Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2570▼ 305 respecto a la semana anterior
Críticas / altas1353▲ 102 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 7 respecto a la semana anterior
Sin puntuar (sin CVSS)56▼ 472 respecto a la semana anterior
154 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Alta (8.2) | 0.34% | — | Mitel CXMitel Micontact Center Business | 15/1/2026 | 17/6/2026 | A vulnerability in the Multimedia Email component of Mitel MiContact Center Business through 10.2.0.10 and Mitel CX through 1.1.0.1 could allow an unauthenticated attacker to conduct a Cross-Site Scripting (XSS) attack due to insufficient input validation. A successful exploit requires user interaction where the email… | |
| Analizada | Crítica (9.4) | 0.41% | — | Mitel Mivoice Mx-one | 15/1/2026 | 17/6/2026 | A vulnerability in the Provisioning Manager component of Mitel MiVoice MX-ONE 7.3 (7.3.0.0.50) through 7.8 SP1 (7.8.1.0.14) could allow an unauthenticated attacker to conduct an authentication bypass attack due to improper authentication mechanisms. A successful exploit could allow an attacker to gain unauthorized… | |
| Analizada | Alta (8.8) | 0.64% | — | Mitel Micollab | 8/8/2025 | 17/6/2026 | A vulnerability in the Suite Applications Services component of Mitel MiCollab 10.0 through SP1 FP1 (10.0.1.101) could allow an authenticated attacker to conduct a SQL Injection attack due to insufficient validation of user input. A successful exploit could allow an attacker to execute arbitrary SQL database commands. | |
| Aplazada | Crítica (9.8) | 0.52% | — | Mitel MicollabAIMitel Nupoint Unified MessagingAI | 8/8/2025 | 17/6/2026 | A vulnerability in the NuPoint Unified Messaging (NPM) component of Mitel MiCollab through 9.8 SP2 (9.8.2.12) could allow an unauthenticated attacker to conduct a path traversal attack due to insufficient input validation. A successful exploit could allow unauthorized access, enabling the attacker to view, corrupt, or… | |
| Aplazada | Media (6.5) | 50% | — | Mitel 6800 Series SIP PhonesAIMitel 6900 Series SIP PhonesAIMitel 6900w Series SIP PhonesAIMitel 6970 Conference UnitAI | 7/8/2025 | 17/6/2026 | A vulnerability in the Mitel 6800 Series, 6900 Series, and 6900w Series SIP Phones through 6.4 SP4 (R6.4.0.4006), and the 6970 Conference Unit through 6.4 SP4 (R6.4.0.4006) or version V1 R0.1.0, could allow an unauthenticated attacker to conduct a command injection attack due to insufficient parameter sanitization. A… | |
| Aplazada | Alta (7.5) | 0.84% | — | Mitel 6800 Series SIP PhonesAIMitel 6900 Series SIP PhonesAIMitel 6900w Series SIP PhonesAIMitel 6970 Conference UnitAI | 23/7/2025 | 17/6/2026 | A vulnerability in the Mitel 6800 Series, 6900 Series, and 6900w Series SIP Phones through 6.4 SP4 (R6.4.0.4006), and the 6970 Conference Unit through 6.4 SP4 (R6.4.0.4006) or version V1 R0.1.0, could allow an unauthenticated attacker to perform a file upload attack due to missing authentication mechanisms. A… | |
| Aplazada | Alta (7.1) | 0.41% | — | Mitel Micontact Center BusinessAI | 24/6/2025 | 17/6/2026 | A vulnerability in the legacy chat component of Mitel MiContact Center Business through 10.0.0.4, 10.1.0.0 through 10.1.0.5, and 10.2.0.0 through 10.2.0.4 could allow an unauthenticated attacker to conduct a reflected cross-site scripting (XSS) attack due to insufficient input validation. A successful exploit requires… | |
