Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2975▼ 108 respecto a la semana anterior
Críticas / altas1449▲ 87 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
201 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (4.3) | 0.76% | — | Cybozu Garoon | 4/7/2022 | 17/6/2026 | Operation restriction bypass vulnerability in Bulletin of Cybozu Garoon 4.0.0 to 5.5.1 allow a remote authenticated attacker to alter the data of Bulletin. | |
| Modificada | Media (5.3) | 1.1% | — | Cybozu Garoon | 4/7/2022 | 17/6/2026 | Improper authentication vulnerability in Scheduler of Cybozu Garoon 4.10.0 to 5.5.1 allows a remote attacker to obtain some data of Facility Information without logging in to the product. | |
| Modificada | Media (4.3) | 0.73% | — | Cybozu Garoon | 4/7/2022 | 17/6/2026 | Improper input validation vulnerability in Scheduler of Cybozu Garoon 4.0.0 to 5.5.1 allows a remote authenticated attacker to alter the data of Scheduler. | |
| Modificada | Media (4.3) | 0.73% | — | Cybozu Garoon | 4/7/2022 | 17/6/2026 | Improper input validation vulnerability in Link of Cybozu Garoon 4.0.0 to 5.5.1 allows a remote authenticated attacker to disable to add Categories. | |
| Modificada | Media (4.3) | 0.73% | — | Cybozu Garoon | 4/7/2022 | 17/6/2026 | Improper input validation vulnerability in Space of Cybozu Garoon 4.0.0 to 5.5.1 allows a remote authenticated attacker to alter the data of Space. | |
| Modificada | Media (4.3) | 0.76% | — | Cybozu Garoon | 4/7/2022 | 17/6/2026 | Operation restriction bypass vulnerability in Workflow of Cybozu Garoon 4.0.0 to 5.5.1 allows a remote authenticated attacker to alter the data of Workflow. | |
| Modificada | Media (6.1) | 0.70% | — | Cybozu Garoon | 4/7/2022 | 17/6/2026 | Cross-site scripting vulnerability in Organization's Information of Cybozu Garoon 4.10.2 to 5.5.1 allows a remote attacker to execute an arbitrary script on the logged-in user's web browser. | |
| Modificada | Media (5.4) | 0.71% | — | Cybozu Garoon | 4/7/2022 | 17/6/2026 | Browse restriction bypass and operation restriction bypass vulnerability in Cabinet of Cybozu Garoon 4.0.0 to 5.5.1 allows a remote authenticated attacker to alter and/or obtain the data of Cabinet. | |
| Modificada | Media (4.3) | 0.76% | — | Cybozu Garoon | 4/7/2022 | 17/6/2026 | Operation restriction bypass vulnerability in Link of Cybozu Garoon 4.0.0 to 5.5.1 allows a remote authenticated attacker to alter the data of Link. | |
| Modificada | Media (4.3) | 0.76% | — | Cybozu Garoon | 4/7/2022 | 17/6/2026 | Operation restriction bypass vulnerability in Portal of Cybozu Garoon 4.0.0 to 5.5.1 allows a remote authenticated attacker to alter the data of Portal. | |
| Modificada | Media (4.3) | 0.88% | — | Cybozu Garoon | 18/8/2021 | 17/6/2026 | Improper input validation vulnerability in Bulletin of Cybozu Garoon 4.10.0 to 5.5.0 allows a remote authenticated attacker to obtain the data of Comment and Space without the viewing privilege. | |
| Modificada | Media (5.4) | 0.60% | — | Cybozu Garoon | 18/8/2021 | 17/6/2026 | Cross-site scripting vulnerability in some functions of E-mail of Cybozu Garoon 4.0.0 to 5.5.0 allows a remote authenticated attacker to inject an arbitrary script via unspecified vectors. | |
