Vulnerability index

Browse CVEs

100 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Media Server MEDIUM 6.5
CVE-2025-49186

The product does not implement sufficient measures to prevent multiple failed authentication attempts within a short time frame, making it susceptibl…

Mitigation only
Fix from $1,600 2025-06-12
Call Management System CRITICAL 9.8
CVE-2025-1041

An improper input validation discovered in Avaya Call Management System could allow an unauthorized remote command via a specially crafted web re…

Fix: 19.2.0.7 / 20.0.1.0+
Fix from $2,300 2025-06-10
Spaces MEDIUM 6.1
CVE-2024-12756

An HTML Injection vulnerability in Avaya Spaces may have allowed disclosure of sensitive information or modification of the page content seen by the …

Mitigation only
Fix from $1,600 2025-02-11
Spaces MEDIUM 5.4
CVE-2024-12755

A Cross-Site Scripting (XSS) vulnerability in Avaya Spaces may have allowed unauthorized code execution and potential disclose of sensitive informati…

Mitigation only
Fix from $1,600 2025-02-11
Aura System Manager MEDIUM 6.7
CVE-2024-7477

A SQL injection vulnerability was found which could allow a command line interface (CLI) user with administrative privileges to execute arbitrary que…

Fix: after 10.1.2
Fix from $1,600 2024-08-08
Ip Office CRITICAL 9.8
CVE-2024-4197

An unrestricted file upload vulnerability in Avaya IP Office was discovered that could allow remote command or code execution via the One-X component…

Fix: 11.1.3.1+
Fix from $2,300 2024-06-25
Ip Office CRITICAL 9.8
CVE-2024-4196

An improper input validation vulnerability was discovered in Avaya IP Office that could allow remote command or code execution via a specially craft…

Fix: 11.1.3.1+
Fix from $2,300 2024-06-25
Aura Device Services CRITICAL 9.8
CVE-2023-3722

An OS command injection vulnerability was found in the Avaya Aura Device Services Web application which could allow remote code execution as the Web …

Fix: after 8.1.4.0
Fix from $2,300 2023-07-19
Call Management System MEDIUM 6.8
CVE-2023-3527

A CSV injection vulnerability was found in the Avaya Call Management System (CMS) Supervisor web application which allows a user with administrative …

Fix: 20.0.0.0+
Fix from $1,600 2023-07-18
Ix Workforce Engagement MEDIUM 6.5
CVE-2023-31187

Avaya IX Workforce Engagement v15.2.7.1195 - CWE-522: Insufficiently Protected Credentials

No fix yet
Fix from $1,600 2023-05-30
Ix Workforce Engagement MEDIUM 6.1
CVE-2023-32218

Avaya IX Workforce Engagement v15.2.7.1195 - CWE-601: URL Redirection to Untrusted Site ('Open Redirect')

Mitigation only
Fix from $1,600 2023-05-30
Ix Workforce Engagement MEDIUM 5.3
CVE-2023-31186

Avaya IX Workforce Engagement v15.2.7.1195 - User Enumeration - Observable Response Discrepancy

Mitigation only
Fix from $1,600 2023-05-30
Scopia Pathfinder 10 Pts Firmware CRITICAL 9.1
CVE-2022-38168

Broken Access Control in User Authentication in Avaya Scopia Pathfinder 10 and 20 PTS version 8.3.7.0.4 allows remote unauthenticated attackers to by…

No fix yet
Fix from $2,300 2022-11-03
Aura Communication Manager MEDIUM 6.7
CVE-2022-2249

Privilege escalation related vulnerabilities were discovered in Avaya Aura Communication Manager that may allow local administrative users to escalat…

Fix: 8.1.3.4+
Fix from $1,600 2022-10-12
Aura Application Enablement Services MEDIUM 6.7
CVE-2022-2975

A vulnerability related to weak permissions was detected in Avaya Aura Application Enablement Services web application, allowing an administrative us…

Fix: 8.1.3.5 / 10.1.0.2+
Fix from $1,600 2022-10-06
Ip Office HIGH 7.8
CVE-2021-25657

