Vulnerability index

Browse CVEs

55 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Freepbx CRITICAL 9.8
CVE-2026-46376

FreePBX is an open source IP PBX. From 15.0.42 to before 16.0.45 and 17.0.7, unauthenticated users may be able to access the User Control Panel (UCP)…

Fix: 16.0.45 / 17.0.7+
Fix from $2,300 2026-05-29
Freepbx HIGH 8.8
CVE-2026-44238

FreePBX is an open source IP PBX. Prior to 16.0.50 and 17.0.11, the CDR Reports module page allows SQL injection through the order and sort POST para…

Fix: 16.0.50 / 17.0.11+
Fix from $1,950 2026-05-29
Freepbx HIGH 8.8
CVE-2026-44239

FreePBX is an open source IP PBX. Prior to 16.0.22 and 17.0.5, the Dashboard module's getcontent AJAX handler includes PHP files based on user-suppli…

Fix: 16.0.22 / 17.0.5+
Fix from $1,950 2026-05-29
Freepbx HIGH 8.1
CVE-2026-44237

FreePBX is an open source IP PBX. Prior to 17.0.8, the FreePBX api module's OAuth2 implementation does not sufficiently validate client credentials d…

Fix: 17.0.8+
Fix from $1,950 2026-05-29
Freepbx HIGH 8.8
CVE-2026-28287EPSS 8%

FreePBX is an open source IP PBX. From versions 16.0.17.2 to before 16.0.20 and from version 17.0.2.4 to before 17.0.5, multiple command injection vu…

Fix: 16.0.20 / 17.0.5+
Fix from $1,950 2026-03-05
Freepbx HIGH 8.8
CVE-2026-28210

FreePBX is an open source IP PBX. Prior to versions 16.0.49 and 17.0.7, FreePBX module cdr (Call Data Record) is vulnerable to SQL query injection. T…

Fix: 16.0.49 / 17.0.7+
Fix from $1,950 2026-03-05
Freepbx HIGH 8.8
CVE-2026-28284

FreePBX is an open source IP PBX. Prior to versions 16.0.10 and 17.0.5, the FreePBX logfiles module contains several authenticated SQL injection vuln…

Fix: 16.0.10 / 17.0.5+
Fix from $1,950 2026-03-05
Freepbx HIGH 7.2
CVE-2026-28209

FreePBX is an open source IP PBX. From versions 16.0.17.2 to before 16.0.20 and from version 17.0.2.4 to before 17.0.5, a command injection vulnerabi…

Fix: 16.0.20 / 17.0.5+
Fix from $1,950 2026-03-05
Freepbx HIGH 7.5
CVE-2025-55210

FreePBX is an open-source web-based graphical user interface (GUI) that manages Asterisk. Prior to 17.0.5 and 16.0.17, FreePBX module api (PBX API) i…

Fix: 16.0.17 / 17.0.5+
Fix from $1,950 2026-02-12
Asterisk HIGH 8.8
CVE-2026-23741

Asterisk is an open source private branch exchange and telephony toolkit. Prior to versions 20.7-cert9, 20.18.2, 21.12.1, 22.8.2, and 23.2.2, the ast…

Fix: 20.18.2 / 21.12.1+
Fix from $1,950 2026-02-06
Certified Asterisk HIGH 7.8
CVE-2026-23740

Asterisk is an open source private branch exchange and telephony toolkit. Prior to versions 20.7-cert9, 20.18.2, 21.12.1, 22.8.2, and 23.2.2, when as…

Fix: 20.18.2 / 21.12.1+
Fix from $1,950 2026-02-06
Asterisk MEDIUM 6.5
CVE-2026-23739

Asterisk is an open source private branch exchange and telephony toolkit. Prior to versions 20.7-cert9, 20.18.2, 21.12.1, 22.8.2, and 23.2.2, the ast…

Fix: 20.18.2 / 21.12.1+
Fix from $1,600 2026-02-06
Asterisk MEDIUM 6.1
CVE-2026-23738

Asterisk is an open source private branch exchange and telephony toolkit. Prior to versions 20.7-cert9, 20.18.2, 21.12.1, 22.8.2, and 23.2.2, user su…

Fix: 23.2.2+
Fix from $1,600 2026-02-06
Freepbx HIGH 7.8
CVE-2025-67722

FreePBX is an open-source web-based graphical user interface (GUI) that manages Asterisk. Prior to versions 16.0.45 and 17.0.24 of the FreePBX framew…

Fix: 16.0.45 / 17.0.24+
Fix from $1,950 2025-12-16
Freepbx HIGH 7.2
CVE-2025-67736EPSS 6%

The FreePBX module tts (Text to Speech) for FreePBX, an open-source web-based graphical user interface (GUI) that manages Asterisk. Versions prior to…

