sangoma kayıtları
sangoma üreticisine ait 85 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 4 · %4,7
- Silahlaştırılmış
- 7 · %8,2
- Pre-auth RCE
- 11
- Düzeltme kaydı olan
- %52,9
- Yayından KEV’e ortanca
- 68 gün
Tekrar eden sınıflar
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')15
- CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')8
- CWE-78 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')6
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')5
- CWE-427 Uncontrolled Search Path Element3
- CWE-287 Improper Authentication3
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWETüm kayıtlar
85 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
96Hemen | CVE-2025-57819Silahlaştırılmış | FreePBX Affected by Authentication Bypass Leading to SQL Injection and RCEsangoma · freepbx · CWE-89 | Kritik10,0 | KEV | %85,5 | 28 Ağu 2025 |
89Hemen | CVE-2025-64328Silahlaştırılmış | FreePBX Administration GUI is Vulnerable to Authenticated Command Injectionsangoma · filestore · CWE-78 | Yüksek8,6 | KEV | %84,6 | 7 Kas 2025 |
86Hemen | CVE-2019-19006Silahlaştırılmış | Sangoma FreePBX 115.0.16.26 and below, 14.0.13.11 and below, 13.0.197.13 and below have Incorrect Access Control.sangoma · freepbx · CWE-287 | Kritik9,8 | KEV | %55,9 | 21 Kas 2019 |
73Bu hafta | CVE-2026-9586Silahlaştırılmış | Unauthenticated SQL Injection Leading to Remote Code Execution in Switchvox SMBsangoma · switchvox · CWE-89 | Kritik9,3 | KEV | %19,0 | 17 Tem 2026 |
53Planlayın | CVE-2014-7235Kavram kanıtı | htdocs_ari/includes/login.php in the ARI Framework module/Asterisk Recording Interface (ARI) in FreePBX before 2.9.0.9, 2.10.x, and 2.11 beffreepbx · freepbx · CWE-94 | Kritik10,0 | — | %43,3 | 7 Eki 2014 |
51Planlayın | CVE-2012-4869Silahlaştırılmış | The callme_startcall function in recordings/misc/callme_page.php in FreePBX 2.9, 2.10, and earlier allows remote attackers to execute arbitrsangoma · freepbx · CWE-94 | Yüksek7,5 | — | %70,3 | 6 Eyl 2012 |
46Planlayın | CVE-2014-1903Silahlaştırılmış | admin/libraries/view.functions.php in FreePBX 2.9 before 2.9.0.14, 2.10 before 2.10.1.15, 2.11 before 2.11.0.23, and 12 before 12.0.1alpha22freepbx · freepbx · CWE-264 | Yüksek7,5 | — | %52,8 | 18 Şub 2014 |
45Planlayın | CVE-2021-45461İstismar yok | FreePBX, when restapps (aka Rest Phone Apps) 15.0.19.87, 15.0.19.88, 16.0.18.40, or 16.0.18.41 is installed, allows remote attackers to execsangoma · restapps | Kritik9,8 | — | %21,7 | 22 Ara 2021 |
44Planlayın | CVE-2023-49294İstismar yok | Asterisk Path Traversal vulnerabilitydigium · asterisk · CWE-22 | Yüksek7,5 | — | %45,3 | 14 Ara 2023 |
40Planlayın | CVE-2021-37706İstismar yok | Potential integer underflow upon receiving STUN message in PJSIPteluu · pjsip · CWE-191 | Kritik9,8 | — | %4,6 | 22 Ara 2021 |
40Planlayın | CVE-2022-23608İstismar yok | Use after free in PJSIPteluu · pjsip · CWE-416 | Kritik9,8 | — | %4,0 | 22 Şub 2022 |
40Planlayın | CVE-2019-12148İstismar yok | The Sangoma Session Border Controller (SBC) 2.3.23-119 GA web interface is vulnerable to an authentication bypass via an argument injection sangoma · session border controller firmware · CWE-88 | Kritik9,8 | — | %3,5 | 22 Eki 2019 |
