VYPR

Vendor CVEs

Cybozu

All CVEs

332 total · sorted by risk
  • CVE-2022-28713Jul 4, 2022
    risk 0.00cvss epss 0.01

    Improper authentication vulnerability in Scheduler of Cybozu Garoon 4.10.0 to 5.5.1 allows a remote attacker to obtain some data of Facility Information without logging in to the product.

  • CVE-2022-28692Jul 4, 2022
    risk 0.00cvss epss 0.01

    Improper input validation vulnerability in Scheduler of Cybozu Garoon 4.0.0 to 5.5.1 allows a remote authenticated attacker to alter the data of Scheduler.

  • CVE-2022-27807Jul 4, 2022
    risk 0.00cvss epss 0.01

    Improper input validation vulnerability in Link of Cybozu Garoon 4.0.0 to 5.5.1 allows a remote authenticated attacker to disable to add Categories.

  • CVE-2022-27803Jul 4, 2022
    risk 0.00cvss epss 0.01

    Improper input validation vulnerability in Space of Cybozu Garoon 4.0.0 to 5.5.1 allows a remote authenticated attacker to alter the data of Space.

  • CVE-2022-27661Jul 4, 2022
    risk 0.00cvss epss 0.01

    Operation restriction bypass vulnerability in Workflow of Cybozu Garoon 4.0.0 to 5.5.1 allows a remote authenticated attacker to alter the data of Workflow.

  • CVE-2022-27627Jul 4, 2022
    risk 0.00cvss epss 0.01

    Cross-site scripting vulnerability in Organization's Information of Cybozu Garoon 4.10.2 to 5.5.1 allows a remote attacker to execute an arbitrary script on the logged-in user's web browser.

  • CVE-2022-26368Jul 4, 2022
    risk 0.00cvss epss 0.01

    Browse restriction bypass and operation restriction bypass vulnerability in Cabinet of Cybozu Garoon 4.0.0 to 5.5.1 allows a remote authenticated attacker to alter and/or obtain the data of Cabinet.

  • CVE-2022-26054Jul 4, 2022
    risk 0.00cvss epss 0.01

    Operation restriction bypass vulnerability in Link of Cybozu Garoon 4.0.0 to 5.5.1 allows a remote authenticated attacker to alter the data of Link.

  • CVE-2022-26051Jul 4, 2022
    risk 0.00cvss epss 0.01

    Operation restriction bypass vulnerability in Portal of Cybozu Garoon 4.0.0 to 5.5.1 allows a remote authenticated attacker to alter the data of Portal.

  • CVE-2021-20807Oct 13, 2021
    risk 0.00cvss epss 0.01

    Cross-site scripting vulnerability in the management screen of Cybozu Remote Service 3.0.0 to 3.1.9 allows a remote attacker to inject an arbitrary script via unspecified vectors.

  • CVE-2021-20806Oct 13, 2021
    risk 0.00cvss epss 0.01

    Open redirect vulnerability in Cybozu Remote Service 3.0.0 to 3.1.9 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via unspecified vectors.

  • CVE-2021-20805Oct 13, 2021
    risk 0.00cvss epss 0.01

    Cross-site scripting vulnerability in the management screen of Cybozu Remote Service 3.1.7 to 3.1.9 allows a remote authenticated attacker to inject an arbitrary script via unspecified vectors.

  • CVE-2021-20804Oct 13, 2021
    risk 0.00cvss epss 0.01

    Cybozu Remote Service 3.1.8 to 3.1.9 allows a remote authenticated attacker to cause a denial of service (DoS) condition via unspecified vectors.

  • CVE-2021-20803Oct 13, 2021
    risk 0.00cvss epss 0.01

    Operation restriction bypass in the management screen of Cybozu Remote Service 3.1.8 to 3.1.9 allows a remote authenticated attacker to alter the data of the management screen.

  • CVE-2021-20802Oct 13, 2021
    risk 0.00cvss epss 0.01

    HTTP header injection vulnerability in Cybozu Remote Service 3.1.8 to 3.1.9 allows a remote attacker to alter the information stored in the product.

  • CVE-2021-20801Oct 13, 2021
    risk 0.00cvss epss 0.01

    Cybozu Remote Service 3.1.8 to 3.1.9 allows a remote authenticated attacker to conduct XML External Entity (XXE) attacks and obtain the information stored in the product via unspecified vectors. This issue occurs only when using Mozilla Firefox.

  • CVE-2021-20800Oct 13, 2021
    risk 0.00cvss epss 0.01

    Cross-site scripting vulnerability in the management screen of Cybozu Remote Service 3.1.8 allows a remote authenticated attacker to inject an arbitrary script via unspecified vectors.

