VYPR
Vendor

Sony

Sony Group Corporation, commonly referred to as Sony, is a Japanese multinational conglomerate headquartered at Sony City in Minato, Tokyo, Japan. The Sony Group encompasses various businesses, including electronics, imaging and sensing, film and television, music, video games, and others.

Founded 1946
Products
149
CVEs
82
Across products
96
Status
Private

Products

149
View all 149 products →

Recent CVEs

82
View all 82 CVEs →
  • CVE-2022-23747CriAug 17, 2022
    risk 0.65cvss 9.8epss 0.10

    In Sony Xperia series 1, 5, and Pro, an out of bound memory access can occur due to lack of validation of the number of frames being passed during music playback.

  • CVE-2020-36923CriJan 6, 2026
    risk 0.64cvss 9.8epss 0.01

    Sony BRAVIA Digital Signage 1.7.8 contains an insecure direct object reference vulnerability that allows attackers to bypass authorization controls. Attackers can access hidden system resources like '/#/content-creation' by manipulating client-side access restrictions.

  • CVE-2020-36885CriDec 10, 2025
    risk 0.64cvss 9.8epss 0.01

    Sony IPELA Network Camera 1.82.01 contains a stack buffer overflow vulnerability in the ftpclient.cgi endpoint that allows remote attackers to execute arbitrary code. Attackers can exploit the vulnerability by sending a crafted POST request with oversized data to the FTP client…

  • CVE-2018-3937CriAug 14, 2018
    risk 0.60cvss 9.1epss 0.10

    An exploitable command injection vulnerability exists in the measurementBitrateExec functionality of Sony IPELA E Series Network Camera G5 firmware 1.87.00. A specially crafted GET request can cause arbitrary commands to be executed. An attacker can send an HTTP request to…

  • CVE-2018-3938CriAug 14, 2018
    risk 0.59cvss 9.1epss 0.03

    An exploitable stack-based buffer overflow vulnerability exists in the 802dot1xclientcert.cgi functionality of Sony IPELA E Series Camera G5 firmware 1.87.00. A specially crafted POST can cause a stack-based buffer overflow, resulting in remote code execution. An attacker can…

  • CVE-2017-2277CriJul 22, 2017
    risk 0.59cvss 9.1epss 0.01

    WG-C10 v3.0.79 and earlier allows an attacker to bypass access restrictions to obtain or alter information stored in the external storage connected to the product via unspecified vectors.

  • CVE-2016-7834HigApr 13, 2017
    risk 0.58cvss 8.8epss 0.04

    SONY SNC-CH115, SNC-CH120, SNC-CH160, SNC-CH220, SNC-CH260, SNC-DH120, SNC-DH120T, SNC-DH160, SNC-DH220, SNC-DH220T, SNC-DH260, SNC-EB520, SNC-EM520, SNC-EM521, SNC-ZB550, SNC-ZM550, SNC-ZM551, SNC-EP550, SNC-EP580, SNC-ER550, SNC-ER550C, SNC-ER580, SNC-ER585, SNC-ER585H,…

  • CVE-2025-5820HigJun 21, 2025
    risk 0.57cvss 8.8epss 0.00

    Sony XAV-AX8500 Bluetooth ERTM Channel Authentication Bypass Vulnerability. This vulnerability allows network-adjacent attackers to bypass authentication on affected Sony XAV-AX8500 devices. Authentication is not required to exploit this vulnerability. The specific flaw exists…

  • CVE-2025-5478HigJun 21, 2025
    risk 0.57cvss 8.8epss 0.00

    Sony XAV-AX8500 Bluetooth SDP Protocol Integer Overflow Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of Sony XAV-AX8500 devices. Authentication is not required to exploit this…

  • CVE-2025-5476HigJun 21, 2025
    risk 0.57cvss 8.8epss 0.00

    Sony XAV-AX8500 Bluetooth Improper Isolation Authentication Bypass Vulnerability. This vulnerability allows network-adjacent attackers to bypass authentication on affected Sony XAV-AX8500 devices. Authentication is not required to exploit this vulnerability. The specific flaw…

  • CVE-2024-23934HigSep 23, 2024
    risk 0.57cvss 8.8epss 0.01

    Sony XAV-AX5500 WMV/ASF Parsing Stack-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Sony XAV-AX5500 devices. User interaction is required to exploit this vulnerability…

  • CVE-2020-5589HigJun 9, 2020
    risk 0.57cvss 8.8epss 0.01

    SONY Wireless Headphones WF-1000X, WF-SP700N, WH-1000XM2, WH-1000XM3, WH-CH700N, WH-H900N, WH-XB700, WH-XB900N, WI-1000X, WI-C600N and WI-SP600N with firmware versions prior to 4.5.2 have vulnerability that someone within the Bluetooth range can make the Bluetooth pairing and…

  • CVE-2018-16593HigJun 19, 2019
    risk 0.57cvss 8.8epss 0.01

    The Photo Sharing Plus component on Sony Bravia TV through 8.587 devices allows Shell Metacharacter Injection.

  • CVE-2019-10844CriApr 4, 2019
    risk 0.57cvss 9.8epss 0.02

    nbla/logger.cpp in libnnabla.a in Sony Neural Network Libraries (aka nnabla) through v1.0.14 relies on the HOME environment variable, which might be untrusted.

  • CVE-2016-7830HigJun 9, 2017
    risk 0.57cvss 8.8epss 0.01

    Sony PCS-XG100, PCS-XG100S, PCS-XG100C, PCS-XG77, PCS-XG77S, PCS-XG77C devices with firmware versions prior to Ver.1.51 and PCS-XC1 devices with firmware version prior to Ver.1.22 allow an attacker on the same network segment to bypass authentication to perform administrative…

  • CVE-2025-5124HigMay 24, 2025
    risk 0.53cvss 8.1epss 0.01

    A vulnerability classified as critical has been found in Sony SNC-M1, SNC-M3, SNC-RZ25N, SNC-RZ30N, SNC-DS10, SNC-CS3N and SNC-RX570N up to 1.30. This affects an unknown part of the component Administrative Interface. The manipulation leads to use of default credentials. It is…

  • CVE-2018-16594HigJun 19, 2019
    risk 0.53cvss 8.1epss 0.01

    The Photo Sharing Plus component on Sony Bravia TV through 8.587 devices allows Directory Traversal.

  • CVE-2019-11336HigMay 14, 2019
    risk 0.53cvss 8.1epss 0.03

    Sony Bravia Smart TV devices allow remote attackers to retrieve the static Wi-Fi password (used when the TV is acting as an access point) by using the Photo Sharing Plus application to execute a backdoor API command, a different vulnerability than CVE-2019-10886.

  • CVE-2025-64772HigDec 1, 2025
    risk 0.51cvss 7.8epss 0.00

    The installer of INZONE Hub 1.0.10.3 to 1.0.17.0 contains an issue with the DLL search path, which may lead to insecurely loading Dynamic Link Libraries. As a result, arbitrary code may be executed with the privilege of the user invoking the installer.

  • CVE-2022-41796HigOct 24, 2022
    risk 0.51cvss 7.8epss 0.00

    Untrusted search path vulnerability in the installer of Content Transfer (for Windows) Ver.1.3 and prior allows an attacker to gain privileges via a Trojan horse DLL in an unspecified directory.