Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2684▼ 80 respecto a la semana anterior
Críticas / altas1442▲ 302 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)64▼ 462 respecto a la semana anterior
71 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Pendiente de análisis | Alta (8.6) | 0.76% | — | FreepbxAI | 28/9/2026 | 30/9/2026 | FreePBX is an open source IP PBX. Prior to version 17.0.9, authenticated users who are authorized to access the GraphQL api module interface of FreePBX are able to execute arbitrary shell commands. Authenticated access to the api module is required. The PBX API module's documentation generator accepts an authenticated… | |
| Pendiente de análisis | Alta (8.6) | 0.45% | — | FreepbxAI | 28/9/2026 | 30/9/2026 | FreePBX is an open source IP PBX. Prior to versions 16.0.40 and 17.0.7, a critical remote code execution (RCE) vulnerability exists in the superfecta module due to unsafe inclusion of arbitrary PHP files, allowing authenticated attackers to execute arbitrary PHP code on the server with the privileges of the web server… | |
| Pendiente de análisis | Alta (8.6) | 0.45% | — | FreepbxAI | 28/9/2026 | 30/9/2026 | FreePBX is an open source IP PBX. Prior to versions 16.0.72 and 17.0.7, a critical vulnerability exists in the FreePBX backup Module that allows authenticated attackers to execute arbitrary code on the server. Authentication with a known username that has sufficient access permissions and/or write access to backup… | |
| Pendiente de análisis | Alta (8.7) | 0.60% | — | FreepbxAI | 28/9/2026 | 30/9/2026 | FreePBX is an open source IP PBX. Prior to versions 16.0.10 and 17.0.5, a critical vulnerability exists in the sound language upload and conversion functionality that allows an authenticated attacker to perform arbitrary file writes, leading directly to remote code execution (RCE). Authentication with a known username… | |
| Pendiente de análisis | Alta (8.6) | 0.60% | — | FreepbxAI | 28/9/2026 | 30/9/2026 | FreePBX is an open source IP PBX. Prior to versions 16.0.39 and 17.0.7, users authenticated via User Control Panel (UCP) are able to execute arbitrary commands on the PBX as the webserver user (typically asterisk) using specially crafted HTTP strings. Authenticated access to UCP is required. Note that this is often… | |
| Pendiente de análisis | Alta (7.7) | 0.30% | — | FreepbxAI | 28/9/2026 | 30/9/2026 | FreePBX is an open source IP PBX. Prior to versions 16.0.4 and 17.0.6, the FreePBX Music on Hold (MoH) module contains a critical security flaw that allows authenticated attackers to execute arbitrary system commands with the privileges of the Asterisk service. Authentication with an existing FreePBX administrator… | |
| Pendiente de análisis | Crítica (9.3) | 0.41% | — | FreepbxAIAsteriskAISocket.ioAI | 13/8/2026 | 10/9/2026 | FreePBX is an open source IP PBX. Prior to 17.0.9, the UCP Node server on ports 8001 and 8003 uses io.use(checkAuth) in node/lib/server.js, but Socket.IO version 4 applies that middleware only to the default namespace. An unauthenticated client can connect to custom namespaces that do not consistently invoke checkAuth… | |
| Pendiente de análisis | Alta (8.6) | 0.51% | — | FreepbxAI | 13/8/2026 | 18/9/2026 | FreePBX is an open source IP PBX. From 17.0.5.34 until 17.0.11, the publicKeySave AJAX endpoint in Backup.class.php accepts an authenticated administrator's SSH public key and appends it to /home/asterisk/.ssh/authorized_keys for the asterisk system user without reliably enforcing backup-only command and source… | |
| Pendiente de análisis | Crítica (9.3) | 1.7% | — | FreepbxAIFreepbx MissedcallAI | 13/8/2026 | 18/9/2026 | FreePBX is an open source IP PBX. From 16.0.0 until 16.0.11 and 17.0.4, the FreePBX missedcall module places the inbound Caller ID name from crafted SIP From headers into the missedcalllog INSERT in agi-bin/missedcallnotify.php without escaping or bound parameters. An unauthenticated caller can inject SQL when a… | |
| Pendiente de análisis | Alta (7.6) | 0.64% | — | FreepbxAIAsteriskAI | 13/8/2026 | 18/9/2026 | FreePBX is an open source IP PBX. From 17.0.1 until 17.0.7, the FreePBX Music on Hold module permits dangerous command-line options for /usr/bin/mpg123 and other allowed players in validateCustomConfiguration() in Music.class.php. An authenticated administrator can use options that write files, open control channels,… | |
| Pendiente de análisis | Alta (8.6) | 0.60% | — | FreepbxAI | 13/8/2026 | 18/9/2026 | FreePBX is an open source IP PBX. Prior to 16.0.47 and 17.0.30, the FreePBX Framework module permits a crafted backup to restore the hidden AUTHTYPE setting with the value none through runRestore() in amp_conf/htdocs/admin/libraries/Builtin/Restore.php. An authenticated user with sufficient backup-restore access or… | |
| Pendiente de análisis | Alta (7.5) | 0.77% | — | FreepbxAIAsteriskAI | 13/8/2026 | 18/9/2026 | FreePBX is an open source IP PBX. Prior to 16.0.6 and 17.0.5.4, the FreePBX Text-To-Speech module allows an authenticated administrator to save a TTS destination name that is HTML-encoded for storage, decoded during dialplan generation, passed as an AGI argument, and used to build filenames inside… | |