| Aplazada | Alta (7.1) | 0.35% | — | Mitel Micontact Center BusinessAI | 24/6/2025 | 17/6/2026 | A vulnerability in the legacy chat component of Mitel MiContact Center Business through 10.2.0.3 could allow an unauthenticated attacker to conduct an information disclosure attack due to improper handling of session data. A successful exploit requires user interaction and could allow an attacker to access sensitive… | |
| Aplazada | Alta (7.2) | 0.90% | — | Mitel Openscape Accounting ManagementAI | 23/6/2025 | 17/6/2026 | Mitel OpenScape Accounting Management through V5 R1.1.0 could allow an authenticated attacker with administrative privileges to conduct a path traversal attack due to insufficient sanitization of user input. A successful exploit could allow an attacker to upload arbitrary files and execute unauthorized commands. | |
| Aplazada | Alta (7.5) | 0.58% | — | Mitel Openscape XpressionsAI | 23/6/2025 | 17/6/2026 | A vulnerability in the WebApl component of Mitel OpenScape Xpressions through V7R1 FR5 HF43 P913 could allow an unauthenticated attacker to conduct a path traversal attack due to insufficient input validation. A successful exploit could allow an attacker to read files from the underlying OS and obtain sensitive… | |
| Aplazada | Media (5.6) | 1.6% | — | Mitel ICP Voip 3100AI | 1/4/2025 | 16/6/2026 | An issue was discovered on Mitel ICP VoIP 3100 devices. When a remote user attempts to log in via TELNET during the login wait time and an external call comes in, the system incorrectly divulges information about the call and any SMDR records generated by the system. The information provided includes the service type,… | |
| Aplazada | Alta (7.3) | 0.43% | — | Lexmark International XCAILexmark International CSAIMitel CXAI | 13/2/2025 | 17/6/2026 | Integer Overflow or Wraparound vulnerability in Lexmark International CX, XC, CS, et. Al. (Postscript interpreter modules) allows Forced Integer Overflow.The vulnerability can be leveraged by an attacker to execute arbitrary code as an unprivileged user. | |
| Aplazada | Alta (7.3) | 1.2% | — | Mitel Openscape 4000AIMitel Openscape 4000 ManagerAI | 6/2/2025 | 17/6/2026 | The Platform component of Mitel OpenScape 4000 and OpenScape 4000 Manager V11 R0.22.0 through V11 R0.22.1, V10 R1.54.0 through V10 R1.54.1, and V10 R1.42.6 and earlier could allow an unauthenticated attacker to conduct a command injection attack due to insufficient parameter sanitization. A successful exploit could… | |
| Aplazada | Alta (8.8) | 0.59% | — | Mitel Openscape 4000AIMitel Openscape 4000 ManagerAI | 6/2/2025 | 17/6/2026 | The Platform component of Mitel OpenScape 4000 and OpenScape 4000 Manager through V10 R1.54.1 and V11 through R0.22.1 could allow an authenticated attacker to conduct a privilege escalation attack due to the execution of a resource with unnecessary privileges. A successful exploit could allow an attacker to execute… | |
| Analizada | Baja (2.7) | 38% | ⚠ Explotación activa | Mitel Micollab | 10/12/2024 | 4/8/2026 | Mitel MiCollab through 9.8 SP2 could allow an authenticated attacker with administrative privilege to conduct a local file read, due to insufficient input sanitization. A successful exploit could allow the authenticated admin attacker to access resources that are constrained to the admin access level, and the… | |
| Analizada | Media (6.5) | 0.36% | — | Mitel Micollab | 21/10/2024 | 17/6/2026 | A vulnerability in the AWV (Audio, Web and Video Conferencing) component of Mitel MiCollab through 9.8 SP1 FP2 (9.8.1.201) could allow an unauthenticated attacker to conduct a CRLF injection attack due to inadequate encoding of user input in URLs. A successful exploit could allow an attacker to perform a phishing… | |
