Skip to main content

Threat Intelligence Database

Comprehensive database of the latest cyber threats affecting organizations worldwide. Filter and search to find specific threat intelligence relevant to your organization.

Pro Console Lifetime

Stop chasing alerts. Route them.

Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.

Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)

View Plans & Pricing

API access activates after upgrading in Console -> Billing.

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now

Filter Threats

Narrow down the results by type, severity, or affected countries

Search threats by title, CVE ID, or description. Maximum 100 characters.
Active filters (1):Package: pkg:github/toptech-systems/tms7

Threat Intelligence

Click on any threat for detailed analysis and mitigation recommendations

0

CVE-2026-71189 is a cross-site scripting (XSS) vulnerability in Toptech Systems TMS7 version 7.6.3. An attacker can craft a request that, when executed by another user, causes attacker-supplied JavaScript to run in the victim's browser within their session context. The vulnerability has a low CVSS score of 3.5, indicating limited impact. There is no information on available patches or vendor advisories. No known exploits are reported in the wild.

Join the discussion
0

CVE-2026-69662 is a low-severity vulnerability in Toptech Systems TMS7 version 7.6.3 involving unsafe use of inline script execution and string evaluation functions. This flaw could potentially allow limited unauthorized code execution due to unsafe function usage. The vulnerability has a CVSS score of 3.7, indicating low impact with low confidentiality and integrity impact and no availability impact. No known exploits are reported in the wild, and no official patch or remediation guidance is currently available.

Join the discussion
0

CVE-2026-71302 is a vulnerability in Toptech Systems TMS7 version 7.6.3 where the application accepts user-supplied session identifiers and fails to regenerate the session ID after authentication. This flaw allows an attacker to set a session ID before victim login and reuse it afterward, enabling session takeover.

Join the discussion
0

CVE-2026-72507 is a critical time-based blind SQL injection vulnerability in Toptech Systems TMS7 version 7.6.3. It affects the "reportType" parameter in the product summary report feature within the balancing reports section. This vulnerability allows an attacker with high privileges to execute unauthorized SQL queries, potentially leading to significant data confidentiality, integrity, and availability impacts.

Join the discussion
0

CVE-2026-68068 is a critical time-based blind SQL injection vulnerability in Toptech Systems TMS7 version 7.6.3. It affects the "screenID" parameter in the electronic transaction queue viewer feature within the manual transactions section. The vulnerability allows an attacker with high privileges to execute unauthorized SQL queries, potentially leading to high confidentiality impact, limited integrity impact, and high availability impact.

Join the discussion
0

CVE-2026-68954 is a critical time-based blind SQL injection vulnerability in the 'pattern' parameter of the search function on the home page of Toptech Systems TMS7 version 7.6.3. This vulnerability allows an attacker with high privileges to execute unauthorized SQL queries, potentially leading to high confidentiality impact, limited integrity impact, and high availability impact.

Join the discussion
0

CVE-2026-63713 is a critical time-based blind SQL injection vulnerability in Toptech Systems TMS7 version 7.6.3. It affects the "search" parameter in the view audit logs feature within the utilities section. This vulnerability allows an attacker with high privileges to execute unauthorized SQL queries, potentially leading to high confidentiality impact, limited integrity impact, and high availability impact.

Join the discussion
0

CVE-2026-72510 is a critical SQL injection vulnerability in Toptech Systems TMS7 version 7.6.3. The issue exists in the "supplier_no" parameter of the business allocation search feature, allowing time-based blind SQL injection attacks. This vulnerability can lead to high confidentiality impact, partial integrity compromise, and high availability impact. No patch or official fix information is currently provided.

Join the discussion
0

CVE-2026-70356 is a critical vulnerability in Toptech Systems TMS7 version 7.6.3 where the file upload endpoint does not enforce server-side file type restrictions. This flaw allows an attacker with high privileges to upload and execute arbitrary PHP files on the web server, potentially leading to full compromise of confidentiality, integrity, and availability.

Join the discussion
0

CVE-2026-71379 is a critical vulnerability in Toptech Systems TMS7 version 7.6.3 where the file export endpoint allows unauthenticated attackers to export arbitrary database tables via crafted POST requests. This flaw leads to complete confidentiality, integrity, and availability compromise of the affected system.

Join the discussion

Showing 1 to 10 of 10 results

Filters:Package: pkg:github/toptech-systems/tms7
Page 1 of 1
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses