Vulnerability index

Browse CVEs

187 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Garoon HIGH 7.5
CVE-2026-22888

Improper input verification issue exists in Cybozu Garoon 5.0.0 to 6.0.3, which may lead to unauthorized alteration of portal settings, potentially b…

Fix: 6.0.3+
Fix from $1,950 2026-02-02
Garoon MEDIUM 6.1
CVE-2026-20711

Cross-site scripting vulnerability exists in E-mail function of Cybozu Garoon 5.0.0 to 6.0.3, which may allow an attacker to reset arbitrary users’ p…

Fix: 6.0.3+
Fix from $1,600 2026-02-02
Garoon MEDIUM 5.4
CVE-2026-22881

Cross-site scripting vulnerability exists in Message function of Cybozu Garoon 5.15.0 to 6.0.3, which may allow an attacker to reset arbitrary users’…

Fix: 6.0.3+
Fix from $1,600 2026-02-02
Office MEDIUM 6.5
CVE-2024-39817

Insertion of sensitive information into sent data issue exists in Cybozu Office 10.0.0 to 10.8.6, which may allow a user who can login to the product…

Fix: 10.8.7+
Fix from $1,600 2024-08-06
Garoon MEDIUM 5.4
CVE-2024-39457

Cybozu Garoon 6.0.0 to 6.0.1 contains a cross-site scripting vulnerability in PDF preview. If this vulnerability is exploited, an arbitrary script ma…

Fix: 6.0.2+
Fix from $1,600 2024-07-19
Garoon MEDIUM 6.5
CVE-2024-31399

Excessive platform resource consumption within a loop issue exists in Cybozu Garoon 5.0.0 to 5.15.2. If this vulnerability is exploited, processing a…

Fix: after 5.15.2
Fix from $1,600 2024-06-11
Garoon CRITICAL 9.0
CVE-2024-31401

Cross-site scripting vulnerability in Cybozu Garoon 5.0.0 to 5.15.2 allows a remote authenticated attacker with an administrative privilege to inject…

Fix: 6.0.0+
Fix from $2,300 2024-06-11
Garoon MEDIUM 6.5
CVE-2024-31400

Insertion of sensitive information into sent data issue exists in Cybozu Garoon 5.0.0 to 5.15.0. If this vulnerability is exploited, unintended data …

Fix: 6.0.0+
Fix from $1,600 2024-06-11
Garoon MEDIUM 5.4
CVE-2024-31403

Incorrect authorization vulnerability in Cybozu Garoon 5.0.0 to 6.0.0 allows a remote authenticated attacker to alter and/or obtain the data of Memo.

Fix: 6.0.1+
Fix from $1,600 2024-06-11
Kunai HIGH 7.5
CVE-2024-23304

Cybozu KUNAI for Android 3.0.20 to 3.0.21 allows a remote unauthenticated attacker to cause a denial-of-service (DoS) condition by performing certain…

Mitigation only
Fix from $1,950 2024-02-06
Cybozu Remote Service MEDIUM 6.5
CVE-2023-46278

Uncontrolled resource consumption vulnerability in Cybozu Remote Service 4.1.0 to 4.1.1 allows a remote authenticated attacker to consume huge storag…

Fix: 4.1.2+
Fix from $1,600 2023-11-01
Remote Service Manager MEDIUM 6.5
CVE-2022-26838

Path traversal vulnerability in Importing Mobile Device Data of Cybozu Remote Service 3.1.2 allows a remote authenticated attacker to cause a denial-…

Mitigation only
Fix from $1,600 2023-08-03
Garoon MEDIUM 6.5
CVE-2023-26595

Denial-of-service (DoS) vulnerability in Message of Cybozu Garoon 4.10.0 to 5.9.2 allows a remote authenticated attacker to cause a denial of service…

Fix: after 5.9.2
Fix from $1,600 2023-05-23
Cybozu Remote Service HIGH 7.5
CVE-2022-44608

Uncontrolled resource consumption vulnerability in Cybozu Remote Service 4.0.0 to 4.0.3 allows a remote authenticated attacker to consume huge storag…

Fix: after 4.0.3
Fix from $1,950 2022-12-07
Office MEDIUM 6.5
CVE-2022-32453

HTTP header injection vulnerability in Cybozu Office 10.0.0 to 10.8.5 may allow a remote attacker to obtain and/or alter the data of the product via …

Fix: after 10.8.5
Fix from $1,600 2022-08-18
Office MEDIUM 6.1
CVE-2022-28715

Cross-site scripting vulnerability in the specific parameters of Cybozu Office 10.0.0 to 10.8.5 allows a remote attacker to inject an arbitrary scrip…

Fix: after 10.8.5
Fix from $1,600 2022-08-18
Office MEDIUM 6.1
CVE-2022-29487

Cross-site scripting vulnerability in Cybozu Office 10.0.0 to 10.8.5 allows a remote attacker to inject an arbitrary script via unspecified vectors.

