Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2975▼ 108 respecto a la semana anterior
Críticas / altas1449▲ 87 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
71 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Alta (8.6) | 6.4% | — | Sangoma Freepbx | 16/12/2025 | 17/6/2026 | The FreePBX module tts (Text to Speech) for FreePBX, an open-source web-based graphical user interface (GUI) that manages Asterisk. Versions prior to 16.0.5 and 17.0.5 are vulnerable to SQL injection by authenticated users with administrator access. Authenticated users with administrative access to the Administrator… | |
| Analizada | Media (5.7) | 0.13% | — | Sangoma Freepbx | 16/12/2025 | 17/6/2026 | FreePBX is an open-source web-based graphical user interface (GUI) that manages Asterisk. Prior to versions 16.0.45 and 17.0.24 of the FreePBX framework, an authenticated local privilege escalation exists in the deprecated FreePBX startup script `amportal`. In the deprecated `amportal` utility, the lookup for the… | |
| Analizada | Alta (8.7) | 3.6% | — | Sangoma Freepbx | 11/12/2025 | 17/6/2026 | FreePBX 16 contains an authenticated remote code execution vulnerability in the API module that allows attackers with valid session credentials to execute arbitrary commands. Attackers can exploit the 'generatedocs' endpoint by crafting malicious POST requests with bash command injection to establish remote shell… | |
| Aplazada | Media (6.9) | 0.27% | — | Freepbx Endpoint ManagerAI | 10/12/2025 | 25/9/2026 | FreePBX Endpoint Manager is a module for managing telephony endpoints in FreePBX systems. Versions prior to 16.0.96 and 17.0.1 through 17.0.9 have a weak default password. By default, this is a 6 digit numeric value which can be brute forced. (This is the app_password parameter). Depending on local configuration, this… | |
| Analizada | Crítica (9.3) | 3.3% | 💥 Exploit | Sangoma Freepbx | 9/12/2025 | 25/9/2026 | FreePBX Endpoint Manager is a module for managing telephony endpoints in FreePBX systems. Versions are vulnerable to authentication bypass when the authentication type is set to "webserver." When providing an Authorization header with an arbitrary value, a session is associated with the target user regardless of valid… | |
| Aplazada | Alta (8.6) | 44% | 💥 Exploit | Freepbx Endpoint ManagerAI | 14/10/2025 | 17/6/2026 | FreePBX Endpoint Manager is a module for managing telephony endpoints in FreePBX systems. In versions prior to 16.0.92 for FreePBX 16 and versions prior to 17.0.6 for FreePBX 17, the Endpoint Manager module contains an authenticated arbitrary file upload vulnerability affecting the fwbrand parameter. The fwbrand… | |
| Aplazada | Alta (8.6) | 38% | 💥 Exploit | Freepbx Endpoint ManagerAI | 14/10/2025 | 17/6/2026 | FreePBX Endpoint Manager is a module for managing telephony endpoints in FreePBX systems. In versions prior to 16.0.92 for FreePBX 16 and versions prior to 17.0.6 for FreePBX 17, the Endpoint Manager module contains authenticated SQL injection vulnerabilities affecting multiple parameters in the basestation, model,… | |
| Analizada | Alta (8.5) | 0.19% | — | Sangoma Freepbx | 14/10/2025 | 17/6/2026 | FreePBX is an open source GUI for managing Asterisk. In versions prior to 16.0.68.39 for FreePBX 16 and versions prior to 17.0.18.38 for FreePBX 17, a reflected cross-site scripting vulnerability is present on the Asterisk HTTP Status page. The Asterisk HTTP status page is exposed by FreePBX and is available by… | |
| Aplazada | Alta (8.6) | 0.53% | — | Freepbx Endpoint ManagerAI | 14/10/2025 | 17/6/2026 | The FreePBX Endpoint Manager module includes a Network Scanning feature that provides web-based access to nmap functionality for network device discovery. In Endpoint Manager 16 before 16.0.92 and 17 before 17.0.6, insufficiently sanitized user-supplied input allows authenticated OS command execution as the asterisk… | |
| Analizada | Media (6.6) | 0.46% | — | Sangoma Freepbx | 15/9/2025 | 17/6/2026 | FreePBX is an open-source web-based graphical user interface. In FreePBX 15, 16, and 17, malicious connections to the Administrator Control Panel web interface can cause the uninstall function to be triggered for certain modules. This function drops the module's database tables, which is where most modules store their… | |
| Analizada | Media (6.3) | 0.44% | — | Sangoma Freepbx | 15/9/2025 | 17/6/2026 | FreePBX is an open-source web-based graphical user interface. From 17.0.19.11 to before 17.0.21, authenticated users of the Administrator Control Panel (ACP) can run arbitrary shell commands by maliciously changing languages of the framework module. This vulnerability is fixed in 17.0.21. | |
| Aplazada | Media (5.1) | 0.42% | — | FreepbxAIAsteriskAI | 5/9/2025 | 17/6/2026 | api is a module for FreePBX@, which is an open source GUI that controls and manages Asterisk© (PBX). In versions lower than 15.0.13, 16.0.2 through 16.0.14, 17.0.1 and 17.0.2, there is an identical OAuth private key used across multiple systems that installed the same FreePBX RPM or DEB package. An attacker with… | |
