Vulmon
Recent Vulnerabilities
Product List
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
mitel vulnerabilities and exploits
(subscribe to this query)
668
VMScore
CVE-2020-10211
A remote code execution vulnerability in UCB component of Mitel MiVoice Connect prior to 19.1 SP1 could allow an unauthenticated remote malicious user to execute arbitrary scripts due to insufficient validation of URL parameters. A successful exploit could allow an malicious user...
Mitel Mivoice Connect Client
Mitel Mivoice Connect
668
VMScore
CVE-2018-18285
SQL injection vulnerabilities in CMG Suite 8.4 SP2 and previous versions, could allow an unauthenticated malicious user to conduct an SQL injection attack due to insufficient input validation for the login interface. A successful exploit could allow an malicious user to extract s...
Mitel Cmg Suite 8.4
Mitel Cmg Suite
NA
CVE-2023-25599
A vulnerability in the conferencing component of Mitel MiVoice Connect up to and including 19.3 SP2, 22.24.1500.0 could allow an unauthenticated malicious user to conduct a reflected cross-site scripting (XSS) attack due to insufficient validation for the test_presenter.php page....
Mitel Mivoice Connect
Mitel Mivoice Connect 19.3
668
VMScore
CVE-2018-18286
SQL injection vulnerabilities in CMG Suite 8.4 SP2 and previous versions, could allow an unauthenticated malicious user to conduct an SQL injection attack due to insufficient input validation for the changepwd interface. A successful exploit could allow an malicious user to extra...
Mitel Cmg Suite 8.4
Mitel Cmg Suite
NA
CVE-2022-41223
The Director database component of MiVoice Connect up to and including 19.3 (22.22.6100.0) could allow an authenticated malicious user to conduct a code-injection attack via crafted data due to insufficient restrictions on the database data type.
Mitel Mivoice Connect
Mitel Mivoice Connect 19.3
605
VMScore
CVE-2022-31784
A vulnerability in the management interface of MiVoice Business up to and including 9.3 PR1 and MiVoice Business Express up to and including 8.0 SP3 PR3 could allow an unauthenticated attacker (that has network access to the management interface) to conduct a buffer overflow atta...
Mitel Mivoice Business
Mitel Mivoice Business Express
445
VMScore
CVE-2020-10377
A weak encryption vulnerability in Mitel MiVoice Connect Client prior to 214.100.1214.0 could allow an unauthenticated malicious user to gain access to user credentials. A successful exploit could allow an malicious user to access the system with compromised user credentials.
Mitel Mivoice Connect Client
Mitel Mivoice Connect
427
VMScore
CVE-2020-27640
The Bluetooth handset of Mitel MiVoice 6940 and 6930 MiNet phones with firmware prior to 1.5.3 could allow an unauthenticated attacker within Bluetooth range to pair a rogue Bluetooth device when a phone handset loses connection, due to an improper pairing mechanism. A successful...
Mitel Mivoice 6940 Firmware
Mitel Mivoice 6930 Firmware
383
VMScore
CVE-2020-12679
A reflected cross-site scripting (XSS) vulnerability in the Mitel ShoreTel Conference Web Application 19.50.1000.0 before MiVoice Connect 18.7 SP2 allows remote malicious users to inject arbitrary JavaScript and HTML via the PATH_INFO to home.php.
Mitel Shoretel Conference Web 19.50.1000.0
Mitel Mivoice Connect
890
VMScore
CVE-2019-12165
MiCollab 7.3 PR2 (7.3.0.204) and previous versions, 7.2 (7.2.2.13) and previous versions, and 7.1 (7.1.0.57) and previous versions and MiCollab AWV 6.3 (6.3.0.103), 6.2 (6.2.2.8), 6.1 (6.1.0.28), 6.0 (6.0.0.61), and 5.0 (5.0.5.7) have a Command Execution Vulnerability. Successful...
Mitel Micollab
Mitel Micollab Audio, Web & Video Conferencing
VMScore
CVSSv2
CVSSv3
VMScore
Recommendations:
path traversal
CVE-2024-33545
CVE-2024-35725
CVE-2024-32704
overflow
file upload
CVE-2024-0230
CVE-2024-32705
CVE-2024-23692
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
« PREV
1
2
3
4
5
6
7
8
NEXT »