VendorsTobesoftxplatformall versions
Vulnerabilities

Tobesoft Xplatform

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

11CVEs
CVE-2020-7815
XPLATFORM v9.2.260 and eariler versions contain a vulnerability that could allow remote files to be downloaded by setting the arguments to the vulnerable method. this can be leveraged for code execution. File download vulnerability in ____COMPONENT____ of TOBESOFT XPLATFORM allows ____ATTACKER/ATTACK____ to cause ____IMPACT____. This issue affects: TOBESOFT XPLATFORM 9.2.250 versions prior to 9.2.260 on Windows.
Published 2020-07-10 · Modified
9.8EPSS 0.012
CVE-2020-7857
A vulnerability of XPlatform could allow an unauthenticated attacker to execute arbitrary command. This vulnerability exists due to insufficient validation of improper classes. This issue affects: Tobesoft XPlatform versions prior to 9.2.2.280.
Published 2021-04-20 · Modified
9.8EPSS 0.010
CVE-2020-7866
Tobesoft XPLATFORM Arbitrary Command Execution Vulnerability
Published 2021-07-20 · Modified
9.8EPSS 0.010
CVE-2020-7853
TOBESOFT XPLATFORM Out-of-Bounds Read/Write Vulnerabilities
Published 2021-03-24 · Modified
9.8EPSS 0.008
CVE-2020-7806
Tobesoft Xplatform ActiveX File Download Vulnerability
Published 2020-05-06 · Modified
9.8EPSS 0.007
CVE-2020-7841
TOBESOFT XPLATFORM arbitrary hta file execution vulnerability
Published 2020-11-17 · Modified
8.8EPSS 0.016
CVE-2021-26629
tobesoft XPLATFORM Path Traversal Vulnerability
Published 2022-04-26 · Modified
8.8EPSS 0.016
CVE-2021-26626
tobesoft XPLATFORM Arbitrary file execution Vulnerability
Published 2022-04-19 · Modified
8.8EPSS 0.013
CVE-2019-19162
A use-after-free vulnerability in the TOBESOFT XPLATFORM versions 9.1 to 9.2.2 may lead to code execution on a system running it.
Published 2020-05-11 · Modified
7.8EPSS 0.012
CVE-2018-5197
A vulnerability in the ExtCommon.dll user extension module version 9.2, 9.2.1, 9.2.2 of Xplatform ActiveX could allow attacker to perform a command injection attack. The vulnerability is due to insufficient input validation of command parameters. An crafted malicious parameters could cause arbitrary command to execute.
Published 2019-01-02 · Modified
7.8EPSS 0.011
CVE-2019-19166
Tobesoft XPlatform Arbitrary File Execution Vulnerability
Published 2020-05-06 · Modified
7.8EPSS 0.004