A privilege escalation vulnerability was discovered in Avaya IP Office Admin Lite and USB Creator that may potentially allow a local user to escalate…

Fix: 11.1+
Fix from $1,950 2022-09-02
Aura Device Services HIGH 7.8
CVE-2021-25654

An arbitrary code execution vulnerability was discovered in Avaya Aura Device Services that may potentially allow a local user to execute specially c…

Fix: after 8.1.4.0
Fix from $1,950 2021-06-25
Aura Experience Portal MEDIUM 6.1
CVE-2021-25655

A vulnerability in the system Service Menu component of Avaya Aura Experience Portal may allow URL Redirection to any untrusted site through a crafte…

Fix: after 7.2.3
Fix from $1,600 2021-06-24
Aura Experience Portal MEDIUM 5.4
CVE-2021-25656

Stored XSS injection vulnerabilities were discovered in the Avaya Aura Experience Portal Web management which could allow an authenticated user to po…

Fix: after 7.2.3
Fix from $1,600 2021-06-24
Aura Utility Services HIGH 8.8
CVE-2021-25650

A privilege escalation vulnerability was discovered in Avaya Aura Utility Services that may potentially allow a local user to execute specially craft…

Fix: after 7.1.3
Fix from $1,950 2021-06-24
Aura Utility Services HIGH 7.8
CVE-2021-25651

A privilege escalation vulnerability was discovered in Avaya Aura Utility Services that may potentially allow a local user to escalate privileges. Af…

Fix: after 7.1.3
Fix from $1,950 2021-06-24
Aura Appliance Virtualization Platform HIGH 7.8
CVE-2021-25653

A privilege escalation vulnerability was discovered in Avaya Aura Appliance Virtualization Platform Utilities (AVPU) that may potentially allow a loc…

Fix: after 8.1.3.1
Fix from $1,950 2021-06-24
Aura Utility Services MEDIUM 5.5
CVE-2021-25649

An information disclosure vulnerability was discovered in the directory and file management of Avaya Aura Utility Services. This vulnerability may po…

Fix: after 7.1.3
Fix from $1,600 2021-06-24
Aura Appliance Virtualization Platform MEDIUM 5.5
CVE-2021-25652

An information disclosure vulnerability was discovered in the directory and file management of Avaya Aura Appliance Virtualization Platform Utilities…

Fix: after 8.1.3.1
Fix from $1,600 2021-06-24
Equinox Conferencing HIGH 8.1
CVE-2020-7037

An XML External Entities (XXE) vulnerability in Media Server component of Avaya Equinox Conferencing could allow an authenticated, remote attacker to…

Fix: 9.1.11+
Fix from $1,950 2021-04-28
Equinox Conferencing HIGH 7.5
CVE-2020-7038

A vulnerability was discovered in Management component of Avaya Equinox Conferencing that could potentially allow an unauthenticated, remote attacker…

Fix: 9.1.11+
Fix from $1,950 2021-04-28
Session Border Controller For Enterprise HIGH 8.8
CVE-2020-7034

A command injection vulnerability in Avaya Session Border Controller for Enterprise could allow an authenticated, remote attacker to send specially c…

Fix: 8.1.2.0+
Fix from $1,950 2021-04-23
Aura Orchestration Designer MEDIUM 6.5
CVE-2020-7035

An XML External Entities (XXE)vulnerability in the web-based user interface of Avaya Aura Orchestration Designer could allow an authenticated, remote…

Fix: after 7.2.2
Fix from $1,600 2021-04-23
Callback Assist MEDIUM 6.5
CVE-2020-7036

An XML External Entities (XXE)vulnerability in Callback Assist could allow an authenticated, remote attacker to gain read access to information that …

Fix: 4.7.1.1+
Fix from $1,600 2021-04-23
Aura System Manager MEDIUM 6.5
CVE-2020-7032

An XML external entity (XXE) vulnerability in Avaya WebLM admin interface allows authenticated users to read arbitrary files or conduct server-side r…

Fix: 8.1.3+
Fix from $1,600 2020-11-13