İçeriğe atla
Noroxi

sangoma kayıtları

sangoma üreticisine ait 85 yayımlanmış kayıt.

Tüm kayıtlar

85 kayıt
  • FreePBX Affected by Authentication Bypass Leading to SQL Injection and RCE

    KritikCVSS 10,0KEVSilahlaştırılmışEPSS %85

    sangoma · freepbx28 Ağu 2025

  • FreePBX Administration GUI is Vulnerable to Authenticated Command Injection

    YüksekCVSS 8,6KEVSilahlaştırılmışEPSS %85

    sangoma · filestore7 Kas 2025

  • Sangoma FreePBX 115.0.16.26 and below, 14.0.13.11 and below, 13.0.197.13 and below have Incorrect Access Control.

    KritikCVSS 9,8KEVSilahlaştırılmışEPSS %56

    sangoma · freepbx21 Kas 2019

  • CVE-2026-9586
    73Bu hafta

    Unauthenticated SQL Injection Leading to Remote Code Execution in Switchvox SMB

    KritikCVSS 9,3KEVSilahlaştırılmışEPSS %19

    sangoma · switchvox17 Tem 2026

  • CVE-2014-7235
    53Planlayın

    htdocs_ari/includes/login.php in the ARI Framework module/Asterisk Recording Interface (ARI) in FreePBX before 2.9.0.9, 2.10.x, and 2.11 bef

    KritikCVSS 10,0Kavram kanıtıEPSS %43

    freepbx · freepbx7 Eki 2014

  • CVE-2012-4869
    51Planlayın

    The callme_startcall function in recordings/misc/callme_page.php in FreePBX 2.9, 2.10, and earlier allows remote attackers to execute arbitr

    YüksekCVSS 7,5SilahlaştırılmışEPSS %70

    sangoma · freepbx6 Eyl 2012

  • CVE-2014-1903
    46Planlayın

    admin/libraries/view.functions.php in FreePBX 2.9 before 2.9.0.14, 2.10 before 2.10.1.15, 2.11 before 2.11.0.23, and 12 before 12.0.1alpha22

    YüksekCVSS 7,5SilahlaştırılmışEPSS %53

    freepbx · freepbx18 Şub 2014

  • CVE-2021-45461
    45Planlayın

    FreePBX, when restapps (aka Rest Phone Apps) 15.0.19.87, 15.0.19.88, 16.0.18.40, or 16.0.18.41 is installed, allows remote attackers to exec

    KritikCVSS 9,8İstismar yokEPSS %22

    sangoma · restapps22 Ara 2021

  • CVE-2023-49294
    44Planlayın

    Asterisk Path Traversal vulnerability

    YüksekCVSS 7,5İstismar yokEPSS %45

    digium · asterisk14 Ara 2023

  • CVE-2021-37706
    40Planlayın

    Potential integer underflow upon receiving STUN message in PJSIP

    KritikCVSS 9,8İstismar yokEPSS %5

    teluu · pjsip22 Ara 2021

  • CVE-2022-23608
    40Planlayın

    Use after free in PJSIP

    KritikCVSS 9,8İstismar yokEPSS %4

    teluu · pjsip22 Şub 2022

  • CVE-2019-12148
    40Planlayın

    The Sangoma Session Border Controller (SBC) 2.3.23-119 GA web interface is vulnerable to an authentication bypass via an argument injection

    KritikCVSS 9,8İstismar yokEPSS %4

    sangoma · session border controller firmware22 Eki 2019

  • CVE-2019-12147
    40Planlayın

    The Sangoma Session Border Controller (SBC) 2.3.23-119 GA web interface is vulnerable to Argument Injection via special characters in the us

    KritikCVSS 9,8İstismar yokEPSS %3

    sangoma · session border controller firmware22 Eki 2019

  • CVE-2020-10666
    40Planlayın

    The restapps (aka Rest Phone apps) module for Sangoma FreePBX and PBXact 13, 14, and 15 through 15.0.19.2 allows remote code execution via a

    KritikCVSS 9,8İstismar yokEPSS %2

    sangoma · restapps31 May 2021

  • CVE-2017-17430
    40Planlayın

    Sangoma NetBorder / Vega Session Controller before 2.3.12-80-GA allows remote attackers to execute arbitrary commands via the web interface.

    KritikCVSS 9,8İstismar yokEPSS %2

    sangoma · netborder\/vega session firmware7 Ara 2017

  • CVE-2008-6598
    40Planlayın

    Multiple race conditions in WANPIPE before 3.3.6 have unknown impact and attack vectors related to "bri restart logic."

    KritikCVSS 10,0İstismar yokEPSS %1

    sangoma · wanpipe3 Nis 2009

  • CVE-2025-32105
    39İzleyin

    A buffer overflow in the the Sangoma IMG2020 HTTP server through 2.3.9.6 allows an unauthenticated user to achieve remote code execution.

    KritikCVSS 9,8İstismar yokEPSS %1

    sangoma · img2020 firmware3 Haz 2025

  • CVE-2024-57520
    39İzleyin

    Insecure Permissions vulnerability in asterisk v22 allows a remote attacker to execute arbitrary code via the action_createconfig function.

    KritikCVSS 9,8İstismar yokEPSS %1

    sangoma · asterisk5 Şub 2025

  • CVE-2020-36630
    39İzleyin

    FreePBX cdr Cdr.class.php ajaxHandler sql injection

    KritikCVSS 9,8İstismar yokEPSS %1

    sangoma · freepbx25 Ara 2022

  • CVE-2025-66039
    38İzleyin

    FreePBX Endpoint Manager Allows Unauthenticated Logins to Administrator Control Panel via Forged Basic Auth Header

    KritikCVSS 9,3SilahlaştırılmışEPSS %3

    sangoma · freepbx9 Ara 2025

  • CVE-2022-21723
    37İzleyin

    Out-of-bounds read in multipart parsing in PJSIP

    KritikCVSS 9,1İstismar yokEPSS %4

    teluu · pjsip26 Oca 2022

  • CVE-2012-2186
    37İzleyin

    Incomplete blacklist vulnerability in main/manager.c in Asterisk Open Source 1.8.x before 1.8.15.1 and 10.x before 10.7.1, Certified Asteris

    KritikCVSS 9,0İstismar yokEPSS %4

    asterisk · open source31 Ağu 2012

  • CVE-2026-46376
    37İzleyin

    FreePBX: Unauthenticated Use of Hard-Coded Credentials Vulnerability in FreePBX UCP Interface

    KritikCVSS 9,3Kavram kanıtıEPSS %0

    sangoma · freepbx29 May 2026

  • CVE-2025-67736
    36İzleyin

    Authenticated SQL Injection in FreePBX tts (Text To Speech) module

    YüksekCVSS 8,6İstismar yokEPSS %6

    sangoma · freepbx15 Ara 2025

  • CVE-2024-58294
    35İzleyin

    FreePBX 16 Authenticated Remote Code Execution via API Module

    YüksekCVSS 8,7İstismar yokEPSS %4

    sangoma · freepbx11 Ara 2025