Skip to main content

Vendor archive

sony CVEs

Beta · best-effort

74 CVEs tagged to vendor sony11 Critical, 35 High, 26 Medium, 2 Low, 0 Unrated.

CVE-2020-36924

Published Jan 6, 2026

Sony BRAVIA Digital Signage 1.7.8 contains a remote file inclusion vulnerability that allows attackers to inject arbitrary client-side scripts through the content material URL par…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-36923

Published Jan 6, 2026

Sony BRAVIA Digital Signage 1.7.8 contains an insecure direct object reference vulnerability that allows attackers to bypass authorization controls. Attackers can access hidden sy…

CVSS 6.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-36922

Published Jan 6, 2026

Sony BRAVIA Digital Signage 1.7.8 contains an information disclosure vulnerability that allows unauthenticated attackers to access sensitive system details through API endpoints.…

CVSS 6.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-36885

Published Dec 10, 2025

Sony IPELA Network Camera 1.82.01 contains a stack buffer overflow vulnerability in the ftpclient.cgi endpoint that allows remote attackers to execute arbitrary code. Attackers ca…

CVSS 9.3 · Critical
Vendor/product tagsBeta · best-effort

CVE-2025-64730

Published Nov 25, 2025

Cross-site scripting vulnerability exists in SNC-CX600W all versions. If this vulnerability is exploited, an arbitrary script may be executed on the web browser of the user who ac…

CVSS 4.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-62497

Published Nov 25, 2025

Cross-site request forgery vulnerability exists in SNC-CX600W versions prior to Ver.2.8.0. If a user accesses a specially crafted webpage while logged in, unintended operations ma…

CVSS 2.1 · Low
evidence mentions
2
Buzz score
21.0
Vendor/product tagsBeta · best-effort

CVE-2025-5820

Published Jun 21, 2025

Sony XAV-AX8500 Bluetooth ERTM Channel Authentication Bypass Vulnerability. This vulnerability allows network-adjacent attackers to bypass authentication on affected Sony XAV-AX85…

CVSS 8.8 · High
evidence mentions
2
Buzz score
21.0
Vendor/product tagsBeta · best-effort

CVE-2025-5479

Published Jun 21, 2025

Sony XAV-AX8500 Bluetooth AVCTP Protocol Heap-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary…

CVSS 7.5 · High
evidence mentions
2
Buzz score
21.0
Vendor/product tagsBeta · best-effort

CVE-2025-5478

Published Jun 21, 2025

Sony XAV-AX8500 Bluetooth SDP Protocol Integer Overflow Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code on affe…

CVSS 8.8 · High
evidence mentions
2
Buzz score
21.0
Vendor/product tagsBeta · best-effort

CVE-2025-5477

Published Jun 21, 2025

Sony XAV-AX8500 Bluetooth L2CAP Protocol Heap-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary…

CVSS 7.5 · High
evidence mentions
2
Buzz score
21.0
Vendor/product tagsBeta · best-effort

CVE-2025-5476

Published Jun 21, 2025

Sony XAV-AX8500 Bluetooth Improper Isolation Authentication Bypass Vulnerability. This vulnerability allows network-adjacent attackers to bypass authentication on affected Sony XA…

CVSS 8.8 · High
evidence mentions
2
Buzz score
21.0
Vendor/product tagsBeta · best-effort

CVE-2025-5475

Published Jun 21, 2025

Sony XAV-AX8500 Bluetooth Packet Handling Integer Overflow Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code on a…

CVSS 7.5 · High
evidence mentions
2
Buzz score
21.0
Vendor/product tagsBeta · best-effort

CVE-2024-23972

Published Sep 23, 2024

Sony XAV-AX5500 USB Configuration Descriptor Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows physically present attackers to execute arbitrary code…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-23922

Published Sep 23, 2024

Sony XAV-AX5500 Insufficient Firmware Update Validation Remote Code Execution Vulnerability. This vulnerability allows physically present attackers to execute arbitrary code on af…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-41796

Published Oct 24, 2022

Untrusted search path vulnerability in the installer of Content Transfer (for Windows) Ver.1.3 and prior allows an attacker to gain privileges via a Trojan horse DLL in an unspeci…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2022-27094

Published May 20, 2022

Sony PlayMemories Home v6.0 contains an unquoted service path which allows attackers to escalate privileges to the system level.

CVSS 6.7 · Medium
Vendor/product tagsBeta · best-effort

CVE-2019-15744

Published Nov 14, 2019

The Sony Xperia Xperia XZs Android device with a build fingerprint of Sony/keyaki_softbank/keyaki_softbank:7.1.1/TONE3-3.0.0-SOFTBANK-170517-0323/1:user/dev-keys contains a pre-in…

CVSS 3.3 · Low
Vendor/product tagsBeta · best-effort

CVE-2019-15416

Published Nov 14, 2019

The Sony keyaki_kddi Android device with a build fingerprint of Sony/keyaki_kddi/keyaki_kddi:7.1.1/TONE3-3.0.0-KDDI-170517-0326/1:user/dev-keys contains a pre-installed app with a…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort
Showing 1-25 of 74 CVEsPage 1 of 3