Vulnerability index

Browse CVEs

55 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

CRITICAL 9.8 CVE-2026-46376 FreePBX is an open source IP PBX. From 15.0.42 to before 16.0.45 and 17.0.7, unauthenticated users may be able to access the User Control Panel (UCP)… Freepbx 16.0.45 / 17.0.7+ Fix from $2,3002026-05-29 HIGH 8.8 CVE-2026-44238 FreePBX is an open source IP PBX. Prior to 16.0.50 and 17.0.11, the CDR Reports module page allows SQL injection through the order and sort POST para… Freepbx 16.0.50 / 17.0.11+ Fix from $1,9502026-05-29 HIGH 8.8 CVE-2026-44239 FreePBX is an open source IP PBX. Prior to 16.0.22 and 17.0.5, the Dashboard module's getcontent AJAX handler includes PHP files based on user-suppli… Freepbx 16.0.22 / 17.0.5+ Fix from $1,9502026-05-29 HIGH 8.1 CVE-2026-44237 FreePBX is an open source IP PBX. Prior to 17.0.8, the FreePBX api module's OAuth2 implementation does not sufficiently validate client credentials d… Freepbx 17.0.8+ Fix from $1,9502026-05-29 HIGH 8.8 CVE-2026-28287EPSS 8% FreePBX is an open source IP PBX. From versions 16.0.17.2 to before 16.0.20 and from version 17.0.2.4 to before 17.0.5, multiple command injection vu… Freepbx 16.0.20 / 17.0.5+ Fix from $1,9502026-03-05 HIGH 8.8 CVE-2026-28210 FreePBX is an open source IP PBX. Prior to versions 16.0.49 and 17.0.7, FreePBX module cdr (Call Data Record) is vulnerable to SQL query injection. T… Freepbx 16.0.49 / 17.0.7+ Fix from $1,9502026-03-05 HIGH 8.8 CVE-2026-28284 FreePBX is an open source IP PBX. Prior to versions 16.0.10 and 17.0.5, the FreePBX logfiles module contains several authenticated SQL injection vuln… Freepbx 16.0.10 / 17.0.5+ Fix from $1,9502026-03-05 HIGH 7.2 CVE-2026-28209 FreePBX is an open source IP PBX. From versions 16.0.17.2 to before 16.0.20 and from version 17.0.2.4 to before 17.0.5, a command injection vulnerabi… Freepbx 16.0.20 / 17.0.5+ Fix from $1,9502026-03-05 HIGH 7.5 CVE-2025-55210 FreePBX is an open-source web-based graphical user interface (GUI) that manages Asterisk. Prior to 17.0.5 and 16.0.17, FreePBX module api (PBX API) i… Freepbx 16.0.17 / 17.0.5+ Fix from $1,9502026-02-12 HIGH 8.8 CVE-2026-23741 Asterisk is an open source private branch exchange and telephony toolkit. Prior to versions 20.7-cert9, 20.18.2, 21.12.1, 22.8.2, and 23.2.2, the ast… Asterisk 20.18.2 / 21.12.1+ Fix from $1,9502026-02-06 HIGH 7.8 CVE-2026-23740 Asterisk is an open source private branch exchange and telephony toolkit. Prior to versions 20.7-cert9, 20.18.2, 21.12.1, 22.8.2, and 23.2.2, when as… Certified Asterisk 20.18.2 / 21.12.1+ Fix from $1,9502026-02-06 MEDIUM 6.5 CVE-2026-23739 Asterisk is an open source private branch exchange and telephony toolkit. Prior to versions 20.7-cert9, 20.18.2, 21.12.1, 22.8.2, and 23.2.2, the ast… Asterisk 20.18.2 / 21.12.1+ Fix from $1,6002026-02-06 MEDIUM 6.1 CVE-2026-23738 Asterisk is an open source private branch exchange and telephony toolkit. Prior to versions 20.7-cert9, 20.18.2, 21.12.1, 22.8.2, and 23.2.2, user su… Asterisk 23.2.2+ Fix from $1,6002026-02-06 HIGH 7.8 CVE-2025-67722 FreePBX is an open-source web-based graphical user interface (GUI) that manages Asterisk. Prior to versions 16.0.45 and 17.0.24 of the FreePBX framew… Freepbx 16.0.45 / 17.0.24+ Fix from $1,9502025-12-16 HIGH 7.2 CVE-2025-67736EPSS 6% The FreePBX module tts (Text to Speech) for FreePBX, an open-source web-based graphical user interface (GUI) that manages Asterisk. Versions prior to… Freepbx 