VYPR
Vendor

Cybozu

Cybozu, Inc. is a Tokyo-based software company that provides web-based groupware services including Cybozu Office and kintone. In addition to the main office in Tokyo, Cybozu also has offices in Matsuyama and Osaka, as well as several overseas subsidiaries in countries including Vietnam, China, Australia and the United States. The U.S.-based subsidiary, kintone Corporation, is located in San Francisco, California.

Founded 1997
Products
31
CVEs
331
Across products
383
Status
Private

Products

31
View all 31 products →

Recent CVEs

331
View all 331 CVEs →
  • CVE-2020-5537CriMay 25, 2020
    risk 0.64cvss 9.8epss 0.03

    Cybozu Desktop for Windows 2.0.23 to 2.2.40 allows remote code execution via unspecified vectors.

  • CVE-2019-5945CriMay 17, 2019
    risk 0.64cvss 9.8epss 0.02

    Cybozu Garoon 4.2.4 to 4.10.1 allow remote attackers to obtain the users' credential information via the authentication of Cybozu Garoon.

  • CVE-2016-1219CriApr 20, 2017
    risk 0.64cvss 9.8epss 0.03

    Cybozu Garoon before 4.2.2 allows remote attackers to bypass login authentication via vectors related to API use.

  • CVE-2024-31401CriJun 11, 2024
    risk 0.59cvss 9.0epss 0.01

    Cross-site scripting vulnerability in Cybozu Garoon 5.0.0 to 5.15.2 allows a remote authenticated attacker with an administrative privilege to inject an arbitrary script on the web browser of the user who is logging in to the product.

  • CVE-2018-0705CriJan 9, 2019
    risk 0.59cvss 9.1epss 0.02

    Directory traversal vulnerability in Cybozu Dezie 8.0.2 to 8.1.2 allows remote attackers to read arbitrary files via HTTP requests.

  • CVE-2021-20795HigOct 13, 2021
    risk 0.57cvss 8.8epss 0.01

    Cross-site request forgery (CSRF) vulnerability in the management screen of Cybozu Remote Service 3.1.8 to 3.1.9 allows a remote attacker to hijack the authentication of administrators and unintended operations may be performed via unspecified vectors.

  • CVE-2019-5931HigMay 17, 2019
    risk 0.57cvss 8.7epss 0.01

    Cybozu Garoon 4.0.0 to 4.6.3 allows authenticated attackers to alter the information with privileges invoking the installer via unspecified vectors.

  • CVE-2018-16171HigJan 9, 2019
    risk 0.57cvss 8.8epss 0.02

    Directory traversal vulnerability in Cybozu Remote Service 3.0.0 to 3.1.8 allows remote attackers to execute Java code file on the server via unspecified vectors.

  • CVE-2018-16169HigJan 9, 2019
    risk 0.57cvss 8.8epss 0.01

    Cybozu Remote Service 3.0.0 to 3.1.0 allows remote authenticated attackers to upload and execute Java code file on the server via unspecified vectors.

  • CVE-2018-0607HigJul 26, 2018
    risk 0.57cvss 8.8epss 0.01

    SQL injection vulnerability in the Notifications application in the Cybozu Garoon 3.5.0 to 4.6.2 allows remote authenticated attackers to execute arbitrary SQL commands via unspecified vectors.

  • CVE-2018-0530HigApr 16, 2018
    risk 0.57cvss 8.8epss 0.01

    SQL injection vulnerability in the Cybozu Garoon 3.5.0 to 4.2.6 allows remote authenticated attackers to execute arbitrary SQL commands via unspecified vectors.

  • CVE-2016-7803HigJun 9, 2017
    risk 0.57cvss 8.8epss 0.02

    SQL injection vulnerability in the Cybozu Garoon 3.0.0 to 4.2.2 allows remote authenticated attackers to execute arbitrary SQL commands via "MultiReport" function.

  • CVE-2016-4907HigJun 9, 2017
    risk 0.57cvss 8.8epss 0.01

    Cybozu Garoon 3.0.0 to 4.2.2 allow remote attackers to obtain CSRF tokens via unspecified vectors.

  • CVE-2016-1218HigApr 20, 2017
    risk 0.57cvss 8.8epss 0.02

    SQL injection vulnerability in Cybozu Garoon before 4.2.2.

  • CVE-2016-1151HigFeb 17, 2016
    risk 0.57cvss 8.8epss 0.01

    Multiple cross-site request forgery (CSRF) vulnerabilities in Cybozu Office 9.9.0 through 10.3.0 allow remote attackers to hijack the authentication of arbitrary users.

  • CVE-2022-30602HigJul 11, 2022
    risk 0.53cvss 8.1epss 0.01

    Operation restriction bypass in multiple applications of Cybozu Garoon 4.0.0 to 5.9.1 allows a remote authenticated attacker to alter the file information and/or delete the files.

  • CVE-2022-29484HigJul 4, 2022
    risk 0.53cvss 8.1epss 0.01

    Operation restriction bypass vulnerability in Space of Cybozu Garoon 4.0.0 to 5.9.0 allows a remote authenticated attacker to delete the data of Space.

  • CVE-2020-5580HigJun 30, 2020
    risk 0.53cvss 8.1epss 0.01

    Cybozu Garoon 4.0.0 to 5.0.1 allows remote authenticated attackers to bypass access restriction to view and/or alter Single sign-on settings via unspecified vectors.

  • CVE-2018-16170HigJan 9, 2019
    risk 0.53cvss 8.1epss 0.02

    Directory traversal vulnerability in Cybozu Remote Service 3.0.0 to 3.1.8 for Windows allows remote authenticated attackers to read arbitrary files via unspecified vectors.

  • CVE-2018-0673HigNov 15, 2018
    risk 0.53cvss 8.1epss 0.01

    Directory traversal vulnerability in Cybozu Garoon 3.5.0 to 4.6.3 allows authenticated attackers to read arbitrary files via unspecified vectors.