CVEs (238)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Cisco 1Unified Communications Manager Apr 29, 2026 Feb 13, 2014 N/A· v4 N/A· v3 7.5 HIGH· v2 SQL injection vulnerability in the Java database interface in Cisco Unified Communications Manager (UCM) 10.0(1) and earlier allows remote attackers to execute arbitrary SQL commands via a crafted URL, aka Bug ID CSCum05...Show more |
1Cisco 1Unified Communications Manager Apr 29, 2026 Feb 13, 2014 N/A· v4 N/A· v3 7.5 HIGH· v2 SQL injection vulnerability in the CallManager Interactive Voice Response (CMIVR) interface in Cisco Unified Communications Manager (UCM) allows remote attackers to execute arbitrary SQL commands via a crafted URL, aka B...Show more |
1Cisco 1Unified Communications Manager Apr 29, 2026 Feb 13, 2014 N/A· v4 N/A· v3 7.5 HIGH· v2 SQL injection vulnerability in the IP Manager Assistant (IPMA) interface in Cisco Unified Communications Manager (UCM) 10.0(1) and earlier allows remote attackers to execute arbitrary SQL commands via a crafted URL, aka...Show more |
1Cisco 1Unified Communications Manager Apr 29, 2026 Feb 13, 2014 N/A· v4 N/A· v3 5.0 MEDIUM· v2 Cisco Unified Communications Manager (UCM) does not require authentication for reading WAR files, which allows remote attackers to obtain sensitive information via unspecified access to a "file storage location," aka Bug...Show more |
1Cisco 1Unified Communications Manager Apr 29, 2026 Feb 13, 2014 N/A· v4 N/A· v3 4.0 MEDIUM· v2 The bulk administration interface in Cisco Unified Communications Manager (UCM) 10.0(1) and earlier allows remote attackers to bypass authentication and read arbitrary files by using an unspecified prompt, aka Bug ID CSC...Show more |
1Cisco 1Unified Communications Manager Apr 29, 2026 Feb 13, 2014 N/A· v4 N/A· v3 4.3 MEDIUM· v2 Cross-site scripting (XSS) vulnerability in the IP Manager Assistant (IPMA) interface in Cisco Unified Communications Manager (UCM) allows remote attackers to inject arbitrary web script or HTML via a crafted URL, aka Bu...Show more |
1Cisco 1Unified Communications Manager Apr 29, 2026 Feb 13, 2014 N/A· v4 N/A· v3 5.0 MEDIUM· v2 The log4jinit web application in Cisco Unified Communications Manager (UCM) does not properly validate authentication, which allows remote attackers to cause a denial of service (performance degradation) via unspecified...Show more |
1Cisco 1Unified Communications Manager Apr 29, 2026 Feb 4, 2014 N/A· v4 N/A· v3 6.0 MEDIUM· v2 Cisco Unified Communications Manager (aka Unified CM) 9.1 (2.10000.28) and earlier allows local users to gain privileges by leveraging incorrect file permissions, aka Bug IDs CSCul24917 and CSCul24908. |
1Cisco 1Unified Communications Manager Apr 29, 2026 Jan 8, 2014 N/A· v4 N/A· v3 4.0 MEDIUM· v2 The administration portal in Cisco Unified Communications Manager (Unified CM) 9.1(1) and earlier does not properly handle role restrictions, which allows remote authenticated users to bypass role-based access control vi...Show more |
1Cisco 1Unified Communications Manager Apr 29, 2026 Dec 21, 2013 N/A· v4 N/A· v3 4.0 MEDIUM· v2 The disaster recovery system (DRS) component in Cisco Unified Communications Manager (UCM) 9.1(1) and earlier allows remote authenticated users to obtain sensitive device information by reading "extraneous information" i...Show more |
1Cisco 1Unified Communications Manager Apr 29, 2026 Dec 12, 2013 N/A· v4 7.3 HIGH· v3 5.0 MEDIUM· v2 The TFTP service in Cisco Unified Communications Manager (aka CUCM or Unified CM) allows remote attackers to obtain sensitive information from a phone via an RRQ operation, as demonstrated by discovering a cleartext UseU...Show more |
1Cisco 1Unified Communications Manager Apr 29, 2026 Nov 18, 2013 N/A· v4 N/A· v3 6.9 MEDIUM· v2 Cisco Unified Communications Manager (Unified CM) 9.1(1) and earlier allows local users to bypass file permissions, and read, modify, or create arbitrary files, via an "overload" of the command-line utility, aka Bug ID C...Show more |
1Cisco 1Unified Communications Manager Apr 29, 2026 Nov 18, 2013 N/A· v4 N/A· v3 6.3 MEDIUM· v2 Directory traversal vulnerability in the license-upload interface in the Enterprise License Manager (ELM) component in Cisco Unified Communications Manager 9.1(1) and earlier allows remote authenticated users to create a...Show more |
1Cisco 1Unified Communications Manager Apr 29, 2026 Nov 1, 2013 N/A· v4 N/A· v3 4.3 MEDIUM· v2 Cisco Unified Communications Manager (aka CUCM or Unified CM) allows remote attackers to cause a denial of service (service restart) via a crafted SIP message, aka Bug ID CSCub54349. |
1Cisco 1Unified Communications Manager Apr 29, 2026 Oct 11, 2013 N/A· v4 N/A· v3 4.0 MEDIUM· v2 Directory traversal vulnerability in the Tomcat administrative web interface in Cisco Unified Communications Manager allows remote authenticated users to read arbitrary files via directory traversal sequences in an unspe...Show more |
1Cisco 1Unified Communications Manager Apr 29, 2026 Aug 29, 2013 N/A· v4 N/A· v3 6.8 MEDIUM· v2 Cross-site request forgery (CSRF) vulnerability in the Enterprise License Manager (ELM) in Cisco Unified Communications Manager (CM) allows remote attackers to hijack the authentication of arbitrary users for requests th...Show more |
1Cisco 1Unified Communications Manager Apr 29, 2026 Aug 25, 2013 N/A· v4 N/A· v3 8.5 HIGH· v2 Buffer overflow in Cisco Unified Communications Manager (Unified CM) 7.1(x) before 7.1(5b)su6, 8.5(x) before 8.5(1)su6, 8.6(x) before 8.6(2a)su3, and 9.x before 9.1(2) allows remote authenticated users to execute arbitra...Show more |
1Cisco 1Unified Communications Manager Apr 29, 2026 Aug 25, 2013 N/A· v4 N/A· v3 7.1 HIGH· v2 Cisco Unified Communications Manager (Unified CM) 8.5(x) and 8.6(x) before 8.6(2a)su3 and 9.x before 9.1(1) does not properly restrict the rate of SIP packets, which allows remote attackers to cause a denial of service (...Show more |
1Cisco 1Unified Communications Manager Apr 29, 2026 Aug 25, 2013 N/A· v4 N/A· v3 7.8 HIGH· v2 Memory leak in Cisco Unified Communications Manager (Unified CM) 8.5(x) before 8.5(1)su6, 8.6(x) before 8.6(2a)su3, and 9.x before 9.1(1) allows remote attackers to cause a denial of service (service disruption) via a hi...Show more |
1Cisco 1Unified Communications Manager Apr 29, 2026 Aug 25, 2013 N/A· v4 N/A· v3 7.8 HIGH· v2 Cisco Unified Communications Manager (Unified CM) 7.1(x) before 7.1(5b)su6a does not properly handle errors, which allows remote attackers to cause a denial of service (service disruption) via malformed registration mess...Show more |