40Planlayın | CVE-2019-12147İstismar yok | The Sangoma Session Border Controller (SBC) 2.3.23-119 GA web interface is vulnerable to Argument Injection via special characters in the ussangoma · session border controller firmware · CWE-88 | Kritik9,8 | — | %2,6 | 22 Eki 2019 |
40Planlayın | CVE-2020-10666İstismar yok | The restapps (aka Rest Phone apps) module for Sangoma FreePBX and PBXact 13, 14, and 15 through 15.0.19.2 allows remote code execution via asangoma · restapps · CWE-77 | Kritik9,8 | — | %2,2 | 31 May 2021 |
40Planlayın | CVE-2017-17430İstismar yok | Sangoma NetBorder / Vega Session Controller before 2.3.12-80-GA allows remote attackers to execute arbitrary commands via the web interface.sangoma · netborder\/vega session firmware · CWE-287 | Kritik9,8 | — | %1,8 | 7 Ara 2017 |
40Planlayın | CVE-2008-6598İstismar yok | Multiple race conditions in WANPIPE before 3.3.6 have unknown impact and attack vectors related to "bri restart logic."sangoma · wanpipe · CWE-362 | Kritik10,0 | — | %1,1 | 3 Nis 2009 |
39İzleyin | CVE-2025-32105İstismar yok | A buffer overflow in the the Sangoma IMG2020 HTTP server through 2.3.9.6 allows an unauthenticated user to achieve remote code execution.sangoma · img2020 firmware · CWE-120 | Kritik9,8 | — | %1,2 | 3 Haz 2025 |
39İzleyin | CVE-2024-57520İstismar yok | Insecure Permissions vulnerability in asterisk v22 allows a remote attacker to execute arbitrary code via the action_createconfig function.sangoma · asterisk · CWE-732 | Kritik9,8 | — | %1,0 | 5 Şub 2025 |
39İzleyin | CVE-2020-36630İstismar yok | FreePBX cdr Cdr.class.php ajaxHandler sql injectionsangoma · freepbx · CWE-89 | Kritik9,8 | — | %0,7 | 25 Ara 2022 |
38İzleyin | CVE-2025-66039Silahlaştırılmış | FreePBX Endpoint Manager Allows Unauthenticated Logins to Administrator Control Panel via Forged Basic Auth Headersangoma · freepbx · CWE-287 | Kritik9,3 | — | %3,3 | 9 Ara 2025 |
37İzleyin | CVE-2022-21723İstismar yok | Out-of-bounds read in multipart parsing in PJSIPteluu · pjsip · CWE-125 | Kritik9,1 | — | %4,4 | 26 Oca 2022 |
37İzleyin | CVE-2012-2186İstismar yok | Incomplete blacklist vulnerability in main/manager.c in Asterisk Open Source 1.8.x before 1.8.15.1 and 10.x before 10.7.1, Certified Asterisasterisk · open source | Kritik9,0 | — | %3,6 | 31 Ağu 2012 |
37İzleyin | CVE-2026-46376Kavram kanıtı | FreePBX: Unauthenticated Use of Hard-Coded Credentials Vulnerability in FreePBX UCP Interfacesangoma · freepbx · CWE-798 | Kritik9,3 | — | %0,5 | 29 May 2026 |
36İzleyin | CVE-2025-67736İstismar yok | Authenticated SQL Injection in FreePBX tts (Text To Speech) modulesangoma · freepbx · CWE-89 | Yüksek8,6 | — | %6,4 | 15 Ara 2025 |
35İzleyin | CVE-2024-58294İstismar yok | FreePBX 16 Authenticated Remote Code Execution via API Modulesangoma · freepbx · CWE-78 | Yüksek8,7 | — | %3,6 | 11 Ara 2025 |
- CVE-2025-5781996Hemen
FreePBX Affected by Authentication Bypass Leading to SQL Injection and RCE
KritikCVSS 10,0KEVSilahlaştırılmışEPSS %85sangoma · freepbx28 Ağu 2025
- CVE-2025-6432889Hemen
FreePBX Administration GUI is Vulnerable to Authenticated Command Injection
YüksekCVSS 8,6KEVSilahlaştırılmışEPSS %85sangoma · filestore7 Kas 2025
- CVE-2019-1900686Hemen
Sangoma FreePBX 115.0.16.26 and below, 14.0.13.11 and below, 13.0.197.13 and below have Incorrect Access Control.