Fix: after 10.8.5
Fix from $1,600 2022-08-18
Office MEDIUM 6.1
CVE-2022-30604

Cross-site scripting vulnerability in the specific parameters of Cybozu Office 10.0.0 to 10.8.5 allows a remote attacker to inject an arbitrary scrip…

Fix: after 10.8.5
Fix from $1,600 2022-08-18
Office MEDIUM 6.1
CVE-2022-33151

Cross-site scripting vulnerability in the specific parameters of Cybozu Office 10.0.0 to 10.8.5 allows remote attackers to inject an arbitrary script…

Fix: after 10.8.5
Fix from $1,600 2022-08-18
Office MEDIUM 5.3
CVE-2022-30693

Information disclosure vulnerability in the system configuration of Cybozu Office 10.0.0 to 10.8.5 allows a remote attacker to obtain the data of the…

Fix: after 10.8.5
Fix from $1,600 2022-08-18
Garoon HIGH 8.1
CVE-2022-30602

Operation restriction bypass in multiple applications of Cybozu Garoon 4.0.0 to 5.9.1 allows a remote authenticated attacker to alter the file inform…

Fix: after 5.9.1
Fix from $1,950 2022-07-11
Garoon MEDIUM 6.5
CVE-2022-29512

Exposure of sensitive information to an unauthorized actor issue in multiple applications of Cybozu Garoon 4.0.0 to 5.9.1 allows a remote authenticat…

Fix: after 5.9.1
Fix from $1,600 2022-07-11
Garoon HIGH 8.1
CVE-2022-29484

Operation restriction bypass vulnerability in Space of Cybozu Garoon 4.0.0 to 5.9.0 allows a remote authenticated attacker to delete the data of Spac…

Fix: after 5.9.0
Fix from $1,950 2022-07-04
Garoon MEDIUM 6.5
CVE-2022-29892

Improper input validation vulnerability in Space of Cybozu Garoon 4.0.0 to 5.5.1 allows a remote authenticated attacker to repeatedly display errors …

Fix: after 5.5.1
Fix from $1,600 2022-07-04
Garoon MEDIUM 6.1
CVE-2022-27627

Cross-site scripting vulnerability in Organization's Information of Cybozu Garoon 4.10.2 to 5.5.1 allows a remote attacker to execute an arbitrary sc…

Fix: after 5.5.1
Fix from $1,600 2022-07-04
Garoon MEDIUM 5.4
CVE-2022-26368

Browse restriction bypass and operation restriction bypass vulnerability in Cabinet of Cybozu Garoon 4.0.0 to 5.5.1 allows a remote authenticated att…

Fix: after 5.5.1
Fix from $1,600 2022-07-04
Garoon MEDIUM 5.3
CVE-2022-28713

Improper authentication vulnerability in Scheduler of Cybozu Garoon 4.10.0 to 5.5.1 allows a remote attacker to obtain some data of Facility Informat…

Fix: after 5.5.1
Fix from $1,600 2022-07-04
Remote Service Manager MEDIUM 6.5
CVE-2021-20804

Cybozu Remote Service 3.1.8 to 3.1.9 allows a remote authenticated attacker to cause a denial of service (DoS) condition via unspecified vectors.

Mitigation only
Fix from $1,600 2021-10-13
Remote Service Manager MEDIUM 6.1
CVE-2021-20806

Open redirect vulnerability in Cybozu Remote Service 3.0.0 to 3.1.9 allows remote attackers to redirect users to arbitrary web sites and conduct phis…

Fix: after 3.1.9
Fix from $1,600 2021-10-13
Remote Service Manager MEDIUM 6.1
CVE-2021-20807

Cross-site scripting vulnerability in the management screen of Cybozu Remote Service 3.0.0 to 3.1.9 allows a remote attacker to inject an arbitrary s…

Fix: after 3.1.9
Fix from $1,600 2021-10-13