VYPR
Vendor

SonicCloudOrg

Products
2
CVEs
4
Across products
4
Status
Private

Products

2

Recent CVEs

4
  • CVE-2026-6620MedApr 20, 2026
    risk 0.41cvss 6.3epss 0.00

    A vulnerability was found in SonicCloudOrg sonic-server up to 2.0.0. The affected element is the function Upload of the file FileTool.java of the component File Upload Endpoint. The manipulation of the argument Type results in path traversal. The attack may be launched remotely.…

  • CVE-2026-15497HigJul 12, 2026
    risk 0.00cvss 7.3epss 0.00

    A vulnerability was determined in SonicCloudOrg sonic-agent up to 2.7.2. This affects an unknown function of the file sonic-server-controller/src/main/java/org/cloud/sonic/controller/controller/ExchangeController.java of the component JWT Authentication Filter. This manipulation…

  • CVE-2026-15496MedJul 12, 2026
    risk 0.00cvss 6.3epss 0.01

    A vulnerability was found in SonicCloudOrg sonic-agent up to 2.7.2. The impacted element is the function evalIsFailed of the file sonic-agent/src/main/java/org/cloud/sonic/agent/tests/script/GroovyScriptImpl.java of the component Groovy Script Handler. The manipulation results…

  • CVE-2026-15495MedJul 12, 2026
    risk 0.00cvss 6.3epss 0.02

    A vulnerability has been found in SonicCloudOrg sonic-agent up to 2.7.2. The affected element is an unknown function of the file AndroidWSServer.java of the component Android WebSocket Server. The manipulation of the argument path leads to os command injection. The attack can be…