  • CVE-2021-20799Oct 13, 2021
    risk 0.00cvss epss 0.01

    Cross-site scripting vulnerability in the management screen of Cybozu Remote Service 3.1.8 to 3.1.9 allows a remote authenticated attacker to inject an arbitrary script via unspecified vectors.

  • CVE-2021-20798Oct 13, 2021
    risk 0.00cvss epss 0.01

    Cross-site scripting vulnerability in the management screen of Cybozu Remote Service 3.1.8 to 3.1.9 allows a remote authenticated attacker to inject an arbitrary script via unspecified vectors.

  • CVE-2021-20797Oct 13, 2021
    risk 0.00cvss epss 0.01

    Cross-site script inclusion vulnerability in the management screen of Cybozu Remote Service 3.1.8 allows a remote authenticated attacker to obtain the information stored in the product. This issue occurs only when using Mozilla Firefox.

  • CVE-2021-20796Oct 13, 2021
    risk 0.00cvss epss 0.01

    Directory traversal vulnerability in the management screen of Cybozu Remote Service 3.1.8 allows a remote authenticated attacker to upload an arbitrary file via unspecified vectors.

  • CVE-2021-20795Oct 13, 2021
    risk 0.00cvss epss 0.01

    Cross-site request forgery (CSRF) vulnerability in the management screen of Cybozu Remote Service 3.1.8 to 3.1.9 allows a remote attacker to hijack the authentication of administrators and unintended operations may be performed via unspecified vectors.

  • CVE-2021-20775Aug 18, 2021
    risk 0.00cvss epss 0.01

    Improper input validation vulnerability in Bulletin of Cybozu Garoon 4.10.0 to 5.5.0 allows a remote authenticated attacker to obtain the data of Comment and Space without the viewing privilege.

  • CVE-2021-20774Aug 18, 2021
    risk 0.00cvss epss 0.01

    Cross-site scripting vulnerability in some functions of E-mail of Cybozu Garoon 4.0.0 to 5.5.0 allows a remote authenticated attacker to inject an arbitrary script via unspecified vectors.

  • CVE-2021-20773Aug 18, 2021
    risk 0.00cvss epss 0.01

    There is a vulnerability in Workflow of Cybozu Garoon 4.0.0 to 5.5.0, which may allow a remote authenticated attacker to delete the route information Workflow without the appropriate privilege.

  • CVE-2021-20772Aug 18, 2021
    risk 0.00cvss epss 0.01

    Information disclosure vulnerability in Bulletin of Cybozu Garoon 4.10.0 to 5.5.0 allows a remote authenticated attacker to obtain the title of Bulletin without the viewing privilege.

  • CVE-2021-20771Aug 18, 2021
    risk 0.00cvss epss 0.01

    Cross-site scripting vulnerability in some functions of E-Mail of Cybozu Garoon 4.0.0 to 5.5.0 allows a remote attacker to inject an arbitrary script via unspecified vectors.

  • CVE-2021-20770Aug 18, 2021
    risk 0.00cvss epss 0.01

    Cross-site scripting vulnerability in Message of Cybozu Garoon 4.6.0 to 5.0.2 allows a remote authenticated attacker to inject an arbitrary script via unspecified vectors.

  • CVE-2021-20769Aug 18, 2021
    risk 0.00cvss epss 0.01

    Cross-site scripting vulnerability in Bulletin of Cybozu Garoon 4.6.0 to 5.0.2 allows a remote authenticated attacker to inject an arbitrary script via unspecified vectors.

  • CVE-2021-20768Aug 18, 2021
    risk 0.00cvss epss 0.01

    Operational restrictions bypass vulnerability in Scheduler and MultiReport of Cybozu Garoon 4.0.0 to 5.0.2 allows a remote authenticated attacker to delete the data of Scheduler and MultiReport without the appropriate privilege.

  • CVE-2021-20767Aug 18, 2021
    risk 0.00cvss epss 0.01

    Cross-site scripting vulnerability in Full Text Search of Cybozu Garoon 4.0.0 to 5.0.2 allows a remote authenticated attacker to inject an arbitrary script via unspecified vectors.

  • CVE-2021-20766Aug 18, 2021
    risk 0.00cvss epss 0.01

    Cross-site scripting vulnerability in Message of Cybozu Garoon 4.0.0 to 5.0.2 allows a remote attacker to inject an arbitrary script via unspecified vectors.

  • CVE-2021-20765Aug 18, 2021
    risk 0.00cvss epss 0.01

    Cross-site scripting vulnerability in Bulletin of Cybozu Garoon 4.0.0 to 5.0.2 allows a remote attacker to inject an arbitrary script via unspecified vectors.

  • CVE-2021-20764Aug 18, 2021
    risk 0.00cvss epss 0.01

    Improper input validation vulnerability in Attaching Files of Cybozu Garoon 4.0.0 to 5.0.2 allows a remote attacker to alter the data of Attaching Files.

