Loading HuntDB...

avaya

35 Products 44 CVEs

CVE Severity Distribution (All Time)

Critical
5
High
17
Medium
22
Low
0

Timeline Overview

Last 30 Days 0 CVEs
Last 6 Months 0 CVEs
Last Year 0 CVEs

Recent CVEs

View all
CVE-2024-7480 MEDIUM 1 year, 3 months ago

An Improper access control vulnerability was found in Avaya Aura System Manager which could allow a command-line interface (CLI) user with administra…

CVE-2024-7477 MEDIUM 1 year, 3 months ago

A SQL injection vulnerability was found which could allow a command line interface (CLI) user with administrative privileges to execute arbitrary que…

CVE-2024-4197 CRITICAL 1 year, 5 months ago

An unrestricted file upload vulnerability in Avaya IP Office was discovered that could allow remote command or code execution via the One-X component…

CVE-2024-4196 CRITICAL 1 year, 5 months ago

An improper input validation vulnerability was discovered in Avaya IP Office that could allow remote command or code execution via a specially craft…

CVE-2023-7031 MEDIUM 1 year, 10 months ago

Insecure Direct Object Reference vulnerabilities were discovered in the Avaya Aura Experience Portal Manager which may allow partial information disc…

CVE-2023-3722 HIGH 2 years, 4 months ago

An OS command injection vulnerability was found in the Avaya Aura Device Services Web application which could allow remote code execution as the Web …

CVE-2023-3527 MEDIUM 2 years, 4 months ago

A CSV injection vulnerability was found in the Avaya Call Management System (CMS) Supervisor web application which allows a user with administrative …

CVE-2023-32218 MEDIUM 2 years, 5 months ago

Avaya IX Workforce Engagement v15.2.7.1195 - CWE-601: URL Redirection to Untrusted Site ('Open Redirect')

CVE-2023-31187 MEDIUM 2 years, 5 months ago

Avaya IX Workforce Engagement v15.2.7.1195 - CWE-522: Insufficiently Protected Credentials

CVE-2023-31186 MEDIUM 2 years, 5 months ago

Avaya IX Workforce Engagement v15.2.7.1195 - User Enumeration - Observable Response Discrepancy