Pinchtab

    Dashboard / Vendors

    Products: 1
    Vulnerabilities: 7
    Known Exploited: 0
    0
    Critical Level Threats
    2
    High Level Threats
    5
    Medium Level Threats
    0
    Low Level Threats

    Vulnerabilities

    100806040200
    JanFebMarAprMayJunJulAugSepOctNovDec
    Critical Level Threats
    High Level Threats
    Medium Level Threats
    Low Level Threats

    Products Security index

    Actions
    Items Per Page

    Vulnerabilities

    CVE-2026-33623

    PinchTab: OS Command Injection via Profile Name in Windows Cleanup Routine Enables Arbitrary Command Execution

    Last Modified: Mar 31, 2026
    Published: Mar 26, 2026

    CVE-2026-33622

    A PinchTab Security Policy Bypass in /wait Allows Arbitrary JavaScript Execution

    Last Modified: Mar 31, 2026
    Published: Mar 26, 2026

    CVE-2026-33621

    PinchTab: Unapplied Rate Limiting Middleware Allows Unbounded Brute-Force of API Token

    Last Modified: Apr 22, 2026
    Published: Mar 26, 2026

    CVE-2026-33620

    PinchTab: API Bearer Token Exposed in URL Query Parameter via Server Logs and Intermediary Systems

    Last Modified: Mar 31, 2026
    Published: Mar 26, 2026

    CVE-2026-33619

    PinchTab has Unauthenticated Blind SSRF in Task Scheduler via Unvalidated callbackUrl

    Last Modified: Apr 22, 2026
    Published: Mar 26, 2026
    Items Per Page
    Pinchtab Vulnerabilities & Security CVEs | CVE-DB