Vulnerabilidades em Cybozu, Inc.

200 resultados
Análise Vexday

Com 200 CVEs catalogadas e nenhuma presença no catálogo KEV da CISA, o perfil de exploração ativa da Cybozu, Inc. situa-se abaixo da média geral do catálogo, indicando baixa atratividade imediata para agentes de ameaça oportunistas. O tipo de falha mais recorrente é CWE-79 (Cross-Site Scripting), o que sugere atenção contínua à validação de entrada e sanitização de saída nas aplicações do vendor. A CVE de maior risco identificada atualmente é CVE-2020-5537, com pontuação EPSS de 0,0293, refletindo probabilidade ainda baixa de exploração em larga escala no curto prazo. A ausência de PoCs públicas e de novas vulnerabilidades nos últimos 90 dias reduz a pressão imediata de remediação, embora o monitoramento contínuo permaneça recomendável dado o volume acumulado de registros.

CVE-2022-29892Improper input validation vulnerability in Space of Cybozu Garoon 4.0.0 to 5.5.1 allows a remote authenticated attacker to repeatedly displaEPSS 1.1%CVE-2017-2109Cybozu KUNAI for Android 3.0.4 to 3.0.5.1 allow remote attackers to obtain log information through a malicious Android application.EPSS 1.1%CVE-2017-2115Cybozu Office 10.0.0 to 10.5.0 allows remote authenticated attackers to bypass access restriction to obtain "customapp" information via unspEPSS 1.0%CVE-2019-5929Cross-site scripting vulnerability in Cybozu Garoon 4.0.0 to 4.6.3 allows remote attackers to inject arbitrary web script or HTML via the apEPSS 1.0%CVE-2019-5939Cross-site scripting vulnerability in Cybozu Garoon 4.0.0 to 4.10.1 allows remote attackers to inject arbitrary web script or HTML via the aEPSS 1.0%CVE-2019-5938Cross-site scripting vulnerability in Cybozu Garoon 4.0.0 to 4.10.1 allows remote attackers to inject arbitrary web script or HTML via the aEPSS 1.0%CVE-2019-5940Cross-site scripting vulnerability in Cybozu Garoon 4.0.0 to 4.10.1 allows remote attackers to inject arbitrary web script or HTML via the aEPSS 1.0%CVE-2019-6023Cybozu Office 10.0.0 to 10.8.3 allows remote authenticated attackers to bypass access restriction which may result in obtaining data withoutEPSS 1.0%CVE-2020-5588Path traversal vulnerability in Cybozu Garoon 5.0.0 to 5.0.1 allows attacker with administrator rights to obtain unintended information via EPSS 1.0%CVE-2020-5583Cybozu Garoon 4.0.0 to 5.0.1 allows remote authenticated attackers to bypass access restriction to obtain unauthorized Multi-Report's data vEPSS 1.0%CVE-2021-20802HTTP header injection vulnerability in Cybozu Remote Service 3.1.8 to 3.1.9 allows a remote attacker to alter the information stored in the EPSS 1.0%CVE-2021-20764Improper input validation vulnerability in Attaching Files of Cybozu Garoon 4.0.0 to 5.0.2 allows a remote attacker to alter the data of AttEPSS 1.0%CVE-2018-0550Cybozu Garoon 3.5.0 to 4.6.1 allows remote authenticated attackers to bypass access restriction to view the closed title of "Cabinet" via unEPSS 1.0%CVE-2022-29512Exposure of sensitive information to an unauthorized actor issue in multiple applications of Cybozu Garoon 4.0.0 to 5.9.1 allows a remote auEPSS 1.0%CVE-2022-26838Path traversal vulnerability in Importing Mobile Device Data of Cybozu Remote Service 3.1.2 allows a remote authenticated attacker to cause EPSS 1.0%CVE-2021-20756Viewing restrictions bypass vulnerability in Address of Cybozu Garoon 4.0.0 to 5.0.2 allows a remote authenticated attacker to obtain the daEPSS 0.9%CVE-2021-20763Operational restrictions bypass vulnerability in Portal of Cybozu Garoon 4.0.0 to 5.0.2 allows a remote authenticated attacker to obtain theEPSS 0.9%CVE-2021-20755Viewing restrictions bypass vulnerability in Portal of Cybozu Garoon 4.0.0 to 5.0.2 allows a remote authenticated attacker to obtain the datEPSS 0.9%CVE-2020-5562Server-side request forgery (SSRF) vulnerability in Cybozu Garoon 4.6.0 to 4.6.3 allows a remote attacker with an administrative privilege tEPSS 0.9%CVE-2022-30693Information disclosure vulnerability in the system configuration of Cybozu Office 10.0.0 to 10.8.5 allows a remote attacker to obtain the daEPSS 0.9%