Vulnerability index

Browse CVEs

69 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Bravia Signage CRITICAL 9.8
CVE-2020-36923

Sony BRAVIA Digital Signage 1.7.8 contains an insecure direct object reference vulnerability that allows attackers to bypass authorization controls. …

Fix: after 1.7.8
Fix from $2,300 2026-01-06
Bravia Signage HIGH 7.5
CVE-2020-36922

Sony BRAVIA Digital Signage 1.7.8 contains an information disclosure vulnerability that allows unauthenticated attackers to access sensitive system d…

Fix: after 1.7.8
Fix from $1,950 2026-01-06
Bravia Signage MEDIUM 6.1
CVE-2020-36924

Sony BRAVIA Digital Signage 1.7.8 contains a remote file inclusion vulnerability that allows attackers to inject arbitrary client-side scripts throug…

Fix: after 1.7.8
Fix from $1,600 2026-01-06
Snc Dh120t Firmware CRITICAL 9.8
CVE-2020-36885

Sony IPELA Network Camera 1.82.01 contains a stack buffer overflow vulnerability in the ftpclient.cgi endpoint that allows remote attackers to execut…

Fix: after 1.82.01
Fix from $2,300 2025-12-10
Snc Cx600w Firmware MEDIUM 6.1
CVE-2025-64730

Cross-site scripting vulnerability exists in SNC-CX600W all versions. If this vulnerability is exploited, an arbitrary script may be executed on the …

Mitigation only
Fix from $1,600 2025-11-25
Snc Cx600w Firmware MEDIUM 6.5
CVE-2025-62497

Cross-site request forgery vulnerability exists in SNC-CX600W versions prior to Ver.2.8.0. If a user accesses a specially crafted webpage while logge…

Fix: 2.8.0+
Fix from $1,600 2025-11-25
Xav Ax8500 Firmware HIGH 8.8
CVE-2025-5476

Sony XAV-AX8500 Bluetooth Improper Isolation Authentication Bypass Vulnerability. This vulnerability allows network-adjacent attackers to bypass auth…

Fix: 3.02.00+
Fix from $1,950 2025-06-21
Xav Ax8500 Firmware HIGH 8.8
CVE-2025-5478

Sony XAV-AX8500 Bluetooth SDP Protocol Integer Overflow Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to …

Fix: 3.02.00+
Fix from $1,950 2025-06-21
Xav Ax8500 Firmware HIGH 8.8
CVE-2025-5820

Sony XAV-AX8500 Bluetooth ERTM Channel Authentication Bypass Vulnerability. This vulnerability allows network-adjacent attackers to bypass authentica…

Fix: 3.02.00+
Fix from $1,950 2025-06-21
Xav Ax8500 Firmware HIGH 7.5
CVE-2025-5475

Sony XAV-AX8500 Bluetooth Packet Handling Integer Overflow Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers …

Fix: 3.02.00+
Fix from $1,950 2025-06-21
Xav Ax8500 Firmware HIGH 7.5
CVE-2025-5477

Sony XAV-AX8500 Bluetooth L2CAP Protocol Heap-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows network-adjacent a…

Fix: 3.02.00+
Fix from $1,950 2025-06-21
Xav Ax8500 Firmware HIGH 7.5
CVE-2025-5479

Sony XAV-AX8500 Bluetooth AVCTP Protocol Heap-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows network-adjacent a…

Fix: 3.02.00+
Fix from $1,950 2025-06-21
Xav Ax5500 Firmware MEDIUM 6.8
CVE-2024-23922

Sony XAV-AX5500 Insufficient Firmware Update Validation Remote Code Execution Vulnerability. This vulnerability allows physically present attackers t…

Patch available
Fix from $1,600 2024-09-23
Xav Ax5500 Firmware MEDIUM 6.8
CVE-2024-23972

Sony XAV-AX5500 USB Configuration Descriptor Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows physically present attack…

Patch available
Fix from $1,600 2024-09-23
Content Transfer HIGH 7.8
CVE-2022-41796

Untrusted search path vulnerability in the installer of Content Transfer (for Windows) Ver.1.3 and prior allows an attacker to gain privileges via a …

Fix: after 1.3
Fix from $1,950 2022-10-24
Playstation 4 Firmware MEDIUM 6.8
CVE-2022-3349

A vulnerability was found in Sony PS4 and PS5. It has been classified as critical. This affects the function UVFAT_readupcasetable of the component e…

No fix yet
Fix from $1,600 2022-09-28
Xperia 1 Firmware CRITICAL 9.8
CVE-2022-23747EPSS 10%

In Sony Xperia series 1, 5, and Pro, an out of bound memory access can occur due to lack of validation of the number of frames being passed during mu…

No fix yet
Fix from $2,300 2022-08-17
Playmemories Home MEDIUM 6.7
CVE-2022-27094

Sony PlayMemories Home v6.0 contains an unquoted service path which allows attackers to escalate privileges to the system level.