| Aplazada | Alta (8.8) | 0.26% | — | Freepbx FrameworkAI | 10/8/2026 | 28/8/2026 | A cross-site request forgery (CSRF) vulnerability in FreePBX Framework 17.0 allows an unauthenticated remote attacker to perform administrative actions on behalf of an authenticated administrator. | |
| Aplazada | Media (4.8) | 0.44% | — | FrogmanAIFreepbxAI | 20/7/2026 | 22/7/2026 | Frogman provides headless FreePBX control. Prior to version 1.6.6, Frogman's chat-console markdown formatter (`assets/js/chat.js`'s `formatMarkdown`) inserted regex capture groups as raw HTML in four template patterns: inline code, bold, markdown links, and download links. Tool responses that reflect user-controlled… | |
| Analizada | Crítica (9.3) | 0.50% | — | Sangoma Freepbx | 29/5/2026 | 21/7/2026 | FreePBX is an open source IP PBX. From 15.0.42 to before 16.0.45 and 17.0.7, unauthenticated users may be able to access the User Control Panel (UCP) using hard-coded initial template credentials if these were not immediately changed by the Administrator who enabled UCP. Authenticated access to ACP is required for the… | |
| Analizada | Alta (7.6) | 0.49% | — | Sangoma Freepbx | 29/5/2026 | 21/7/2026 | FreePBX is an open source IP PBX. Prior to 16.0.22 and 17.0.5, the Dashboard module's getcontent AJAX handler includes PHP files based on user-supplied input without path sanitization. The $_REQUEST['rawname'] parameter is concatenated into an include() call with a .class.php suffix, allowing path traversal via ../… | |
| Analizada | Alta (8.5) | 0.53% | — | Sangoma Freepbx | 29/5/2026 | 21/7/2026 | FreePBX is an open source IP PBX. Prior to 16.0.50 and 17.0.11, the CDR Reports module page allows SQL injection through the order and sort POST parameters. Authentication with a FreePBX Administration Control Panel account that has CDR section access is required. Full administrator privileges are not needed. This… | |
| Analizada | Alta (7.6) | 0.35% | — | Sangoma Freepbx | 29/5/2026 | 21/7/2026 | FreePBX is an open source IP PBX. Prior to 17.0.8, the FreePBX api module's OAuth2 implementation does not sufficiently validate client credentials during token issuance. Knowledge of a valid client_id is required. The validateClient() method in ClientRepository.php unconditionally returns true, allowing any party… | |
| Aplazada | Alta (8.6) | 0.97% | — | FreepbxAI | 18/5/2026 | 24/7/2026 | FreePBX is an open source IP PBX. In versions below 16.0.71 and 17.0.6, the backup module does not properly sanitize data during restore operations, potentially leading to compromise if the backup contains carefully crafted hostile data. During backup restore operations, FreePBX extracts selected files from a… | |
| Analizada | Alta (8.6) | 2.4% | — | Freepbx API | 21/4/2026 | 14/7/2026 | FreePBX api module version 17.0.8 and prior contain a command injection vulnerability in the initiateGqlAPIProcess() function where GraphQL mutation input fields are passed directly to shell_exec() without sanitization or escaping. An authenticated user with a valid bearer token can send a GraphQL moduleOperations… | |
| Analizada | Alta (8.6) | 1.6% | — | Sangoma Freepbx | 5/3/2026 | 17/6/2026 | FreePBX is an open source IP PBX. From versions 16.0.17.2 to before 16.0.20 and from version 17.0.2.4 to before 17.0.5, multiple command injection vulnerabilities exist in the recordings module. This issue has been patched in versions 16.0.20 and 17.0.5. | |
| Analizada | Alta (8.6) | 0.46% | — | Sangoma Freepbx | 5/3/2026 | 17/6/2026 | FreePBX is an open source IP PBX. Prior to versions 16.0.10 and 17.0.5, the FreePBX logfiles module contains several authenticated SQL injection vulnerabilities. This issue has been patched in versions 16.0.10 and 17.0.5. | |
| Analizada | Alta (8.6) | 0.56% | — | Sangoma Freepbx | 5/3/2026 | 17/6/2026 | FreePBX is an open source IP PBX. Prior to versions 16.0.49 and 17.0.7, FreePBX module cdr (Call Data Record) is vulnerable to SQL query injection. This issue has been patched in versions 16.0.49 and 17.0.7. | |
| Analizada | Alta (7.5) | 1.5% | — | Sangoma Freepbx | 5/3/2026 | 17/6/2026 | FreePBX is an open source IP PBX. From versions 16.0.17.2 to before 16.0.20 and from version 17.0.2.4 to before 17.0.5, a command injection vulnerability exists in FreePBX when using the ElevenLabs Text-to-Speech (TTS) engine in the recordings module. This issue has been patched in versions 16.0.20 and 17.0.5. | |
| Analizada | Baja (2) | 0.32% | — | Sangoma Freepbx | 12/2/2026 | 17/6/2026 | FreePBX is an open-source web-based graphical user interface (GUI) that manages Asterisk. Prior to 17.0.5 and 16.0.17, FreePBX module api (PBX API) is vulnerable to privilege escalation by authenticated users with REST/GraphQL API access. This vulnerability allows an attacker to forge a valid JWT with full access to… |