| Modificada | Media (4.3) | 0.78% | — | Cybozu Garoon | 18/8/2021 | 17/6/2026 | There is a vulnerability in Workflow of Cybozu Garoon 4.0.0 to 5.5.0, which may allow a remote authenticated attacker to delete the route information Workflow without the appropriate privilege. | |
| Modificada | Media (4.3) | 0.88% | — | Cybozu Garoon | 18/8/2021 | 17/6/2026 | Information disclosure vulnerability in Bulletin of Cybozu Garoon 4.10.0 to 5.5.0 allows a remote authenticated attacker to obtain the title of Bulletin without the viewing privilege. | |
| Modificada | Media (6.1) | 0.80% | — | Cybozu Garoon | 18/8/2021 | 17/6/2026 | Cross-site scripting vulnerability in some functions of E-Mail of Cybozu Garoon 4.0.0 to 5.5.0 allows a remote attacker to inject an arbitrary script via unspecified vectors. | |
| Modificada | Media (5.4) | 0.60% | — | Cybozu Garoon | 18/8/2021 | 17/6/2026 | Cross-site scripting vulnerability in Message of Cybozu Garoon 4.6.0 to 5.0.2 allows a remote authenticated attacker to inject an arbitrary script via unspecified vectors. | |
| Modificada | Media (5.4) | 0.60% | — | Cybozu Garoon | 18/8/2021 | 17/6/2026 | Cross-site scripting vulnerability in Bulletin of Cybozu Garoon 4.6.0 to 5.0.2 allows a remote authenticated attacker to inject an arbitrary script via unspecified vectors. | |
| Modificada | Media (4.3) | 0.82% | — | Cybozu Garoon | 18/8/2021 | 17/6/2026 | Operational restrictions bypass vulnerability in Scheduler and MultiReport of Cybozu Garoon 4.0.0 to 5.0.2 allows a remote authenticated attacker to delete the data of Scheduler and MultiReport without the appropriate privilege. | |
| Modificada | Media (5.4) | 0.61% | — | Cybozu Garoon | 18/8/2021 | 17/6/2026 | Cross-site scripting vulnerability in Full Text Search of Cybozu Garoon 4.0.0 to 5.0.2 allows a remote authenticated attacker to inject an arbitrary script via unspecified vectors. | |
| Modificada | Media (6.1) | 0.76% | — | Cybozu Garoon | 18/8/2021 | 17/6/2026 | Cross-site scripting vulnerability in Message of Cybozu Garoon 4.0.0 to 5.0.2 allows a remote attacker to inject an arbitrary script via unspecified vectors. | |
| Modificada | Media (6.1) | 0.80% | — | Cybozu Garoon | 18/8/2021 | 17/6/2026 | Cross-site scripting vulnerability in Bulletin of Cybozu Garoon 4.0.0 to 5.0.2 allows a remote attacker to inject an arbitrary script via unspecified vectors. | |
| Modificada | Media (5.3) | 0.99% | — | Cybozu Garoon | 18/8/2021 | 17/6/2026 | Improper input validation vulnerability in Attaching Files of Cybozu Garoon 4.0.0 to 5.0.2 allows a remote attacker to alter the data of Attaching Files. | |
| Modificada | Media (4.3) | 0.93% | — | Cybozu Garoon | 18/8/2021 | 17/6/2026 | Operational restrictions bypass vulnerability in Portal of Cybozu Garoon 4.0.0 to 5.0.2 allows a remote authenticated attacker to obtain the data of Portal without the appropriate privilege. | |
| Modificada | Media (4.3) | 0.80% | — | Cybozu Garoon | 18/8/2021 | 17/6/2026 | Improper input validation vulnerability in E-mail of Cybozu Garoon 4.0.0 to 5.0.2 allows a remote authenticated to alter the data of E-mail without the appropriate privilege. | |
| Modificada | Baja (2.7) | 0.75% | — | Cybozu Garoon | 18/8/2021 | 17/6/2026 | Improper input validation vulnerability in E-mail of Cybozu Garoon 4.0.0 to 5.0.2 allows a remote attacker with an administrative privilege to alter the data of E-mail without the appropriate privilege. |