Mitel / Micollab
48 CVEs
| CVE ID | Description | Severity | CVSS | Published |
|---|---|---|---|---|
| CVE-2025-52914 | A vulnerability in the Suite Applications Services component of Mitel MiCollab 10.0 through SP1 FP1 (10.0.1.101) could allow an authenticated attacker to condu… | HIGH | 8.8 | Aug 8, 2025 |
| CVE-2024-55550 KEV | Mitel MiCollab through 9.8 SP2 could allow an authenticated attacker with administrative privilege to conduct a local file read, due to insufficient input sani… | MEDIUM | 4.4 | Dec 10, 2024 |
| CVE-2024-47912 | A vulnerability in the AWV (Audio, Web, and Video) Conferencing component of Mitel MiCollab through 9.8 SP1 FP2 (9.8.1.201) could allow an unauthenticated atta… | HIGH | 8.2 | Oct 21, 2024 |
| CVE-2024-47224 | A vulnerability in the AWV (Audio, Web and Video Conferencing) component of Mitel MiCollab through 9.8 SP1 FP2 (9.8.1.201) could allow an unauthenticated attac… | MEDIUM | 6.5 | Oct 21, 2024 |
| CVE-2024-47223 | A vulnerability in the AWV (Audio, Web and Video Conferencing) component of Mitel MiCollab through 9.8 SP1 FP2 (9.8.1.201) could allow an unauthenticated attac… | CRITICAL | 9.4 | Oct 21, 2024 |
| CVE-2024-47189 | The API Interface of the AWV (Audio, Web and Video Conferencing) component of Mitel MiCollab through 9.8 SP1 FP2 (9.8.1.201) could allow an unauthenticated att… | HIGH | 7.7 | Oct 21, 2024 |
| CVE-2024-41714 | A vulnerability in the Web Interface component of Mitel MiCollab through 9.8 SP1 (9.8.1.5) and MiVoice Business Solution Virtual Instance (MiVB SVI) through 1.… | HIGH | 8.8 | Oct 21, 2024 |
| CVE-2024-41713 KEV | A vulnerability in the NuPoint Unified Messaging (NPM) component of Mitel MiCollab through 9.8 SP1 FP2 (9.8.1.201) could allow an unauthenticated attacker to c… | CRITICAL | 9.1 | Oct 21, 2024 |
| CVE-2024-41712 | A vulnerability in the Web Conferencing Component of Mitel MiCollab through 9.8.1.5 could allow an authenticated attacker to conduct a command injection attack… | MEDIUM | 6.6 | Oct 21, 2024 |
| CVE-2024-35315 | A vulnerability in the Desktop Client of Mitel MiCollab through 9.7.1.110, and MiVoice Business Solution Virtual Instance (MiVB SVI) 1.0.0.25, could allow an a… | MEDIUM | 5.6 | Oct 21, 2024 |
| CVE-2024-35314 | A vulnerability in the Desktop Client of Mitel MiCollab through 9.7.1.110, and MiVoice Business Solution Virtual Instance (MiVB SVI) 1.0.0.25, could allow an u… | CRITICAL | 9.8 | Oct 21, 2024 |
| CVE-2024-35287 | A vulnerability in the NuPoint Messenger (NPM) component of Mitel MiCollab through version 9.8 SP1 (9.8.1.5) could allow an authenticated attacker with adminis… | MEDIUM | 6.7 | Oct 21, 2024 |
| CVE-2024-35286 | A vulnerability in NuPoint Messenger (NPM) of Mitel MiCollab through 9.8.0.33 allows an unauthenticated attacker to conduct a SQL injection attack due to insuf… | CRITICAL | 9.8 | Oct 21, 2024 |
| CVE-2024-35285 | A vulnerability in NuPoint Messenger (NPM) of Mitel MiCollab through 9.8.0.33 allows an unauthenticated attacker to conduct a command injection attack due to i… | CRITICAL | 9.8 | Oct 21, 2024 |
| CVE-2024-30160 | A vulnerability in the Suite Applications Services component of Mitel MiCollab through 9.7.1.110 could allow an authenticated attacker with administrative priv… | MEDIUM | 4.8 | Oct 21, 2024 |
| CVE-2024-30159 | A vulnerability in the web conferencing component of Mitel MiCollab through 9.7.1.110 could allow an authenticated attacker with administrative privileges to c… | MEDIUM | 4.8 | Oct 21, 2024 |
| CVE-2024-30158 | A vulnerability in the web conferencing component of Mitel MiCollab through 9.7.1.110 could allow an authenticated attacker with administrative privileges to c… | HIGH | 7.2 | Oct 21, 2024 |
| CVE-2024-30157 | A vulnerability in the Suite Applications Services component of Mitel MiCollab through 9.7.1.110 could allow an authenticated attacker with administrative priv… | HIGH | 7.2 | Oct 21, 2024 |
| CVE-2023-25597 | A vulnerability in the web conferencing component of Mitel MiCollab through 9.6.2.9 could allow an unauthenticated attacker to download a shared file via a cra… | MEDIUM | 5.9 | Apr 14, 2023 |
| CVE-2022-41326 | The web conferencing component of Mitel MiCollab through 9.6.0.13 could allow an unauthenticated attacker to upload arbitrary scripts due to improper authoriza… | CRITICAL | 9.8 | Nov 22, 2022 |
| CVE-2022-36454 | A vulnerability in the MiCollab Client API of Mitel MiCollab through 9.5.0.101 could allow an authenticated attacker to modify their profile parameters due to… | MEDIUM | 6.5 | Oct 25, 2022 |
| CVE-2022-36453 | A vulnerability in the MiCollab Client API of Mitel MiCollab 9.1.3 through 9.5.0.101 could allow an authenticated attacker to modify their profile parameters d… | HIGH | 8.8 | Oct 25, 2022 |
| CVE-2022-36452 | A vulnerability in the web conferencing component of Mitel MiCollab through 9.5.0.101 could allow an unauthenticated attacker to upload malicious files. A succ… | CRITICAL | 9.8 | Oct 25, 2022 |
| CVE-2022-36451 | A vulnerability in the MiCollab Client server component of Mitel MiCollab through 9.5.0.101 could allow an authenticated attacker to conduct a Server-Side Requ… | HIGH | 8.8 | Oct 25, 2022 |
| CVE-2022-26143 KEV | The TP-240 (aka tp240dvr) component in Mitel MiCollab before 9.4 SP1 FP1 and MiVoice Business Express through 8.1 allows remote attackers to obtain sensitive i… | CRITICAL | 9.8 | Mar 9, 2022 |
Showing 1 to 25 of 48 CVEs