No fix yet
Fix from $1,600 2022-05-20
Audio Usb Driver HIGH 7.8
CVE-2021-20793

Untrusted search path vulnerability in the installer of Sony Audio USB Driver V1.10 and prior and the installer of HAP Music Transfer Ver.1.3.0 and p…

Fix: after 1.10
Fix from $1,950 2021-08-26
Srs Xb33 Firmware MEDIUM 5.9
CVE-2021-38544

Sony SRS-XB33 and SRS-XB43 devices through 2021-08-09 allow remote attackers to recover speech signals from an LED on the device, via a telescope and…

Fix: after 2021-08-09
Fix from $1,600 2021-08-11
Wf 1000x Firmware HIGH 8.8
CVE-2020-5589

SONY Wireless Headphones WF-1000X, WF-SP700N, WH-1000XM2, WH-1000XM3, WH-CH700N, WH-H900N, WH-XB700, WH-XB900N, WI-1000X, WI-C600N and WI-SP600N with…

Mitigation only
Fix from $1,950 2020-06-09
Catalyst Browse HIGH 7.8
CVE-2019-19364

A weak malicious user can escalate its privilege whenever CatalystProductionSuite.2019.1.exe (version 1.1.0.21) and CatalystBrowseSuite.2019.1.exe (v…

Fix: after 2019.1
Fix from $1,950 2019-12-04
Xperia Touch Firmware MEDIUM 5.5
CVE-2019-15743

The Sony Xperia Touch Android device with a build fingerprint of Sony/blanc_windy/blanc_windy:7.0/LOIRE-SMART-BLANC-1.0.0-170530-0834/1:user/dev-keys…

Mitigation only
Fix from $1,600 2019-11-14
Xperia Xzs Firmware HIGH 7.8
CVE-2019-15416

The Sony keyaki_kddi Android device with a build fingerprint of Sony/keyaki_kddi/keyaki_kddi:7.1.1/TONE3-3.0.0-KDDI-170517-0326/1:user/dev-keys conta…

Mitigation only
Fix from $1,950 2019-11-14
Bravia Firmware HIGH 7.5
CVE-2019-11889

Sony BRAVIA Smart TV devices allow remote attackers to cause a denial of service (device hang) via a crafted web page over HbbTV.

No fix yet
Fix from $1,950 2019-07-09
Bravia Firmware HIGH 7.5
CVE-2019-11890

Sony Bravia Smart TV devices allow remote attackers to cause a denial of service (device hang or reboot) via a SYN flood attack over a wired or Wi-Fi…

No fix yet
Fix from $1,950 2019-07-09
Vaio Update HIGH 7.8
CVE-2019-5981

Improper authorization vulnerability in VAIO Update 7.3.0.03150 and earlier allows an attackers to execute arbitrary executable file with administrat…

Fix: after 7.3.0.03150
Fix from $1,950 2019-07-05
Vaio Update HIGH 7.5
CVE-2019-5982

Improper download file verification vulnerability in VAIO Update 7.3.0.03150 and earlier allows remote attackers to conduct a man-in-the-middle attac…

Fix: after 7.3.0.03150
Fix from $1,950 2019-07-05
R5c Firmware HIGH 8.8
CVE-2018-16593

The Photo Sharing Plus component on Sony Bravia TV through 8.587 devices allows Shell Metacharacter Injection.

Fix: 8.216 / 8.464+
Fix from $1,950 2019-06-19
R5c Firmware HIGH 8.1
CVE-2018-16594

The Photo Sharing Plus component on Sony Bravia TV through 8.587 devices allows Directory Traversal.

Fix: 8.216 / 8.464+
Fix from $1,950 2019-06-19