Cisco / Unity Connection
65 CVEs
| CVE ID | Description | Severity | CVSS | Published |
|---|---|---|---|---|
| CVE-2026-20034 | Cisco Unity Connection Remote Code Execution Vulnerability | HIGH | 8.8 | May 6, 2026 |
| CVE-2026-20035 | Cisco Unity Connection Server-Side Request Forgery Vulnerability | HIGH | 7.2 | May 6, 2026 |
| CVE-2026-20059 | Cisco Unity Connection Reflected Cross-Site Scripting Vulnerability | MEDIUM | 6.1 | Apr 15, 2026 |
| CVE-2026-20061 | Cisco Unity Connection SQL Injection Vulnerability | MEDIUM | 6.5 | Apr 15, 2026 |
| CVE-2026-20060 | Cisco Unity Connection Open Redirect Vulnerability | MEDIUM | 4.7 | Apr 15, 2026 |
| CVE-2026-20081 | Cisco Unity Connection Arbitrary File Download Vulnerability | MEDIUM | 6.5 | Apr 15, 2026 |
| CVE-2026-20078 | Cisco Unity Connection Arbitrary File Download Vulnerability | MEDIUM | 6.5 | Apr 15, 2026 |
| CVE-2026-20045 KEV | Cisco Unified Communications Products Remote Code Execution Vulnerability | CRITICAL | 9.8 | Jan 21, 2026 |
| CVE-2025-20278 | Cisco Unified Communications Products Command Injection Vulnerability | MEDIUM | 6.7 | Jun 4, 2025 |
| CVE-2024-20253 | A vulnerability in multiple Cisco Unified Communications and Contact Center Solutions products could allow an unauthenticated, remote attacker to execute arbit… | CRITICAL | 10.0 | Jan 26, 2024 |
| CVE-2024-20305 | A vulnerability in the web-based management interface of Cisco Unity Connection could allow an authenticated, remote attacker to conduct a cross-site scripting… | MEDIUM | 4.8 | Jan 26, 2024 |
| CVE-2024-20272 | A vulnerability in the web-based management interface of Cisco Unity Connection could allow an unauthenticated, remote attacker to upload arbitrary files to an… | CRITICAL | 9.8 | Jan 17, 2024 |
| CVE-2023-20259 | A vulnerability in an API endpoint of multiple Cisco Unified Communications Products could allow an unauthenticated, remote attacker to cause high CPU utilizat… | HIGH | 8.6 | Oct 4, 2023 |
| CVE-2023-20266 | A vulnerability in Cisco Emergency Responder, Cisco Unified Communications Manager (Unified CM), Cisco Unified Communications Manager Session Management Editio… | HIGH | 7.2 | Aug 30, 2023 |
| CVE-2022-20859 | Cisco Unified Communications Products Access Control Vulnerability | HIGH | 8.8 | Jul 6, 2022 |
| CVE-2022-20800 | Cisco Unified Communications Products Cross-Site Scripting Vulnerability | MEDIUM | 6.1 | Jul 6, 2022 |
| CVE-2022-20752 | Cisco Unified Communications Products Timing Attack Vulnerability | MEDIUM | 5.3 | Jul 6, 2022 |
| CVE-2022-20788 | Cisco Unified Communications Products Cross-Site Scripting Vulnerability | MEDIUM | 6.1 | Apr 21, 2022 |
| CVE-2021-44228 KEV | Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints | CRITICAL | 10.0 | Dec 10, 2021 |
| CVE-2021-34701 | Cisco Unified Communications Products Path Traversal Vulnerability | MEDIUM | 4.3 | Nov 4, 2021 |
| CVE-2021-1409 | Cisco Unified Communications Products Cross-Site Scripting Vulnerabilities | MEDIUM | 6.1 | Apr 8, 2021 |
| CVE-2021-1380 | Cisco Unified Communications Products Cross-Site Scripting Vulnerabilities | MEDIUM | 6.1 | Apr 8, 2021 |
| CVE-2021-1362 | Cisco Unified Communications Products Remote Code Execution Vulnerability | HIGH | 8.8 | Apr 8, 2021 |
| CVE-2021-1226 | Cisco Unified Communications Products Information Disclosure Vulnerability | MEDIUM | 6.5 | Jan 13, 2021 |
| CVE-2020-3130 | Cisco Unity Connection Directory Traversal Vulnerability | MEDIUM | 6.5 | Sep 23, 2020 |
Showing 1 to 25 of 65 CVEs