Vulmon
Recent Vulnerabilities
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
mitel vulnerabilities and exploits
(subscribe to this query)
5
CVSSv2
CVE-2018-18819
A vulnerability in the web conference chat component of MiCollab, versions 7.3 PR6 (7.3.0.601) and previous versions, and 8.0 (8.0.0.40) up to and including 8.0 SP2 FP2 (8.0.2.202), and MiVoice Business Express versions 7.3 PR3 (7.3.1.302) and previous versions, and 8.0 (8.0.0.40...
Mitel Micollab
Mitel Mivoice Business Express
10
CVSSv2
CVE-2019-12165
MiCollab 7.3 PR2 (7.3.0.204) and previous versions, 7.2 (7.2.2.13) and previous versions, and 7.1 (7.1.0.57) and previous versions and MiCollab AWV 6.3 (6.3.0.103), 6.2 (6.2.2.8), 6.1 (6.1.0.28), 6.0 (6.0.0.61), and 5.0 (5.0.5.7) have a Command Execution Vulnerability. Successful...
Mitel Micollab
Mitel Micollab Audio\\, Web \\& Video Conferencing
7.5
CVSSv2
CVE-2018-18285
SQL injection vulnerabilities in CMG Suite 8.4 SP2 and previous versions, could allow an unauthenticated malicious user to conduct an SQL injection attack due to insufficient input validation for the login interface. A successful exploit could allow an malicious user to extract s...
Mitel Cmg Suite 8.4
Mitel Cmg Suite
7.5
CVSSv2
CVE-2018-18286
SQL injection vulnerabilities in CMG Suite 8.4 SP2 and previous versions, could allow an unauthenticated malicious user to conduct an SQL injection attack due to insufficient input validation for the changepwd interface. A successful exploit could allow an malicious user to extra...
Mitel Cmg Suite 8.4
Mitel Cmg Suite
10
CVSSv2
CVE-2018-19275
The BluStar component in Mitel InAttend prior to 2.5 SP3 and CMG prior to 8.4 SP3 Suite Servers has a default password, which could allow remote malicious users to gain unauthorized access and execute arbitrary scripts with potential impacts to the confidentiality, integrity and ...
Mitel Cmg Suite
Mitel Cmg Suite 8.4
Mitel Inattend
Mitel Inattend 2.5
4.3
CVSSv2
CVE-2019-9592
A reflected Cross-site scripting (XSS) vulnerability in ShoreTel Connect ONSITE 19.45.1602.0 allows remote malicious users to inject arbitrary web script or HTML via the url parameter.
Mitel Connect Onsite 19.45.1602.0
1 EDB exploit
4.3
CVSSv2
CVE-2019-9593
A reflected Cross-site scripting (XSS) vulnerability in ShoreTel Connect ONSITE 18.82.2000.0 allows remote malicious users to inject arbitrary web script or HTML via the page parameter.
Mitel Connect Onsite 18.82.2000.0
1 EDB exploit
4.3
CVSSv2
CVE-2019-9591
A reflected Cross-site scripting (XSS) vulnerability in ShoreTel Connect ONSITE prior to 19.49.1500.0 allows remote malicious users to inject arbitrary web script or HTML via the brandUrl parameter.
Mitel Connect Onsite
1 EDB exploit
4.3
CVSSv2
CVE-2018-16226
A vulnerability in the web admin component of Mitel MiVoice Office 400, versions R5.0 HF3 (v8839a1) and previous versions, could allow an unauthenticated malicious user to conduct a reflected cross-site scripting (XSS) attack, due to insufficient validation for the start.asp page...
Mitel Mivoice Office 400 R5.0
10
CVSSv2
CVE-2018-15497
The Mitel MiVoice 5330e VoIP device is affected by memory corruption flaws in the SIP/SDP packet handling functionality. An attacker can exploit this issue remotely, by sending a particular pattern of SIP/SDP packets, to cause a denial of service state in the affected devices and...
Mitel Mivoice 5330e Firmware
CVSSv2
CVSSv2
CVSSv3
VMScore
Recommendations:
CVE-2024-33572
CVE-2024-24919
CVE-2024-0230
CVE-2024-32714
HTML injection
local file inclusion
CVE-2024-31098
CVE-2024-31244
privilege
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
« PREV
5
6
7
8
9
10
NEXT »