Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6673
Adobe 6383
Ibm 6286
Cisco 5751
Debian 3919
Mozilla 2886
Apache 2864
Redhat 2586
CRITICAL 9.8
CVE-2019-19608
A SQL injection vulnerability in in the web conferencing component of Mitel MiCollab AWV before 8.1.2.2 could allow an unauthenticated attack due to …
Micollab Audio\, Web \& Video Conferencing
after 8.1.1.11
MEDIUM 6.1
CVE-2019-19370
A cross-site scripting (XSS) vulnerability in the web conferencing component of the Mitel MiCollab application before 9.0.15 for Android could allow …
Micollab
9.0.15+
MEDIUM 6.1
CVE-2019-19371
A cross-site scripting (XSS) vulnerability in the web conferencing component of Mitel MiCollab AWV before 8.1.2.2 could allow an unauthenticated atta…
Micollab Audio\, Web \& Video Conferencing
after 8.1.1.11
MEDIUM 5.9
CVE-2019-18863
A key length vulnerability in the implementation of the SRTP 128-bit key on Mitel 6800 and 6900 SIP series phones, versions 5.1.0.2051 SP2 and earlie…
6863i Firmware
5.1.0.2051+
MEDIUM 6.5
CVE-2020-9379
The Software Development Kit of the MiContact Center Business with Site Based Security 8.0 through 9.0.1.0 before KB496276 allows an authenticated us…
Micontact Center Business
after 9.0.1.0
MEDIUM 5.9
CVE-2019-19891
An encryption key vulnerability on Mitel SIP-DECT wireless devices 8.0 and 8.1 could allow an attacker to launch a man-in-the-middle attack. A succes…
Sip Dect Firmware
Mitigation only
MEDIUM 5.3
CVE-2018-18819
A vulnerability in the web conference chat component of MiCollab, versions 7.3 PR6 (7.3.0.601) and earlier, and 8.0 (8.0.0.40) through 8.0 SP2 FP2 (8…
Micollab
after 8.0.2.202
CRITICAL 9.8
CVE-2019-12165
MiCollab 7.3 PR2 (7.3.0.204) and earlier, 7.2 (7.2.2.13) and earlier, and 7.1 (7.1.0.57) and earlier and MiCollab AWV 6.3 (6.3.0.103), 6.2 (6.2.2.8),…
Micollab
after 7.3.0.204
CRITICAL 9.8
CVE-2018-18285
SQL injection vulnerabilities in CMG Suite 8.4 SP2 and earlier, could allow an unauthenticated attacker to conduct an SQL injection attack due to ins…
Cmg Suite
after 8.4
CRITICAL 9.8
CVE-2018-18286
SQL injection vulnerabilities in CMG Suite 8.4 SP2 and earlier, could allow an unauthenticated attacker to conduct an SQL injection attack due to ins…
Cmg Suite
after 8.4
CRITICAL 9.8
CVE-2018-19275
The BluStar component in Mitel InAttend before 2.5 SP3 and CMG before 8.4 SP3 Suite Servers has a default password, which could allow remote attacker…
Cmg Suite
2.5 / 8.4+
MEDIUM 6.1
CVE-2019-9591EPSS 5%
A reflected Cross-site scripting (XSS) vulnerability in ShoreTel Connect ONSITE before 19.49.1500.0 allows remote attackers to inject arbitrary web s…
Connect Onsite
19.49.1500.0+
MEDIUM 6.1
CVE-2019-9592EPSS 5%
A reflected Cross-site scripting (XSS) vulnerability in ShoreTel Connect ONSITE 19.45.1602.0 allows remote attackers to inject arbitrary web script o…
Connect Onsite
No fix yet
MEDIUM 6.1
CVE-2019-9593
A reflected Cross-site scripting (XSS) vulnerability in ShoreTel Connect ONSITE 18.82.2000.0 allows remote attackers to inject arbitrary web script o…
Connect Onsite
No fix yet
CRITICAL 9.8
CVE-2018-15497
The Mitel MiVoice 5330e VoIP device is affected by memory corruption flaws in the SIP/SDP packet handling functionality. An attacker can exploit this…
