Products: 2
    Vulnerabilities: 13
    Known Exploited: 0
    0
    Critical Level Threats
    7
    High Level Threats
    4
    Medium Level Threats
    1
    Low Level Threats

    Vulnerabilities

    100806040200
    JanFebMarAprMayJunJulAugSepOctNovDec
    Critical Level Threats
    High Level Threats
    Medium Level Threats
    Low Level Threats

    Products Security index

    Actions
    Items Per Page

    Vulnerabilities

    CVE-2023-7327

    Ozeki SMS Gateway <= 10.3.208 Unauthenticated Arbitrary File Read

    Last Modified: Apr 15, 2026
    Published: Nov 12, 2025

    CVE-2020-14030

    An issue was discovered in Ozeki NG SMS Gateway through 4.17.6. It stores SMS messages in .NET serialized format on the filesystem. By generating (and writing to the disk) malicious .NET serialized files, an attacker can trick the product into deserializing them, resulting in arbitrary code execution.

    Last Modified: Nov 21, 2024
    Published: Sep 29, 2020

    CVE-2020-14022

    Ozeki NG SMS Gateway 4.17.1 through 4.17.6 does not check the file type when bulk importing new contacts ("Import Contacts" functionality) from a file. It is possible to upload an executable or .bat file that can be executed with the help of a functionality (E.g. the "Application Starter" module) within the application.

    Last Modified: Nov 21, 2024
    Published: Sep 22, 2020

    CVE-2020-14025

    Ozeki NG SMS Gateway through 4.17.6 has multiple CSRF vulnerabilities. For example, an administrator, by following a link, can be tricked into making unwanted changes such as installing new modules or changing a password.

    Last Modified: Nov 21, 2024
    Published: Sep 22, 2020

    CVE-2020-14024

    Ozeki NG SMS Gateway through 4.17.6 has multiple authenticated stored and/or reflected XSS vulnerabilities via the (1) Receiver or Recipient field in the Mailbox feature, (2) OZFORM_GROUPNAME field in the Group configuration of addresses, (3) listname field in the Defining address lists configuration, or (4) any GET Parameter in the /default URL of the application.

    Last Modified: Nov 21, 2024
    Published: Sep 22, 2020
    Items Per Page
    Ozeki Vulnerabilities & Security CVEs | CVE-DB