Fix: 16.0.5 / 17.0.5+
Fix from $1,950 2025-12-16
Freepbx HIGH 8.8
CVE-2024-58294

FreePBX 16 contains an authenticated remote code execution vulnerability in the API module that allows attackers with valid session credentials to ex…

No fix yet
Fix from $1,950 2025-12-11
Freepbx CRITICAL 9.8
CVE-2025-66039

FreePBX Endpoint Manager is a module for managing telephony endpoints in FreePBX systems. Versions are vulnerable to authentication bypass when the a…

Fix: 16.0.44 / 17.0.23+
Fix from $2,300 2025-12-09
Filestore HIGH 7.2
CVE-2025-64328 KEVEPSS 85%

FreePBX Endpoint Manager is a module for managing telephony endpoints in FreePBX systems. In versions 17.0.2.36 and above before 17.0.3, the filestor…

Fix: 17.0.3+
Fix from $1,950 2025-11-07
Freepbx MEDIUM 5.4
CVE-2025-59429

FreePBX is an open source GUI for managing Asterisk. In versions prior to 16.0.68.39 for FreePBX 16 and versions prior to 17.0.18.38 for FreePBX 17, …

Fix: 16.0.68.39 / 17.0.18.38+
Fix from $1,600 2025-10-14
Asterisk HIGH 7.8
CVE-2025-1131

A local privilege escalation vulnerability exists in the safe_asterisk script included with the Asterisk toolkit package. When Asterisk is started vi…

Fix: 18.26.3 / 20.15.1+
Fix from $1,950 2025-09-23
Freepbx HIGH 8.8
CVE-2025-55211

FreePBX is an open-source web-based graphical user interface. From 17.0.19.11 to before 17.0.21, authenticated users of the Administrator Control Pan…

Fix: 17.0.21+
Fix from $1,950 2025-09-15
Freepbx HIGH 7.5
CVE-2025-59056

FreePBX is an open-source web-based graphical user interface. In FreePBX 15, 16, and 17, malicious connections to the Administrator Control Panel web…

Fix: 15.0.38 / 16.0.41+
Fix from $1,950 2025-09-15
Freepbx CRITICAL 9.8
CVE-2025-57819 KEVEPSS 88%

FreePBX is an open-source web-based graphical user interface. FreePBX 15, 16, and 17 endpoints are vulnerable due to insufficiently sanitized user-su…

Fix: 15.0.66 / 16.0.89+
Fix from $2,300 2025-08-28
Asterisk HIGH 7.5
CVE-2025-57767

Asterisk is an open source private branch exchange and telephony toolkit. Prior to versions 20.15.2, 21.10.2, and 22.5.2, if a SIP request is receive…

Fix: 20.15.2 / 21.10.2+
Fix from $1,950 2025-08-28
Asterisk MEDIUM 6.5
CVE-2025-54995

Asterisk is an open source private branch exchange and telephony toolkit. Prior to versions 18.26.4 and 18.9-cert17, RTP UDP ports and internal resou…

Fix: 18.9 / 18.26.4+
Fix from $1,600 2025-08-28
Asterisk MEDIUM 6.5
CVE-2025-49832

Asterisk is an open source private branch exchange and telephony toolkit. In versions up to and including 18.26.2, between 20.00.0 and 20.15.0, 20.7-…

Fix: 18.26.3 / 20.15.1+
Fix from $1,600 2025-08-01
Img2020 Firmware CRITICAL 9.8
CVE-2025-32105

A buffer overflow in the the Sangoma IMG2020 HTTP server through 2.3.9.6 allows an unauthenticated user to achieve remote code execution.

Fix: after 2.3.9.6
Fix from $2,300 2025-06-03
Asterisk HIGH 7.8
CVE-2025-47780

Asterisk is an open-source private branch exchange (PBX). Prior to versions 18.26.2, 20.14.1, 21.9.1, and 22.4.1 of Asterisk and versions 18.9-cert14…

Fix: 18.9 / 18.26.2+
Fix from $1,950 2025-05-22
Asterisk MEDIUM 6.5
CVE-2025-47779

Asterisk is an open-source private branch exchange (PBX). Prior to versions 18.26.2, 20.14.1, 21.9.1, and 22.4.1 of Asterisk and versions 18.9-cert14…

Fix: 18.9 / 18.26.2+
Fix from $1,600 2025-05-22
Asterisk CRITICAL 9.8
CVE-2024-57520

Insecure Permissions vulnerability in asterisk v22 allows a remote attacker to execute arbitrary code via the action_createconfig function. NOTE: thi…

Fix: after 22.5.1
Fix from $2,300 2025-02-05