Mitel
mitel
134 CVEs • 128 products
Products (128)
Click to collapseToggle
Products (128)
Click to collapse
CVEs (134)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
The AWV portal of Mitel MiCollab before 9.2 could allow an attacker to gain access to conference information by sending arbitrary code due to improper input validation, aka XSS. Successful exploitation could allow an att...Show more |
The AWV component of Mitel MiCollab before 9.2 could allow an attacker to gain access to a web conference due to insufficient access control for conference codes. |
The NuPoint Messenger Portal of Mitel MiCollab before 9.2 could allow an authenticated attacker to execute arbitrary scripts due to insufficient input validation, aka XSS. A successful exploit could allow an attacker to...Show more |
The SAS portal of Mitel MiCollab before 9.2 could allow an attacker to access user credentials due to improper input validation, aka SQL Injection. |
The AWV component of Mitel MiCollab before 9.2 could allow an attacker to view system information by sending arbitrary code due to improper input validation, aka XSS. |
The Ignite portal in Mitel MiContact Center Business before 9.3.0.0 could allow a local attacker to view system information due to insufficient output sanitization. |
The conferencing component on Mitel ShoreTel 19.46.1802.0 devices could allow an unauthenticated attacker to conduct a reflected cross-site scripting (XSS) attack (via the PATH_INFO to index.php) due to insufficient vali...Show more |
1Mitel 1Micontact Center Business Jun 17, 2026 Sep 25, 2020 N/A· v4 7.1 HIGH· v3 3.6 LOW· v2 The Ignite portal in Mitel MiContact Center Business before 9.3.0.0 could allow an attacker to execute arbitrary scripts due to insufficient input validation, aka XSS. A successful exploit could allow an attacker to gain...Show more |
1Mitel 1Micloud Management Portal Jun 17, 2026 Sep 25, 2020 N/A· v4 5.3 MEDIUM· v3 5.0 MEDIUM· v2 Mitel MiCloud Management Portal before 6.1 SP5 could allow an attacker, by sending a crafted request, to retrieve sensitive information due to insufficient access control. |
1Mitel 1Micloud Management Portal Jun 17, 2026 Sep 25, 2020 N/A· v4 9.6 CRITICAL· v3 6.8 MEDIUM· v2 Mitel MiCloud Management Portal before 6.1 SP5 could allow an unauthenticated attacker to execute arbitrary scripts due to insufficient input validation, aka XSS. A successful exploit could allow an attacker to gain acce...Show more |
1Mitel 1Micloud Management Portal Jun 17, 2026 Sep 25, 2020 N/A· v4 7.2 HIGH· v3 6.5 MEDIUM· v2 Mitel MiCloud Management Portal before 6.1 SP5 could allow a remote attacker to conduct a SQL Injection attack and access user credentials due to improper input validation. |
1Mitel 1Micloud Management Portal Jun 17, 2026 Sep 25, 2020 N/A· v4 5.3 MEDIUM· v3 5.0 MEDIUM· v2 Mitel MiCloud Management Portal before 6.1 SP5 could allow an attacker, by sending a crafted request, to view system information due to insufficient output sanitization. |
1Mitel 1Mivoice Connect Client Jun 17, 2026 Aug 26, 2020 N/A· v4 8.8 HIGH· v3 6.5 MEDIUM· v2 A remote code execution vulnerability in Mitel MiVoice Connect Client before 214.100.1223.0 could allow an attacker to execute arbitrary code in the chat notification window, due to improper rendering of chat messages. A...Show more |
1Mitel 1Micollab Audio, Web & Video Conferencing Jun 17, 2026 Aug 26, 2020 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 An Authentication Bypass vulnerability in the Published Area of the web conferencing component of Mitel MiCollab AWV before 8.1.2.4 and 9.x before 9.1.3 could allow an unauthenticated attacker to gain access to unauthori...Show more |
The SAS portal of Mitel MiCollab before 9.1.3 could allow an attacker to access user data by performing a header injection in HTTP responses, due to the improper handling of input parameters. A successful exploit could a...Show more |
The Mitel MiCollab application before 9.1.332 for iOS could allow an unauthorized user to access restricted files and folders due to insufficient access control. An exploit requires a rooted iOS device, and (if successfu...Show more |
1Mitel 116863 Firmware 6865 Firmware6867 Firmware+8 moreJun 17, 2026 Aug 26, 2020 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 The Web UI component of Mitel MiVoice 6800 and 6900 series SIP Phones with firmware before 5.1.0.SP5 could allow an unauthenticated attacker to expose sensitive information due to improper memory handling during failed l...Show more |
1Mitel 1Micollab Audio, Web & Video Conferencing Jun 17, 2026 Jun 10, 2020 N/A· v4 5.3 MEDIUM· v3 5.0 MEDIUM· v2 A Directory Traversal vulnerability in the web conference component of Mitel MiCollab AWV before 8.1.2.4 and 9.x before 9.1.3 could allow an attacker to access arbitrary files from restricted directories of the server vi...Show more |
1Mitel 2Mivoice Connect Shoretel Conference WebJun 17, 2026 May 7, 2020 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 A reflected cross-site scripting (XSS) vulnerability in the Mitel ShoreTel Conference Web Application 19.50.1000.0 before MiVoice Connect 18.7 SP2 allows remote attackers to inject arbitrary JavaScript and HTML via the P...Show more |
1Mitel 1Mivoice Connect Client Jun 17, 2026 Apr 17, 2020 N/A· v4 9.8 CRITICAL· v3 5.0 MEDIUM· v2 A weak encryption vulnerability in Mitel MiVoice Connect Client before 214.100.1214.0 could allow an unauthenticated attacker to gain access to user credentials. A successful exploit could allow an attacker to access the...Show more |