Top technology
Linux 13140
Google 12536
Microsoft 12379
Oracle 6843
Apple 6692
Adobe 6387
Ibm 6336
Cisco 5759
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
HIGH 7.2
CVE-2019-16965
resources/cmd.php in FusionPBX up to 4.5.7 suffers from a command injection vulnerability due to a lack of input validation, which allows authenticat…
Fusionpbx
after 4.5.7
MEDIUM 6.5
CVE-2019-16985
In FusionPBX up to v4.5.7, the file app\xml_cdr\xml_cdr_delete.php uses an unsanitized "rec" variable coming from the URL, which is base64 decoded an…
Fusionpbx
after 4.5.7
MEDIUM 6.5
CVE-2019-16986
In FusionPBX up to v4.5.7, the file resources\download.php uses an unsanitized "f" variable coming from the URL, which takes any pathname and allows …
Fusionpbx
after 4.5.7
MEDIUM 6.1
CVE-2019-16987
In FusionPBX up to v4.5.7, the file app\contacts\contact_import.php uses an unsanitized "query_string" variable coming from the URL, which is reflect…
Fusionpbx
after 4.5.7
MEDIUM 6.1
CVE-2019-16988
In FusionPBX up to v4.5.7, the file app\basic_operator_panel\resources\content.php uses an unsanitized "eavesdrop_dest" variable coming from the URL,…
Fusionpbx
after 4.5.7
MEDIUM 6.1
CVE-2019-16989
In FusionPBX up to v4.5.7, the file app\conferences_active\conference_interactive.php uses an unsanitized "c" variable coming from the URL, which is …
Fusionpbx
after 4.5.7
MEDIUM 6.1
CVE-2019-16991
In FusionPBX up to v4.5.7, the file app\edit\filedelete.php uses an unsanitized "file" variable coming from the URL, which is reflected in HTML, lead…
Fusionpbx
after 4.5.7
MEDIUM 6.1
CVE-2019-16981
In FusionPBX up to v4.5.7, the file app\conference_profiles\conference_profile_params.php uses an unsanitized "id" variable coming from the URL, whic…
Fusionpbx
after 4.5.7
MEDIUM 6.1
CVE-2019-16982
In FusionPBX up to v4.5.7, the file app\access_controls\access_control_nodes.php uses an unsanitized "id" variable coming from the URL, which is refl…
Fusionpbx
after 4.5.7
MEDIUM 6.1
CVE-2019-16983
In FusionPBX up to v4.5.7, the file resources\paging.php has a paging function (called by several pages of the interface), which uses an unsanitized …
Fusionpbx
after 4.5.7
MEDIUM 6.1
CVE-2019-16984
In FusionPBX up to v4.5.7, the file app\recordings\recording_play.php uses an unsanitized "filename" variable coming from the URL, which is base64 de…
Fusionpbx
after 4.5.7
HIGH 8.8
CVE-2019-16980
In FusionPBX up to v4.5.7, the file app\call_broadcast\call_broadcast_edit.php uses an unsanitized "id" variable coming from the URL in an unparamete…
Fusionpbx
after 4.5.7
MEDIUM 6.5
CVE-2019-16990
In FusionPBX up to v4.5.7, the file app/music_on_hold/music_on_hold.php uses an unsanitized "file" variable coming from the URL, which takes any path…
Fusionpbx
after 4.5.7
MEDIUM 6.1
CVE-2019-16978
In FusionPBX up to v4.5.7, the file app\devices\device_settings.php uses an unsanitized "id" variable coming from the URL, which is reflected on 2 oc…
Fusionpbx
after 4.5.7
MEDIUM 6.1
CVE-2019-16979
In FusionPBX up to v4.5.7, the file app\contacts\contact_urls.php uses an unsanitized "id" variable coming from the URL, which is reflected in HTML, …
Fusionpbx
after 4.5.7
HIGH 8.8
CVE-2019-15029EPSS 12%
FusionPBX 4.4.8 allows an attacker to execute arbitrary system commands by submitting a malicious command to the service_edit.php file (which will in…
Fusionpbx
No fix yet
HIGH 8.8
CVE-2019-11409EPSS 87%
app/operator_panel/exec.php in the Operator Panel module in FusionPBX 4.4.3 suffers from a command injection vulnerability due to a lack of input val…
Fusionpbx
Patch available
HIGH 7.2
CVE-2019-11410
app/backup/index.php in the Backup Module in FusionPBX 4.4.3 suffers from a command injection vulnerability due to a lack of input validation, which …
Fusionpbx
Patch available
HIGH 7.2
CVE-2019-11407
app/operator_panel/index_inc.php in the Operator Panel module in FusionPBX 4.4.3 suffers from an information disclosure vulnerability due to excessiv…
Fusionpbx
Patch available
MEDIUM 6.1
CVE-2019-11408EPSS 7%
XSS in app/operator_panel/index_inc.php in the Operator Panel module in FusionPBX 4.4.3 allows remote unauthenticated attackers to inject arbitrary J…
Fusionpbx
Patch available