| Analizada | Alta (8.8) | 1.3% | — | Mitel MicollabMitel Mivoice Business Solution Virtual Instance | 21/10/2024 | 17/6/2026 | A vulnerability in the Web Interface component of Mitel MiCollab through 9.8 SP1 (9.8.1.5) and MiVoice Business Solution Virtual Instance (MiVB SVI) through 1.0.0.27 could allow an authenticated attacker to conduct a command injection attack, due to insufficient parameter sanitization. A successful exploit could allow… | |
| Analizada | Crítica (9.1) | 98% | ⚠ Explotación activa | Mitel Micollab | 21/10/2024 | 4/8/2026 | A vulnerability in the NuPoint Unified Messaging (NPM) component of Mitel MiCollab through 9.8 SP1 FP2 (9.8.1.201) could allow an unauthenticated attacker to conduct a path traversal attack, due to insufficient input validation. A successful exploit could allow unauthorized access, enabling the attacker to view,… | |
| Analizada | Media (6.6) | 0.55% | — | Mitel Micollab | 21/10/2024 | 17/6/2026 | A vulnerability in the Web Conferencing Component of Mitel MiCollab through 9.8.1.5 could allow an authenticated attacker to conduct a command injection attack, due to insufficient validation of user input. A successful exploit could allow an attacker to execute arbitrary commands on the system within the context of… | |
| Analizada | Media (5.6) | 0.77% | — | Mitel MicollabMitel Mivoice Business Solution Virtual Instance | 21/10/2024 | 17/6/2026 | A vulnerability in the Desktop Client of Mitel MiCollab through 9.7.1.110, and MiVoice Business Solution Virtual Instance (MiVB SVI) 1.0.0.25, could allow an authenticated attacker to conduct a privilege escalation attack due to improper file validation. A successful exploit could allow an attacker to run arbitrary… | |
| Analizada | Crítica (9.8) | 1.8% | — | Mitel MicollabMitel Mivoice Business Solution Virtual Instance | 21/10/2024 | 17/6/2026 | A vulnerability in the Desktop Client of Mitel MiCollab through 9.7.1.110, and MiVoice Business Solution Virtual Instance (MiVB SVI) 1.0.0.25, could allow an unauthenticated attacker to conduct a command injection attack due to insufficient parameter sanitization. A successful exploit requires user interaction and… | |
| Analizada | Media (6.7) | 0.21% | — | Mitel Micollab | 21/10/2024 | 17/6/2026 | A vulnerability in the NuPoint Messenger (NPM) component of Mitel MiCollab through version 9.8 SP1 (9.8.1.5) could allow an authenticated attacker with administrative privilege to conduct a privilege escalation attack due to the execution of a resource with unnecessary privileges. A successful exploit could allow an… | |
| Analizada | Crítica (9.8) | 66% | — | Mitel Micollab | 21/10/2024 | 17/6/2026 | A vulnerability in NuPoint Messenger (NPM) of Mitel MiCollab through 9.8.0.33 allows an unauthenticated attacker to conduct a SQL injection attack due to insufficient sanitization of user input. A successful exploit could allow an attacker to access sensitive information and execute arbitrary database and management… | |
| Analizada | Crítica (9.8) | 1.3% | — | Mitel Micollab | 21/10/2024 | 17/6/2026 | A vulnerability in NuPoint Messenger (NPM) of Mitel MiCollab through 9.8.0.33 allows an unauthenticated attacker to conduct a command injection attack due to insufficient parameter sanitization. | |
| Modificada | Media (4.8) | 0.32% | — | Mitel Micollab | 21/10/2024 | 17/6/2026 | A vulnerability in the Suite Applications Services component of Mitel MiCollab through 9.7.1.110 could allow an authenticated attacker with administrative privileges to conduct a Stored Cross-Site Scripting (XSS) attack due to insufficient validation of user input. A successful exploit could allow an attacker to… |