Vulnerability index

Browse CVEs

11 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

HIGH 8.8 CVE-2024-58294 FreePBX 16 contains an authenticated remote code execution vulnerability in the API module that allows attackers with valid session credentials to ex… Freepbx No fix yet Fix from $1,9502025-12-11 HIGH 7.2 CVE-2024-53564 A vulnerability was discovered in FreePBX 17.0.19.17. It does not verify the type of uploaded (valid FreePBX module) files, allowing high-privilege a… Freepbx Mitigation only Fix from $1,9502024-12-02 HIGH 8.1 CVE-2023-26567 Sangoma FreePBX 1805 through 2302 (when obtained as a ,.ISO file) places AMPDBUSER, AMPDBPASS, AMPMGRUSER, and AMPMGRPASS in the list of global varia… Freepbx Linux 7 Mitigation only Fix from $1,9502023-04-26 MEDIUM 5.3 CVE-2021-45310 Sangoma Technologies Corporation Switchvox Version 102409 is affected by an information disclosure vulnerability due to an improper access restrictio… Switchvox No fix yet Fix from $1,6002022-02-14 CRITICAL 9.8 CVE-2021-45461EPSS 20% FreePBX, when restapps (aka Rest Phone Apps) 15.0.19.87, 15.0.19.88, 16.0.18.40, or 16.0.18.41 is installed, allows remote attackers to execute arbit… Restapps No fix yet Fix from $2,3002021-12-22 CRITICAL 9.8 CVE-2019-12147 The Sangoma Session Border Controller (SBC) 2.3.23-119 GA web interface is vulnerable to Argument Injection via special characters in the username fi… Session Border Controller Firmware No fix yet Fix from $2,3002019-10-22 CRITICAL 9.8 CVE-2019-12148 The Sangoma Session Border Controller (SBC) 2.3.23-119 GA web interface is vulnerable to an authentication bypass via an argument injection vulnerabi… Session Border Controller Firmware No fix yet Fix from $2,3002019-10-22 HIGH 7.2 CVE-2018-6393 FreePBX 10.13.66-32bit and 14.0.1.24 (SNG7-PBX-64bit-1712-2) allow post-authentication SQL injection via the order parameter. NOTE: the vendor disput… Freepbx No fix yet Fix from $1,9502018-01-29 CRITICAL 9.8 CVE-2017-17430 Sangoma NetBorder / Vega Session Controller before 2.3.12-80-GA allows remote attackers to execute arbitrary commands via the web interface. Netborder\/vega Session Firmware Mitigation only Fix from $2,3002017-12-07 HIGH 7.5 CVE-2017-9358 A memory exhaustion vulnerability exists in Asterisk Open Source 13.x before 13.15.1 and 14.x before 14.4.1 and Certified Asterisk 13.13 before 13.13… Asterisk Mitigation only Fix from $1,9502017-06-02 HIGH 10.0 CVE-2008-6598 Multiple race conditions in WANPIPE before 3.3.6 have unknown impact and attack vectors related to "bri restart logic." Wanpipe No fix yet Fix from $1,9502009-04-03