Skip to content
Signals
NVD · CVE-2026-64604 · In the Linux kernel, the following vulnerability has been resolved: KVM: VMX: Grab vmcs12 on CR8 interception update iff vCPU is in guest mode When updating CR8NVD · CVE-2026-64603 · In the Linux kernel, the following vulnerability has been resolved: platform/x86: intel-hid: Protect ACPI notify handler against recursion Since commit e2ffcda1NVD · CVE-2026-64602 · In the Linux kernel, the following vulnerability has been resolved: iio: adc: spear: Initialize completion before requesting IRQ In the report from Jaeyoung ChuNVD · CVE-2026-64601 · In the Linux kernel, the following vulnerability has been resolved: ALSA: us144mkii: capture_urb_complete: redundant usb_anchor_urb corrupts anchor list on eachCISA KEV · CVE-2026-63077 · 9.8 · JetBrains TeamCity Deserialization of Untrusted Data Vulnerability · Added 2026-08-05 · Due 2026-08-08CISA KEV · CVE-2026-18556 · 7.4 · N-able N-central Authentication Bypass Using an Alternate Path or Channel Vulnerability · Added 2026-08-04 · Due 2026-08-07NVD · CVE-2026-64604 · In the Linux kernel, the following vulnerability has been resolved: KVM: VMX: Grab vmcs12 on CR8 interception update iff vCPU is in guest mode When updating CR8NVD · CVE-2026-64603 · In the Linux kernel, the following vulnerability has been resolved: platform/x86: intel-hid: Protect ACPI notify handler against recursion Since commit e2ffcda1NVD · CVE-2026-64602 · In the Linux kernel, the following vulnerability has been resolved: iio: adc: spear: Initialize completion before requesting IRQ In the report from Jaeyoung ChuNVD · CVE-2026-64601 · In the Linux kernel, the following vulnerability has been resolved: ALSA: us144mkii: capture_urb_complete: redundant usb_anchor_urb corrupts anchor list on eachCISA KEV · CVE-2026-63077 · 9.8 · JetBrains TeamCity Deserialization of Untrusted Data Vulnerability · Added 2026-08-05 · Due 2026-08-08CISA KEV · CVE-2026-18556 · 7.4 · N-able N-central Authentication Bypass Using an Alternate Path or Channel Vulnerability · Added 2026-08-04 · Due 2026-08-07

Vendors · avaya

avaya

· 5 Critical

Total CVEs

139

Critical

5

Products

158

Search All CVEs →

139

Products (158)

