Vulnerability index

Browse CVEs

100 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

MEDIUM 6.5 CVE-2025-49186 The product does not implement sufficient measures to prevent multiple failed authentication attempts within a short time frame, making it susceptibl… Media Server Mitigation only Fix from $1,6002025-06-12 CRITICAL 9.8 CVE-2025-1041 An improper input validation discovered in Avaya Call Management System could allow an unauthorized remote command via a specially crafted web re… Call Management System 19.2.0.7 / 20.0.1.0+ Fix from $2,3002025-06-10 MEDIUM 6.1 CVE-2024-12756 An HTML Injection vulnerability in Avaya Spaces may have allowed disclosure of sensitive information or modification of the page content seen by the … Spaces Mitigation only Fix from $1,6002025-02-11 MEDIUM 5.4 CVE-2024-12755 A Cross-Site Scripting (XSS) vulnerability in Avaya Spaces may have allowed unauthorized code execution and potential disclose of sensitive informati… Spaces Mitigation only Fix from $1,6002025-02-11 MEDIUM 6.7 CVE-2024-7477 A SQL injection vulnerability was found which could allow a command line interface (CLI) user with administrative privileges to execute arbitrary que… Aura System Manager after 10.1.2 Fix from $1,6002024-08-08 CRITICAL 9.8 CVE-2024-4197 An unrestricted file upload vulnerability in Avaya IP Office was discovered that could allow remote command or code execution via the One-X component… Ip Office 11.1.3.1+ Fix from $2,3002024-06-25 CRITICAL 9.8 CVE-2024-4196 An improper input validation vulnerability was discovered in Avaya IP Office that could allow remote command or code execution via a specially craft… Ip Office 11.1.3.1+ Fix from $2,3002024-06-25 CRITICAL 9.8 CVE-2023-3722 An OS command injection vulnerability was found in the Avaya Aura Device Services Web application which could allow remote code execution as the Web … Aura Device Services after 8.1.4.0 Fix from $2,3002023-07-19 MEDIUM 6.8 CVE-2023-3527 A CSV injection vulnerability was found in the Avaya Call Management System (CMS) Supervisor web application which allows a user with administrative … Call Management System 20.0.0.0+ Fix from $1,6002023-07-18 MEDIUM 6.5 CVE-2023-31187 Avaya IX Workforce Engagement v15.2.7.1195 - CWE-522: Insufficiently Protected Credentials Ix Workforce Engagement No fix yet Fix from $1,6002023-05-30 MEDIUM 6.1 CVE-2023-32218 Avaya IX Workforce Engagement v15.2.7.1195 - CWE-601: URL Redirection to Untrusted Site ('Open Redirect') Ix Workforce Engagement Mitigation only Fix from $1,6002023-05-30 MEDIUM 5.3 CVE-2023-31186 Avaya IX Workforce Engagement v15.2.7.1195 - User Enumeration - Observable Response Discrepancy Ix Workforce Engagement Mitigation only Fix from $1,6002023-05-30 CRITICAL 9.1 CVE-2022-38168 Broken Access Control in User Authentication in Avaya Scopia Pathfinder 10 and 20 PTS version 8.3.7.0.4 allows remote unauthenticated attackers to by… Scopia Pathfinder 10 Pts Firmware No fix yet Fix from $2,3002022-11-03 MEDIUM 6.7 CVE-2022-2249 Privilege escalation related vulnerabilities were discovered in Avaya Aura Communication Manager that may allow local administrative users to escalat… Aura Communication Manager 8.1.3.4+ Fix from $1,6002022-10-12 MEDIUM 6.7 CVE-2022-2975 A vulnerability related to weak permissions was detected in Avaya Aura Application Enablement Services web application, allowing an administrative us… Aura Application Enablement Services 8.1.3.5 / 10.1.0.2+ Fix from $1,6002022-10-06 HIGH 7.8 CVE-2021-25657 A privilege escalation vulnerability was discovered in Avaya IP Office Admin Lite and USB Creator that may potentially allow a local user to escalate… Ip Office 11.1+ Fix from $1,9502022-09-02 HIGH 7.8 CVE-2021-25654 An arbitrary code execution vulnerability was discovered in Avaya Aura Device Services that may potentially allow a local user to execute specially c… Aura Device Services after 8.1.4.0 Fix from $1,9502021-06-25 MEDIUM 6.1 CVE-2021-25655 A vulnerability in the system Service Menu component of Avaya Aura Experience Portal may allow URL Redirection to any untrusted site through a crafte… Aura Experience Portal after 7.2.3 Fix from $1,6002021-06-24 MEDIUM 5.4 CVE-2021-25656 Stored XSS injection vulnerabilities were discovered in the Avaya Aura Experience Portal Web management which could allow an authenticated user to po… Aura Experience Portal after 7.2.3 Fix from $1,6002021-06-24 HIGH 8.8 CVE-2021-25650 A privilege escalation vulnerability was discovered in Avaya Aura Utility Services that may potentially allow a local user to execute specially craft… Aura Utility Services after 7.1.3 Fix from $1,9502021-06-24 HIGH 7.8 CVE-2021-25651 A privilege escalation vulnerability was discovered in Avaya Aura Utility Services that may potentially allow a local user to escalate privileges. Af… Aura Utility Services after 7.1.3 Fix from $1,9502021-06-24 HIGH 7.8 CVE-2021-25653 A privilege escalation vulnerability was discovered in Avaya Aura Appliance Virtualization Platform Utilities (AVPU) that may potentially allow a loc… Aura Appliance Virtualization Platform after 8.1.3.1 Fix from $1,9502021-06-24 MEDIUM 5.5 CVE-2021-25649 An information disclosure vulnerability was discovered in the directory and file management of Avaya Aura Utility Services. This vulnerability may po… Aura Utility Services after 7.1.3 Fix from $1,6002021-06-24 MEDIUM 5.5 CVE-2021-25652 An information disclosure vulnerability was discovered in the directory and file management of Avaya Aura Appliance Virtualization Platform Utilities… Aura Appliance Virtualization Platform after 8.1.3.1 Fix from $1,6002021-06-24 HIGH 8.1 CVE-2020-7037 An XML External Entities (XXE) vulnerability in Media Server component of Avaya Equinox Conferencing could allow an authenticated, remote attacker to… Equinox Conferencing 9.1.11+ Fix from $1,9502021-04-28 HIGH 7.5 CVE-2020-7038 A vulnerability was discovered in Management component of Avaya Equinox Conferencing that could potentially allow an unauthenticated, remote attacker… Equinox Conferencing 9.1.11+ Fix from $1,9502021-04-28 HIGH 8.8 CVE-2020-7034 A command injection vulnerability in Avaya Session Border Controller for Enterprise could allow an authenticated, remote attacker to send specially c… Session Border Controller For Enterprise 8.1.2.0+ Fix from $1,9502021-04-23 MEDIUM 6.5 CVE-2020-7035 An XML External Entities (XXE)vulnerability in the web-based user interface of Avaya Aura Orchestration Designer could allow an authenticated, remote… Aura Orchestration Designer after 7.2.2 Fix from $1,6002021-04-23 MEDIUM 6.5 CVE-2020-7036 An XML External Entities (XXE)vulnerability in Callback Assist could allow an authenticated, remote attacker to gain read access to information that … Callback Assist 4.7.1.1+ Fix from $1,6002021-04-23 MEDIUM 6.5 CVE-2020-7032 An XML external entity (XXE) vulnerability in Avaya WebLM admin interface allows authenticated users to read arbitrary files or conduct server-side r… Aura System Manager 8.1.3+ Fix from $1,6002020-11-13