Mivoice 5330e Firmware
after 6.5.0.16
MEDIUM 6.1
CVE-2018-12901
A vulnerability in the conferencing component of Mitel ST 14.2, versions GA29 (19.49.9400.0) and earlier, could allow an unauthenticated attacker to …
St Firmware
19.49.9400.0+
MEDIUM 6.1
CVE-2018-16226
A vulnerability in the web admin component of Mitel MiVoice Office 400, versions R5.0 HF3 (v8839a1) and earlier, could allow an unauthenticated attac…
Mivoice Office 400
Mitigation only
HIGH 7.5
CVE-2016-6562
On iOS and Android devices, the ShoreTel Mobility Client app version 9.1.3.109 fails to properly validate SSL certificates provided by HTTPS connecti…
Shortel Mobility Client
Mitigation only
MEDIUM 6.5
CVE-2018-9102
A vulnerability in the conferencing component of Mitel MiVoice Connect, versions R1707-PREM SP1 (21.84.5535.0) and earlier, and Mitel ST 14.2, versio…
Mivoice Connect
after 21.84.5535.0
MEDIUM 6.1
CVE-2018-9101
A vulnerability in the conferencing component of Mitel MiVoice Connect, versions R1707-PREM SP1 (21.84.5535.0) and earlier, and Mitel ST 14.2, versio…
Mivoice Connect
after 21.84.5535.0
MEDIUM 6.1
CVE-2018-9103
A vulnerability in the conferencing component of Mitel MiVoice Connect, versions R1707-PREM SP1 (21.84.5535.0) and earlier, and Mitel ST 14.2, versio…
Mivoice Connect
after 21.84.5535.0
MEDIUM 6.1
CVE-2018-9104
A vulnerability in the conferencing component of Mitel MiVoice Connect, versions R1707-PREM SP1 (21.84.5535.0) and earlier, and Mitel ST 14.2, versio…
Mivoice Connect
after 21.84.5535.0
CRITICAL 9.8
CVE-2018-5779
A vulnerability in the conferencing component of Mitel Connect ONSITE, versions R1711-PREM and earlier, and Mitel ST 14.2, release GA28 and earlier, …
Connect Onsite
Mitigation only
CRITICAL 9.8
CVE-2018-5780
A vulnerability in the conferencing component of Mitel Connect ONSITE, versions R1711-PREM and earlier, and Mitel ST 14.2, release GA28 and earlier, …
Connect Onsite
Mitigation only
CRITICAL 9.8
CVE-2018-5781
A vulnerability in the conferencing component of Mitel Connect ONSITE, versions R1711-PREM and earlier, and Mitel ST 14.2, release GA28 and earlier, …
Connect Onsite
Mitigation only
CRITICAL 9.8
CVE-2018-5782EPSS 19%
A vulnerability in the conferencing component of Mitel Connect ONSITE, versions R1711-PREM and earlier, and Mitel ST 14.2, release GA28 and earlier, …
Connect Onsite
No fix yet
HIGH 8.8
CVE-2017-16251
A vulnerability in the conferencing component of Mitel ST 14.2, release GA28 and earlier, could allow an authenticated user to upload a malicious scr…
St14.2
Mitigation only
MEDIUM 5.3
CVE-2017-16250
A vulnerability in Mitel ST 14.2, release GA28 and earlier, could allow an attacker to use the API function to enumerate through user-ids which could…
St14.2
Mitigation only
HIGH 7.8
CVE-2008-6797
The server in Mitel NuPoint Messenger R11 and R3 sends usernames and passwords in cleartext to Exchange servers, which allows remote attackers to obt…
Mitel Nupoint Messenger
Mitigation only
MEDIUM 5.0
CVE-2004-0945
The web management interface for Mitel 3300 Integrated Communications Platform (ICP) before 4.2.2.11 allows remote authenticated users to cause a den…
Mitel 3300 Integrated Communication Platform
Mitigation only