  • CVE-2021-20763Aug 18, 2021
    risk 0.00cvss epss 0.01

    Operational restrictions bypass vulnerability in Portal of Cybozu Garoon 4.0.0 to 5.0.2 allows a remote authenticated attacker to obtain the data of Portal without the appropriate privilege.

  • CVE-2021-20762Aug 18, 2021
    risk 0.00cvss epss 0.01

    Improper input validation vulnerability in E-mail of Cybozu Garoon 4.0.0 to 5.0.2 allows a remote authenticated to alter the data of E-mail without the appropriate privilege.

  • CVE-2021-20761Aug 18, 2021
    risk 0.00cvss epss 0.01

    Improper input validation vulnerability in E-mail of Cybozu Garoon 4.0.0 to 5.0.2 allows a remote attacker with an administrative privilege to alter the data of E-mail without the appropriate privilege.

  • CVE-2021-20760Aug 18, 2021
    risk 0.00cvss epss 0.01

    Improper input validation vulnerability in User Profile of Cybozu Garoon 4.0.0 to 5.0.2 allows a remote authenticated attacker to alter the data of User Profile without the appropriate privilege.

  • CVE-2021-20759Aug 18, 2021
    risk 0.00cvss epss 0.01

    Operational restrictions bypass vulnerability in Bulletin of Cybozu Garoon 4.6.0 to 5.0.2 allows a remote authenticated attacker to alter the data of Portal without the appropriate privilege.

  • CVE-2021-20758Aug 18, 2021
    risk 0.00cvss epss 0.00

    Cross-site request forgery (CSRF) vulnerability in Message of Cybozu Garoon 4.0.0 to 5.0.2 allows a remote authenticated attacker to hijack the authentication of administrators and perform an arbitrary operation via unspecified vectors.

  • CVE-2021-20757Aug 18, 2021
    risk 0.00cvss epss 0.01

    Operational restrictions bypass vulnerability in E-mail of Cybozu Garoon 4.0.0 to 5.0.2 allows a remote authenticated attacker to alter the data of Portal without the appropriate privilege.

  • CVE-2021-20756Aug 18, 2021
    risk 0.00cvss epss 0.01

    Viewing restrictions bypass vulnerability in Address of Cybozu Garoon 4.0.0 to 5.0.2 allows a remote authenticated attacker to obtain the data of Address without the viewing privilege.

  • CVE-2021-20755Aug 18, 2021
    risk 0.00cvss epss 0.01

    Viewing restrictions bypass vulnerability in Portal of Cybozu Garoon 4.0.0 to 5.0.2 allows a remote authenticated attacker to obtain the data of Portal without the viewing privilege.

  • CVE-2021-20754Aug 18, 2021
    risk 0.00cvss epss 0.01

    Improper input validation vulnerability in Workflow of Cybozu Garoon 4.0.0 to 5.0.2 allows a remote authenticated attacker to alter the data of Workflow without the appropriate privilege.

  • CVE-2021-20753Aug 18, 2021
    risk 0.00cvss epss 0.01

    Cross-site scripting vulnerability in Scheduler of Cybozu Garoon 4.0.0 to 5.0.2 allows a remote authenticated attacker to inject an arbitrary script via unspecified vectors.

  • CVE-2021-20634Mar 18, 2021
    risk 0.00cvss epss 0.01

    Improper access control vulnerability in Custom App of Cybozu Office 10.0.0 to 10.8.4 allows authenticated attackers to bypass access restriction and obtain the date of Custom App via unspecified vectors.

  • CVE-2021-20633Mar 18, 2021
    risk 0.00cvss epss 0.01

    Improper access control vulnerability in Cabinet of Cybozu Office 10.0.0 to 10.8.4 allows authenticated attackers to bypass access restriction and obtain the date of Cabinet via unspecified vectors.

  • CVE-2021-20632Mar 18, 2021
    risk 0.00cvss epss 0.01

    Improper access control vulnerability in Bulletin Board of Cybozu Office 10.0.0 to 10.8.4 allows authenticated attackers to bypass access restriction and obtain the data of Bulletin Board via unspecified vectors.

  • CVE-2021-20631Mar 18, 2021
    risk 0.00cvss epss 0.01

    Improper input validation vulnerability in Custom App of Cybozu Office 10.0.0 to 10.8.4 allows authenticated attacker to alter the data of Custom App via unspecified vectors.

  • CVE-2021-20629Mar 18, 2021
    risk 0.00cvss epss 0.01

    Cross-site scripting vulnerability in E-mail of Cybozu Office 10.0.0 to 10.8.4 allows remote attackers to inject an arbitrary script via unspecified vectors.

Page 4 of 7