Vulnerability index

Browse CVEs

187 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Remote Service Manager MEDIUM 5.4
CVE-2021-20803

Operation restriction bypass in the management screen of Cybozu Remote Service 3.1.8 to 3.1.9 allows a remote authenticated attacker to alter the dat…

Mitigation only
Fix from $1,600 2021-10-13
Remote Service Manager MEDIUM 5.4
CVE-2021-20805

Cross-site scripting vulnerability in the management screen of Cybozu Remote Service 3.1.7 to 3.1.9 allows a remote authenticated attacker to inject …

Fix: after 3.1.9
Fix from $1,600 2021-10-13
Remote Service Manager MEDIUM 5.3
CVE-2021-20802

HTTP header injection vulnerability in Cybozu Remote Service 3.1.8 to 3.1.9 allows a remote attacker to alter the information stored in the product.

Mitigation only
Fix from $1,600 2021-10-13
Remote Service Manager HIGH 8.8
CVE-2021-20795

Cross-site request forgery (CSRF) vulnerability in the management screen of Cybozu Remote Service 3.1.8 to 3.1.9 allows a remote attacker to hijack t…

Mitigation only
Fix from $1,950 2021-10-13
Remote Service Manager MEDIUM 6.5
CVE-2021-20796

Directory traversal vulnerability in the management screen of Cybozu Remote Service 3.1.8 allows a remote authenticated attacker to upload an arbitra…

Mitigation only
Fix from $1,600 2021-10-13
Remote Service Manager MEDIUM 6.5
CVE-2021-20801

Cybozu Remote Service 3.1.8 to 3.1.9 allows a remote authenticated attacker to conduct XML External Entity (XXE) attacks and obtain the information s…

Mitigation only
Fix from $1,600 2021-10-13
Remote Service Manager MEDIUM 5.4
CVE-2021-20797

Cross-site script inclusion vulnerability in the management screen of Cybozu Remote Service 3.1.8 allows a remote authenticated attacker to obtain th…

Mitigation only
Fix from $1,600 2021-10-13
Remote Service Manager MEDIUM 5.4
CVE-2021-20798

Cross-site scripting vulnerability in the management screen of Cybozu Remote Service 3.1.8 to 3.1.9 allows a remote authenticated attacker to inject …

Mitigation only
Fix from $1,600 2021-10-13
Remote Service Manager MEDIUM 5.4
CVE-2021-20799

Cross-site scripting vulnerability in the management screen of Cybozu Remote Service 3.1.8 to 3.1.9 allows a remote authenticated attacker to inject …

Mitigation only
Fix from $1,600 2021-10-13
Remote Service Manager MEDIUM 5.4
CVE-2021-20800

Cross-site scripting vulnerability in the management screen of Cybozu Remote Service 3.1.8 allows a remote authenticated attacker to inject an arbitr…

Mitigation only
Fix from $1,600 2021-10-13
Garoon MEDIUM 6.1
CVE-2021-20765

Cross-site scripting vulnerability in Bulletin of Cybozu Garoon 4.0.0 to 5.0.2 allows a remote attacker to inject an arbitrary script via unspecified…

Fix: after 5.0.2
Fix from $1,600 2021-08-18
Garoon MEDIUM 6.1
CVE-2021-20766

Cross-site scripting vulnerability in Message of Cybozu Garoon 4.0.0 to 5.0.2 allows a remote attacker to inject an arbitrary script via unspecified …

Fix: after 5.0.2
Fix from $1,600 2021-08-18
Garoon MEDIUM 6.1
CVE-2021-20771

Cross-site scripting vulnerability in some functions of E-Mail of Cybozu Garoon 4.0.0 to 5.5.0 allows a remote attacker to inject an arbitrary script…

Fix: after 5.5.0
Fix from $1,600 2021-08-18
Garoon MEDIUM 5.4
CVE-2021-20767

Cross-site scripting vulnerability in Full Text Search of Cybozu Garoon 4.0.0 to 5.0.2 allows a remote authenticated attacker to inject an arbitrary …

Fix: after 5.0.2
Fix from $1,600 2021-08-18
Garoon MEDIUM 5.4
CVE-2021-20769

Cross-site scripting vulnerability in Bulletin of Cybozu Garoon 4.6.0 to 5.0.2 allows a remote authenticated attacker to inject an arbitrary script v…