KritikCVSS 9,8KEVSilahlaştırılmışEPSS %56sangoma · freepbx21 Kas 2019
- CVE-2026-958673Bu hafta
Unauthenticated SQL Injection Leading to Remote Code Execution in Switchvox SMB
KritikCVSS 9,3KEVSilahlaştırılmışEPSS %19sangoma · switchvox17 Tem 2026
- CVE-2014-723553Planlayın
htdocs_ari/includes/login.php in the ARI Framework module/Asterisk Recording Interface (ARI) in FreePBX before 2.9.0.9, 2.10.x, and 2.11 bef
KritikCVSS 10,0Kavram kanıtıEPSS %43freepbx · freepbx7 Eki 2014
- CVE-2012-486951Planlayın
The callme_startcall function in recordings/misc/callme_page.php in FreePBX 2.9, 2.10, and earlier allows remote attackers to execute arbitr
YüksekCVSS 7,5SilahlaştırılmışEPSS %70sangoma · freepbx6 Eyl 2012
- CVE-2014-190346Planlayın
admin/libraries/view.functions.php in FreePBX 2.9 before 2.9.0.14, 2.10 before 2.10.1.15, 2.11 before 2.11.0.23, and 12 before 12.0.1alpha22
YüksekCVSS 7,5SilahlaştırılmışEPSS %53freepbx · freepbx18 Şub 2014
- CVE-2021-4546145Planlayın
FreePBX, when restapps (aka Rest Phone Apps) 15.0.19.87, 15.0.19.88, 16.0.18.40, or 16.0.18.41 is installed, allows remote attackers to exec
KritikCVSS 9,8İstismar yokEPSS %22sangoma · restapps22 Ara 2021
- CVE-2023-4929444Planlayın
Asterisk Path Traversal vulnerability
YüksekCVSS 7,5İstismar yokEPSS %45digium · asterisk14 Ara 2023
- CVE-2021-3770640Planlayın
Potential integer underflow upon receiving STUN message in PJSIP
KritikCVSS 9,8İstismar yokEPSS %5teluu · pjsip22 Ara 2021
- CVE-2022-2360840Planlayın
Use after free in PJSIP
KritikCVSS 9,8İstismar yokEPSS %4teluu · pjsip22 Şub 2022
- CVE-2019-1214840Planlayın
The Sangoma Session Border Controller (SBC) 2.3.23-119 GA web interface is vulnerable to an authentication bypass via an argument injection
KritikCVSS 9,8İstismar yokEPSS %4sangoma · session border controller firmware22 Eki 2019
- CVE-2019-1214740Planlayın
The Sangoma Session Border Controller (SBC) 2.3.23-119 GA web interface is vulnerable to Argument Injection via special characters in the us
KritikCVSS 9,8İstismar yokEPSS %3sangoma · session border controller firmware22 Eki 2019
- CVE-2020-1066640Planlayın
The restapps (aka Rest Phone apps) module for Sangoma FreePBX and PBXact 13, 14, and 15 through 15.0.19.2 allows remote code execution via a
KritikCVSS 9,8İstismar yokEPSS %2sangoma · restapps31 May 2021
- CVE-2017-1743040Planlayın
Sangoma NetBorder / Vega Session Controller before 2.3.12-80-GA allows remote attackers to execute arbitrary commands via the web interface.
KritikCVSS 9,8İstismar yokEPSS %2sangoma · netborder\/vega session firmware7 Ara 2017
- CVE-2008-659840Planlayın
Multiple race conditions in WANPIPE before 3.3.6 have unknown impact and attack vectors related to "bri restart logic."
KritikCVSS 10,0İstismar yokEPSS %1sangoma · wanpipe3 Nis 2009
- CVE-2025-3210539İzleyin
A buffer overflow in the the Sangoma IMG2020 HTTP server through 2.3.9.6 allows an unauthenticated user to achieve remote code execution.
KritikCVSS 9,8İstismar yokEPSS %1sangoma · img2020 firmware3 Haz 2025
- CVE-2024-5752039İzleyin
Insecure Permissions vulnerability in asterisk v22 allows a remote attacker to execute arbitrary code via the action_createconfig function.
KritikCVSS 9,8İstismar yokEPSS %1sangoma · asterisk5 Şub 2025
- CVE-2020-3663039İzleyin
FreePBX cdr Cdr.class.php ajaxHandler sql injection
KritikCVSS 9,8İstismar yokEPSS %1sangoma · freepbx25 Ara 2022
- CVE-2025-6603938İzleyin
FreePBX Endpoint Manager Allows Unauthenticated Logins to Administrator Control Panel via Forged Basic Auth Header
KritikCVSS 9,3SilahlaştırılmışEPSS %3sangoma · freepbx9 Ara 2025
- CVE-2022-2172337İzleyin
Out-of-bounds read in multipart parsing in PJSIP
KritikCVSS 9,1İstismar yokEPSS %4teluu · pjsip26 Oca 2022
- CVE-2012-218637İzleyin
Incomplete blacklist vulnerability in main/manager.c in Asterisk Open Source 1.8.x before 1.8.15.1 and 10.x before 10.7.1, Certified Asteris
KritikCVSS 9,0İstismar yokEPSS %4asterisk · open source31 Ağu 2012
- CVE-2026-4637637İzleyin
FreePBX: Unauthenticated Use of Hard-Coded Credentials Vulnerability in FreePBX UCP Interface
KritikCVSS 9,3Kavram kanıtıEPSS %0sangoma · freepbx29 May 2026
- CVE-2025-6773636İzleyin
Authenticated SQL Injection in FreePBX tts (Text To Speech) module
YüksekCVSS 8,6İstismar yokEPSS %6sangoma · freepbx15 Ara 2025
- CVE-2024-5829435İzleyin
FreePBX 16 Authenticated Remote Code Execution via API Module
YüksekCVSS 8,7İstismar yokEPSS %4sangoma · freepbx11 Ara 2025