Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

TeamDavid — Vulnerabilities & Security Advisories 22

All 22 CVE vulnerabilities found in TeamDavid, with AI-generated Chinese analysis, references, and POCs.

TeamDavid is a cybersecurity solution developed by TeamDavid Corporation that manages endpoint security and threat intelligence across enterprise networks. This vulnerability aggregation page compiles a comprehensive list of known security weaknesses, including Common Weakness Enumerations (CWEs) and associated Common Vulnerabilities and Exposures (CVEs), specifically affecting TeamDavid software and its integrated components. The data spans from the initial public release of the product up to the most recent disclosures, ensuring that historical context and emerging risks are both accessible to security professionals. Users can utilize this resource to track a vendor's advisories by reviewing how TeamDavid addresses specific threats over time, understand a weakness class by examining the root causes and mitigation strategies documented in the reports, and look up a product's vulnerability history to assess the overall security posture and patching cadence. This page serves as a centralized reference for analysts, auditors, and IT administrators who need to evaluate the risk landscape associated with TeamDavid products. By consolidating these details, the page facilitates informed decision-making regarding system updates and defensive configurations. It is designed to provide transparent, factual information without interpretation, allowing users to verify the status of known issues and compare them against industry benchmarks. The content is regularly updated to reflect the latest findings from security researchers and official vendor notifications.

Vendor: Tobit Laboratories AG

CVE IDTitleCVSSSeverityPublished
CVE-2026-54205 TeamDavid: Server-Side Request Forgery (SSRF) via 'pathname' parameter in link storing functionality CWE-20 6.3 Medium2026-08-07
CVE-2026-54218 TeamDavid: Weak Cryptography and Insecure Password Storage CWE-321 8.8 High2026-08-07
CVE-2026-54217 TeamDavid: Stored XSS in web application CWE-20 5.3 Medium2026-08-07
CVE-2026-54216 TeamDavid: Reflected Cross Site Scripting (XSS) via the 'EntryInfo' parameter CWE-79 5.3 Medium2026-08-07
CVE-2026-54215 TeamDavid: Open Redirect via the 'replyUrl' parameter CWE-601 5.3 Medium2026-08-07
CVE-2026-54214 TeamDavid: Header Injection through the 'cType' URL parameter CWE-601 5.3 Medium2026-08-07
CVE-2026-54213 TeamDavid: Denial of Service via endpoint 'internalRestart' CWE-284 9.2 Critical2026-08-07
CVE-2026-54212 TeamDavid: Buffer Overflow in JSON-parsing CWE-787 9.5 Critical2026-08-07
CVE-2026-54211 TeamDavid: Buffer Overflow in multiple form data parameters CWE-787 9.5 Critical2026-08-07
CVE-2026-54210 TeamDavid: Buffer Overflow in file names of file upload functionalities CWE-787 9.5 Critical2026-08-07
CVE-2026-54209 TeamDavid: Buffer Overflow in 'editini' function CWE-125 8.9 High2026-08-07
CVE-2026-54208 TeamDavid: Arbitrary File Write leading to Stored XSS CWE-20 8.5 High2026-08-07
CVE-2026-54207 TeamDavid: Server-Side Request Forgery (SSRF) via 'pathname' parameter in move archive functionality CWE-20 6.3 Medium2026-08-07
CVE-2026-54206 TeamDavid: Server-Side Request Forgery (SSRF) via 'pathname' parameter in sending functionality CWE-20 6.3 Medium2026-08-07
CVE-2026-54204 TeamDavid: Server-Side Request Forgery (SSRF) via 'pathnameroot' parameter in search functionality CWE-20 7.7 High2026-08-07
CVE-2026-54203 TeamDavid: Memory Leak leaking sensitive information CWE-200 9.2 Critical2026-08-07
CVE-2026-54202 TeamDavid: Path Traversal in the archive creation functionality CWE-36 8.5 High2026-08-07
CVE-2026-54201 TeamDavid: Missing Authorization CWE-862 6.9 Medium2026-08-07
CVE-2026-54200 TeamDavid: Local File Inclusion via the form field 'scjob' CWE-73 8.4 High2026-08-07
CVE-2026-54199 TeamDavid: Header Injection through request body in link storing functionality CWE-20 5.3 Medium2026-08-07
CVE-2026-12071 TeamDavid: Header Injection leading to Open Redirect via URL-encoded characters CWE-601 5.3 Medium2026-08-07
CVE-2026-12070 TeamDavid: Arbitrary File Deletion via form field 'scjob' CWE-73 8.4 High2026-08-07

All 22 known CVE vulnerabilities affecting TeamDavid with full Chinese analysis, references, and POCs where available.