16.0.5 / 17.0.5+ Fix from $1,9502025-12-16 HIGH 8.8 CVE-2024-58294 FreePBX 16 contains an authenticated remote code execution vulnerability in the API module that allows attackers with valid session credentials to ex… Freepbx No fix yet Fix from $1,9502025-12-11 CRITICAL 9.8 CVE-2025-66039 FreePBX Endpoint Manager is a module for managing telephony endpoints in FreePBX systems. Versions are vulnerable to authentication bypass when the a… Freepbx 16.0.44 / 17.0.23+ Fix from $2,3002025-12-09 HIGH 7.2 CVE-2025-64328 KEVEPSS 85% FreePBX Endpoint Manager is a module for managing telephony endpoints in FreePBX systems. In versions 17.0.2.36 and above before 17.0.3, the filestor… Filestore 17.0.3+ Fix from $1,9502025-11-07 MEDIUM 5.4 CVE-2025-59429 FreePBX is an open source GUI for managing Asterisk. In versions prior to 16.0.68.39 for FreePBX 16 and versions prior to 17.0.18.38 for FreePBX 17, … Freepbx 16.0.68.39 / 17.0.18.38+ Fix from $1,6002025-10-14 HIGH 7.8 CVE-2025-1131 A local privilege escalation vulnerability exists in the safe_asterisk script included with the Asterisk toolkit package. When Asterisk is started vi… Asterisk 18.26.3 / 20.15.1+ Fix from $1,9502025-09-23 HIGH 8.8 CVE-2025-55211 FreePBX is an open-source web-based graphical user interface. From 17.0.19.11 to before 17.0.21, authenticated users of the Administrator Control Pan… Freepbx 17.0.21+ Fix from $1,9502025-09-15 HIGH 7.5 CVE-2025-59056 FreePBX is an open-source web-based graphical user interface. In FreePBX 15, 16, and 17, malicious connections to the Administrator Control Panel web… Freepbx 15.0.38 / 16.0.41+ Fix from $1,9502025-09-15 CRITICAL 9.8 CVE-2025-57819 KEVEPSS 88% FreePBX is an open-source web-based graphical user interface. FreePBX 15, 16, and 17 endpoints are vulnerable due to insufficiently sanitized user-su… Freepbx 15.0.66 / 16.0.89+ Fix from $2,3002025-08-28 HIGH 7.5 CVE-2025-57767 Asterisk is an open source private branch exchange and telephony toolkit. Prior to versions 20.15.2, 21.10.2, and 22.5.2, if a SIP request is receive… Asterisk 20.15.2 / 21.10.2+ Fix from $1,9502025-08-28 MEDIUM 6.5 CVE-2025-54995 Asterisk is an open source private branch exchange and telephony toolkit. Prior to versions 18.26.4 and 18.9-cert17, RTP UDP ports and internal resou… Asterisk 18.9 / 18.26.4+ Fix from $1,6002025-08-28 MEDIUM 6.5 CVE-2025-49832 Asterisk is an open source private branch exchange and telephony toolkit. In versions up to and including 18.26.2, between 20.00.0 and 20.15.0, 20.7-… Asterisk 18.26.3 / 20.15.1+ Fix from $1,6002025-08-01 CRITICAL 9.8 CVE-2025-32105 A buffer overflow in the the Sangoma IMG2020 HTTP server through 2.3.9.6 allows an unauthenticated user to achieve remote code execution. Img2020 Firmware after 2.3.9.6 Fix from $2,3002025-06-03 HIGH 7.8 CVE-2025-47780 Asterisk is an open-source private branch exchange (PBX). Prior to versions 18.26.2, 20.14.1, 21.9.1, and 22.4.1 of Asterisk and versions 18.9-cert14… Asterisk 18.9 / 18.26.2+ Fix from $1,9502025-05-22 MEDIUM 6.5 CVE-2025-47779 Asterisk is an open-source private branch exchange (PBX). Prior to versions 18.26.2, 20.14.1, 21.9.1, and 22.4.1 of Asterisk and versions 18.9-cert14… Asterisk 18.9 / 18.26.2+ Fix from $1,6002025-05-22 CRITICAL 9.8 CVE-2024-57520 Insecure Permissions vulnerability in asterisk v22 allows a remote attacker to execute arbitrary code via the action_createconfig function. NOTE: thi… Asterisk after 22.5.1 Fix from $2,3002025-02-05