Sbond maintains a focused application portfolio centered on the Watcharr media management product, with the durable signal centered on data-transmission and session-handling issues such as cleartext transmission of sensitive information and insufficient session expiration. Treat this as a compact vendor profile rather than a broad trend line; live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Sbond over time
Signals from CVEs in this vendor scope (2 CVEs).
2 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2024-48827HIGH An issue in sbondCo Watcharr v.1.43.0 allows a remote attacker to execute arbitrary code and escalate privileges via the Change Password function. | Oct 11, 2024 | 8.8 | 37 | NO | YES |
CVE-2024-50634HIGH A vulnerability in a weak JWT token in Watcharr v1.43.0 and below allows attackers to perform privilege escalation using a crafted JWT token. This vulnerability is not limited to p | Nov 8, 2024 | 8.8 | 24 | NO | NO |
Signals from CVEs in this vendor scope (2 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Sbond.
Media articles that mention a CVE ID that affects a product developed by Sbond — matched by CVE ID, not by vendor name.