploit | tobesoft Nexacro arbitrary file download vulnerabilitytobesoft · nexacro · CWE-345 | High8.8 | — | 0.6% | Apr 19, 2022 |
35Monitor | CVE-2020-7874No exploit | NEXACRO14 Runtime arbitrary file download and execution vulnerabilitytobesoft · nexacro · CWE-494 | High8.8 | — | 0.6% | Sep 9, 2021 |
31Monitor | CVE-2019-19162No exploit | A use-after-free vulnerability in the TOBESOFT XPLATFORM versions 9.1 to 9.2.2 may lead to code execution on a system running it.tobesoft · xplatform · CWE-416 | High7.8 | — | 1.2% | May 11, 2020 |
31Monitor | CVE-2018-5197No exploit | A vulnerability in the ExtCommon.dll user extension module version 9.2, 9.2.1, 9.2.2 of Xplatform ActiveX could allow attacker to perform a tobesoft · xplatform · CWE-20 | High7.8 | — | 1.1% | Jan 2, 2019 |
31Monitor | CVE-2019-19166No exploit | Tobesoft XPlatform Arbitrary File Execution Vulnerabilitytobesoft · xplatform · CWE-494 | High7.8 | — | 0.4% | May 6, 2020 |
30Monitor | CVE-2021-26613No exploit | tobesoft nexacro arbitrary file creation vulnerabilitytobesoft · nexacro · CWE-20 | High7.5 | — | 0.8% | Feb 9, 2022 |
- CVE-2020-782540Plan
A vulnerability exists that could allow the execution of operating system commands on systems running MiPlatform 2019.05.16 and earlier.
CriticalCVSS 9.8No exploitEPSS 2%tobesoft · miplatformJul 17, 2020
- CVE-2021-2660740Plan
TOBESOFT NEXACRO17 arbitrary command execution vulnerability
CriticalCVSS 9.8No exploitEPSS 2%tobesoft · nexacroOct 26, 2021
- CVE-2021-2661239Monitor
tobesoft Nexacro platform arbitrary file creation vulnerability
CriticalCVSS 9.8No exploitEPSS 1%tobesoft · nexacroNov 30, 2021
- CVE-2020-781539Monitor
XPLATFORM v9.2.260 and eariler versions contain a vulnerability that could allow remote files to be downloaded by setting the arguments to t
CriticalCVSS 9.8No exploitEPSS 1%tobesoft · xplatformJul 10, 2020
- CVE-2020-785739Monitor
A vulnerability of XPlatform could allow an unauthenticated attacker to execute arbitrary command.
CriticalCVSS 9.8No exploitEPSS 1%tobesoft · xplatformApr 20, 2021
- CVE-2020-786639Monitor
Tobesoft XPLATFORM Arbitrary Command Execution Vulnerability
CriticalCVSS 9.8No exploitEPSS 1%tobesoft · xplatformJul 20, 2021
- CVE-2020-785339Monitor
TOBESOFT XPLATFORM Out-of-Bounds Read/Write Vulnerabilities
CriticalCVSS 9.8No exploitEPSS 1%tobesoft · xplatformMar 24, 2021
- CVE-2020-780639Monitor
Tobesoft Xplatform ActiveX File Download Vulnerability
CriticalCVSS 9.8No exploitEPSS 1%tobesoft · xplatformMay 6, 2020
- CVE-2019-1916739Monitor
Tobesoft Nexacro14 ActiveX File Download Vulnerability
CriticalCVSS 9.8No exploitEPSS 1%tobesoft · nexacroMay 6, 2020
- CVE-2020-784135Monitor
TOBESOFT XPLATFORM arbitrary hta file execution vulnerability
HighCVSS 8.8No exploitEPSS 2%tobesoft · xplatformNov 17, 2020
- CVE-2021-2662935Monitor
tobesoft XPLATFORM Path Traversal Vulnerability
HighCVSS 8.8No exploitEPSS 2%tobesoft · xplatformApr 26, 2022
- CVE-2021-2662635Monitor
tobesoft XPLATFORM Arbitrary file execution Vulnerability
HighCVSS 8.8No exploitEPSS 1%tobesoft · xplatformApr 19, 2022
- CVE-2021-2662535Monitor
tobesoft Nexacro arbitrary file download vulnerability
HighCVSS 8.8No exploitEPSS 1%tobesoft · nexacroApr 19, 2022
- CVE-2020-787435Monitor
NEXACRO14 Runtime arbitrary file download and execution vulnerability
HighCVSS 8.8No exploitEPSS 1%tobesoft · nexacroSep 9, 2021
- CVE-2019-1916231Monitor
A use-after-free vulnerability in the TOBESOFT XPLATFORM versions 9.1 to 9.2.2 may lead to code execution on a system running it.
HighCVSS 7.8No exploitEPSS 1%tobesoft · xplatformMay 11, 2020
- CVE-2018-519731Monitor
A vulnerability in the ExtCommon.dll user extension module version 9.2, 9.2.1, 9.2.2 of Xplatform ActiveX could allow attacker to perform a
HighCVSS 7.8No exploitEPSS 1%tobesoft · xplatformJan 2, 2019
- CVE-2019-1916631Monitor
Tobesoft XPlatform Arbitrary File Execution Vulnerability
HighCVSS 7.8No exploitEPSS 0%tobesoft · xplatformMay 6, 2020
- CVE-2021-2661330Monitor
tobesoft nexacro arbitrary file creation vulnerability
HighCVSS 7.5No exploitEPSS 1%tobesoft · nexacroFeb 9, 2022