Fix: after 5.0.2
Fix from $1,600 2021-08-18
Garoon MEDIUM 5.4
CVE-2021-20770

Cross-site scripting vulnerability in Message of Cybozu Garoon 4.6.0 to 5.0.2 allows a remote authenticated attacker to inject an arbitrary script vi…

Fix: after 5.0.2
Fix from $1,600 2021-08-18
Garoon MEDIUM 5.4
CVE-2021-20774

Cross-site scripting vulnerability in some functions of E-mail of Cybozu Garoon 4.0.0 to 5.5.0 allows a remote authenticated attacker to inject an ar…

Fix: after 5.5.0
Fix from $1,600 2021-08-18
Garoon MEDIUM 5.3
CVE-2021-20764

Improper input validation vulnerability in Attaching Files of Cybozu Garoon 4.0.0 to 5.0.2 allows a remote attacker to alter the data of Attaching Fi…

Fix: after 5.0.2
Fix from $1,600 2021-08-18
Garoon HIGH 8.0
CVE-2021-20758

Cross-site request forgery (CSRF) vulnerability in Message of Cybozu Garoon 4.0.0 to 5.0.2 allows a remote authenticated attacker to hijack the authe…

Fix: after 5.0.2
Fix from $1,950 2021-08-18
Garoon MEDIUM 5.4
CVE-2021-20753

Cross-site scripting vulnerability in Scheduler of Cybozu Garoon 4.0.0 to 5.0.2 allows a remote authenticated attacker to inject an arbitrary script …

Fix: after 5.0.2
Fix from $1,600 2021-08-18
Office MEDIUM 6.5
CVE-2021-20631

Improper input validation vulnerability in Custom App of Cybozu Office 10.0.0 to 10.8.4 allows authenticated attacker to alter the data of Custom App…

Fix: after 10.8.4
Fix from $1,600 2021-03-18
Office MEDIUM 6.5
CVE-2021-20624

Improper access control vulnerability in Scheduler of Cybozu Office 10.0.0 to 10.8.4 allows an authenticated attacker to bypass access restriction an…

Fix: after 10.8.4
Fix from $1,600 2021-03-18
Office MEDIUM 6.5
CVE-2021-20626

Improper access control vulnerability in Workflow of Cybozu Office 10.0.0 to 10.8.4 allows authenticated attackers to bypass access restriction and a…

Fix: after 10.8.4
Fix from $1,600 2021-03-18
Office MEDIUM 6.1
CVE-2021-20627

Cross-site scripting vulnerability in Address Book of Cybozu Office 10.0.0 to 10.8.4 allows remote attackers to inject an arbitrary script via unspec…

Fix: after 10.8.4
Fix from $1,600 2021-03-18
Office MEDIUM 6.1
CVE-2021-20628

Cross-site scripting vulnerability in Address Book of Cybozu Office 10.0.0 to 10.8.4 allows remote attackers to inject an arbitrary script via unspec…

Fix: after 10.8.4
Fix from $1,600 2021-03-18
Office MEDIUM 6.1
CVE-2021-20629

Cross-site scripting vulnerability in E-mail of Cybozu Office 10.0.0 to 10.8.4 allows remote attackers to inject an arbitrary script via unspecified …

Fix: after 10.8.4
Fix from $1,600 2021-03-18
Garoon MEDIUM 6.5
CVE-2020-5643

Improper input validation vulnerability in Cybozu Garoon 5.0.0 to 5.0.2 allows a remote authenticated attacker to delete some data of the bulletin bo…

Fix: after 5.0.2
Fix from $1,600 2020-11-06
Garoon MEDIUM 6.5
CVE-2020-5587

Cybozu Garoon 4.0.0 to 5.0.1 allow remote authenticated attackers to obtain unintended information via unspecified vectors.

Fix: after 5.0.1
Fix from $1,600 2020-06-30
Garoon HIGH 8.1
CVE-2020-5580

Cybozu Garoon 4.0.0 to 5.0.1 allows remote authenticated attackers to bypass access restriction to view and/or alter Single sign-on settings via unsp…

Fix: after 5.0.1
Fix from $1,950 2020-06-30
Garoon HIGH 7.5
CVE-2020-5584

Cybozu Garoon 4.0.0 to 5.0.1 allow remote attackers to obtain unintended information via unspecified vectors.

Fix: after 5.0.1
Fix from $1,950 2020-06-30