Vulnerabilities > Tobesoft > Critical

DATE CVE VULNERABILITY TITLE RISK
2021-10-26 CVE-2021-26607 Improper Input Validation vulnerability in Tobesoft Nexacro
An Improper input validation in execDefaultBrowser method of NEXACRO17 allows a remote attacker to execute arbitrary command on affected systems.
network
low complexity
tobesoft CWE-20
critical
10.0
2020-07-17 CVE-2020-7825 OS Command Injection vulnerability in Tobesoft Miplatform 2019.05.16
A vulnerability exists that could allow the execution of operating system commands on systems running MiPlatform 2019.05.16 and earlier.
network
low complexity
tobesoft CWE-78
critical
10.0