| Aplazada | Media (5.1) | 0.36% | — | FreepbxAIAsteriskAI | 4/9/2025 | 17/6/2026 | contactmanager is a module for FreePBX@, which is an open source GUI that controls and manages Asterisk© (PBX). In versions 15.0.14 and below, 16.0.0 through 16.0.26.4 and 17.0.0 through 17.0.5, a stored cross-site scripting (XSS) vulnerability in FreePBX allows a low-privileged User Control Panel (UCP) user to inject… | |
| Analizada | Crítica (10) | 85% | ⚠ Explotación activa💥 Exploit | Sangoma Freepbx | 28/8/2025 | 25/9/2026 | FreePBX is an open-source web-based graphical user interface. FreePBX 15, 16, and 17 endpoints are vulnerable due to insufficiently sanitized user-supplied data allowing unauthenticated access to FreePBX Administrator leading to arbitrary database manipulation and remote code execution. This issue has been patched in… | |
| Analizada | Alta (7.2) | 0.35% | — | Sangoma Freepbx | 2/12/2024 | 17/6/2026 | A vulnerability was discovered in FreePBX 17.0.19.17. It does not verify the type of uploaded (valid FreePBX module) files, allowing high-privilege administrators to insert unwanted files. NOTE: the Supplier's position is that there is no risk beyond what high-privilege administrators are intentionally allowed to do. | |
| Aplazada | Media (6.8) | 0.51% | — | Freepbx OSS Endpoint ManagerAI | 1/10/2024 | 17/6/2026 | OSS Endpoint Manager is an endpoint manager module for FreePBX. OSS Endpoint Manager module activation can allow authenticated web users unauthorized access to read system files with the permissions of the webserver process. This vulnerability is fixed in 14.0.4. | |
| Aplazada | Alta (8.6) | 0.71% | — | Sangoma FreepbxAIAsteriskAI | 14/5/2024 | 17/6/2026 | Sangoma FreePBX 1805 through 2203 on Linux contains hardcoded credentials for the Asterisk REST Interface (ARI), which allows remote attackers to reconfigure Asterisk and make external and internal calls via HTTP and WebSocket requests sent to the API. | |
| Modificada | Alta (8.8) | 0.72% | — | Sangoma Freepbx | 2/11/2023 | 9/7/2026 | Sangoma Technologies FreePBX before cdr 15.0.18, 16.0.40, 15.0.16, and 16.0.17 was discovered to contain an access control issue via a modified parameter value, e.g., changing extension=self to extension=101. | |
| Modificada | Alta (8.1) | 0.65% | — | Sangoma Freepbx Linux 7 | 26/4/2023 | 17/6/2026 | Sangoma FreePBX 1805 through 2302 (when obtained as a ,.ISO file) places AMPDBUSER, AMPDBPASS, AMPMGRUSER, and AMPMGRPASS in the list of global variables. This exposes cleartext authentication credentials for the Asterisk Database (MariaDB/MySQL) and Asterisk Manager Interface. For example, an attacker can make a… | |
| Modificada | Media (6.1) | 0.52% | — | Sangoma Freepbx | 27/12/2022 | 17/6/2026 | A vulnerability was found in FreePBX arimanager up to 13.0.5.3 and classified as problematic. Affected by this issue is some unknown functionality of the component Views Handler. The manipulation of the argument dataurl leads to cross site scripting. The attack may be launched remotely. Upgrading to version 13.0.5.4… | |
| Modificada | Crítica (9.8) | 0.71% | — | Sangoma Freepbx | 25/12/2022 | 17/6/2026 | A vulnerability was found in FreePBX cdr 14.0. It has been classified as critical. This affects the function ajaxHandler of the file ucp/Cdr.class.php. The manipulation of the argument limit/offset leads to sql injection. Upgrading to version 14.0.5.21 is able to address this issue. The name of the patch is… | |
| Modificada | Media (4.8) | 0.56% | — | Sangoma Freepbx | 16/3/2020 | 17/6/2026 | An XSS Injection vulnerability exists in Sangoma FreePBX and PBXact 13, 14, and 15 within the Call Event Logging report screen in the cel module at the admin/config.php?display=cel URI via date fields. This affects cel through 13.0.26.9, 14.x through 14.0.2.14, and 15.x through 15.0.15.4. | |
| Modificada | Media (4.8) | 0.56% | — | Sangoma Freepbx | 16/3/2020 | 17/6/2026 | Multiple XSS vulnerabilities exist in the Backup & Restore module \ v14.0.10.2 through v14.0.10.7 for FreePBX, as shown at /admin/config.php?display=backup on the FreePBX Administrator web site. An attacker can modify the id parameter of the backup configuration screen and embed malicious XSS code via a link. When… | |
| Modificada | Alta (7.2) | 3.1% | — | Sangoma Freepbx | 16/3/2020 | 17/6/2026 | In Sangoma FreePBX 13 through 15 and sysadmin (aka System Admin) 13.0.92 through 15.0.13.6 modules have a Remote Command Execution vulnerability that results in Privilege Escalation. | |
| Modificada | Media (4.8) | 0.53% | — | Sangoma Freepbx | 16/3/2020 | 17/6/2026 | An XSS Injection vulnerability exists in Sangoma FreePBX and PBXact 13, 14, and 15 within the Debug/Test page of the Superfecta module at the admin/config.php?display=superfecta URI. This affects Superfecta through 13.0.4.7, 14.x through 14.0.24, and 15.x through 15.0.2.20. |