Vulmon
Recent Vulnerabilities
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
mitel vulnerabilities and exploits
(subscribe to this query)
4.3
CVSSv2
CVE-2019-19370
A cross-site scripting (XSS) vulnerability in the web conferencing component of the Mitel MiCollab application prior to 9.0.15 for Android could allow an unauthenticated malicious user to conduct a reflected cross-site scripting (XSS) attack due to insufficient validation in the ...
Mitel Micollab
4.3
CVSSv2
CVE-2019-19371
A cross-site scripting (XSS) vulnerability in the web conferencing component of Mitel MiCollab AWV prior to 8.1.2.2 could allow an unauthenticated malicious user to conduct a reflected cross-site scripting (XSS) attack due to insufficient validation in the join meeting interface....
Mitel Micollab Audio\\, Web \\& Video Conferencing
7.5
CVSSv2
CVE-2019-19607
A SQL injection vulnerability in the web conferencing component of Mitel MiCollab AWV prior to 8.1.2.2 could allow an unauthenticated attack due to insufficient input validation for the session parameter. A successful exploit could allow an malicious user to extract sensitive inf...
Mitel Micollab Audio\\, Web \\& Video Conferencing
7.5
CVSSv2
CVE-2019-19608
A SQL injection vulnerability in in the web conferencing component of Mitel MiCollab AWV prior to 8.1.2.2 could allow an unauthenticated attack due to insufficient input validation for the registeredList.cgi page. A successful exploit could allow an malicious user to extract sens...
Mitel Micollab Audio\\, Web \\& Video Conferencing
4
CVSSv2
CVE-2020-9379
The Software Development Kit of the MiContact Center Business with Site Based Security 8.0 up to and including 9.0.1.0 before KB496276 allows an authenticated user to access sensitive information. A successful exploit could allow unauthorized access to user conversations.
Mitel Micontact Center Business
4.3
CVSSv2
CVE-2019-19891
An encryption key vulnerability on Mitel SIP-DECT wireless devices 8.0 and 8.1 could allow an malicious user to launch a man-in-the-middle attack. A successful exploit may allow the malicious user to intercept sensitive information.
Mitel Sip-dect Firmware 8.0
Mitel Sip-dect Firmware 8.1
5
CVSSv2
CVE-2018-18819
A vulnerability in the web conference chat component of MiCollab, versions 7.3 PR6 (7.3.0.601) and previous versions, and 8.0 (8.0.0.40) up to and including 8.0 SP2 FP2 (8.0.2.202), and MiVoice Business Express versions 7.3 PR3 (7.3.1.302) and previous versions, and 8.0 (8.0.0.40...
Mitel Micollab
Mitel Mivoice Business Express
10
CVSSv2
CVE-2019-12165
MiCollab 7.3 PR2 (7.3.0.204) and previous versions, 7.2 (7.2.2.13) and previous versions, and 7.1 (7.1.0.57) and previous versions and MiCollab AWV 6.3 (6.3.0.103), 6.2 (6.2.2.8), 6.1 (6.1.0.28), 6.0 (6.0.0.61), and 5.0 (5.0.5.7) have a Command Execution Vulnerability. Successful...
Mitel Micollab
Mitel Micollab Audio\\, Web \\& Video Conferencing
7.5
CVSSv2
CVE-2018-18285
SQL injection vulnerabilities in CMG Suite 8.4 SP2 and previous versions, could allow an unauthenticated malicious user to conduct an SQL injection attack due to insufficient input validation for the login interface. A successful exploit could allow an malicious user to extract s...
Mitel Cmg Suite 8.4
Mitel Cmg Suite
7.5
CVSSv2
CVE-2018-18286
SQL injection vulnerabilities in CMG Suite 8.4 SP2 and previous versions, could allow an unauthenticated malicious user to conduct an SQL injection attack due to insufficient input validation for the changepwd interface. A successful exploit could allow an malicious user to extra...
Mitel Cmg Suite 8.4
Mitel Cmg Suite
CVSSv2
CVSSv2
CVSSv3
VMScore
Recommendations:
authentication bypass
CVE-2024-30051
remote
CVE-2024-27954
CVE-2023-51483
CVE-2023-47782
SSRF
CVE-2024-24715
CVE-2023-52424
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
« PREV
4
5
6
7
8
9
10
NEXT »