communication manager16 CVEsmodular messaging message storage server15 CVEss830011 CVEss870011 CVEss850011 CVEsaura communication manager10 CVEsdefinity one media server10 CVEsconverged communications server10 CVEss810010 CVEsip office9 CVEsaura system manager9 CVEsip600 media servers9 CVEssip enablement services8 CVEsintuity audix7 CVEsmessaging storage server6 CVEsaura session manager6 CVEsaura system platform6 CVEss34006 CVEsmessage networking6 CVEsiq5 CVEsaura utility services4 CVEsargent office4 CVEsmn1004 CVEsaura experience portal4 CVEsaura presence services4 CVEsintuity audix lx4 CVEsaura application enablement services4 CVEs4602sw ip phone4 CVEss87103 CVEssg2033 CVEssg2083 CVEssg53 CVEsintegrated management3 CVEsvoice portal3 CVEsmeeting exchange3 CVEsone-x3 CVEsvsu3 CVEsip soft phone3 CVEsnetwork routing3 CVEsaura conferencing3 CVEsix workforce engagement3 CVEslibsafe3 CVEscvlan3 CVEsequinox conferencing3 CVEscall management system3 CVEssg2003 CVEssession border controller for enterprise2 CVEsaura appliance virtualization platform2 CVEsaura messaging2 CVEsaura device services2 CVEsaura application server 53002 CVEsaura sip enablement services2 CVEss8300c server2 CVEsspaces2 CVEsaura voice portal2 CVEscall management system server2 CVEsproactive contact2 CVEsinteractive response2 CVEsaura orchestration designer2 CVEsmedia server2 CVEsip office contact center2 CVEsnetwork reporting1 CVEsoctelaccess server1 CVEsocteldesigner1 CVEsone-x client enablement services1 CVEsone-x communicator1 CVEsoperational analyst1 CVEsorchestration designer1 CVEsoutbound contact management1 CVEspredictive dialer system1 CVEsscopia pathfinder 10 pts1 CVEsscopia pathfinder 10 pts firmware1 CVEsscopia pathfinder 20 pts1 CVEsscopia pathfinder 20 pts firmware1 CVEssecure access link gateway1 CVEssession border controller for enterprise firmware1 CVEsspeech access1 CVEstn2602ap ip media resource 320 circuit pack1 CVEsunified communication center1 CVEsunified messenger1 CVEsvisual messenger1 CVEsvisual vector client1 CVEsvoip handset1 CVEsvpnmanager console1 CVEsvpnremote1 CVEsvsp operating system software1 CVEsvsu 1001 CVEsvsu 100001 CVEsvsu 20001 CVEsvsu 75001 CVEsweb messenger1 CVEsweblm1 CVEswireless ap-31 CVEswireless ap-41 CVEswireless ap-51 CVEswireless ap-61 CVEswireless ap-71 CVEswireless ap-81 CVEs96081 CVEs9608 firmware1 CVEs9608g1 CVEs9608g firmware1 CVEs9611g1 CVEs9611g firmware1 CVEs9621g1 CVEs9621g firmware1 CVEs9641g1 CVEs9641g firmware1 CVEs9641gs1 CVEs9641gs firmware1 CVEs96x1 ip deskphone1 CVEs96x1 ip deskphone firmware1 CVEsag2501 CVEsagent access1 CVEsaura1 CVEsaura communication manager messagint1 CVEsaura conferencing standard edition1 CVEsaura system platform firmware1 CVEsavaya aura system platform1 CVEsbasic call management system reporting desktop1 CVEsbreeze platform1 CVEsbroadcast server1 CVEscajun m770-atm1 CVEscajun p1301 CVEscajun p3301 CVEscajun p5501 CVEscajun p550r1 CVEscajun p5801 CVEscajun p8801 CVEscajun p8821 CVEscall management server supervisor1 CVEscall management system supervisor1 CVEscallback assist1 CVEscallpilot1 CVEscallvisor asai lan1 CVEscommunication server 1000 telephony manager1 CVEscomputer telephony1 CVEscontact center express1 CVEscontrol manager1 CVEscs1000e1 CVEscs1000e\/cs1000m signaling server1 CVEscs1000e\/cs1000m signaling server firmware1 CVEscs1000e firmware1 CVEscs1000m1 CVEscs1000m firmware1 CVEscsu 50001 CVEscustomer interaction express1 CVEsenterprise manager1 CVEsexpanded meet-me conferencing1 CVEsintegrated management suit1 CVEsinteraction center1 CVEsintuity lx1 CVEsip agent1 CVEsip office application server1 CVEsip office customer call reporter1 CVEsip office phone manager1 CVEsip softphone1 CVEsmessaging application server1 CVEs

Recent Vulnerabilities

View all 139
CVE-2025-49186MEDIUM 5.3

The product does not implement sufficient measures to prevent multiple failed authentication attempts within a short time frame, making it susceptible to brute-force attacks.

CVE-2025-1041CRITICAL 9.9

An improper input validation discovered in Avaya Call Management System could allow an unauthorized remote command via a specially crafted web request. Affected versions include 18.x, 19.x prior to 19.2.0.7, and 20.x prior to 20.0.1.0.

CVE-2024-12756HIGH 7.3

An HTML Injection vulnerability in Avaya Spaces may have allowed disclosure of sensitive information or modification of the page content seen by the user.

CVE-2024-12755HIGH 7.9

A Cross-Site Scripting (XSS) vulnerability in Avaya Spaces may have allowed unauthorized code execution and potential disclose of sensitive information.

CVE-2024-7480MEDIUM 4.2

An Improper access control vulnerability was found in Avaya Aura System Manager which could allow a command-line interface (CLI) user with administrative privileges to read arbitrary files on the system. Affected versions include 10.1.x.x and 10.2.x.x. Versions prior to 10.1 are end of manufacturer support.

CVE-2024-7477MEDIUM 6.5

A SQL injection vulnerability was found which could allow a command line interface (CLI) user with administrative privileges to execute arbitrary queries against the Avaya Aura System Manager database.  Affected versions include 10.1.x.x and 10.2.x.x. Versions prior to 10.1 are end of manufacturer support.

CVE-2024-4197CRITICAL 9.9

An unrestricted file upload vulnerability in Avaya IP Office was discovered that could allow remote command or code execution via the One-X component. Affected versions include all versions prior to 11.1.3.1.

CVE-2024-4196CRITICAL 10.0

An improper input validation vulnerability was discovered in Avaya IP Office that could allow remote command or code execution via a specially crafted web request to the Web Control component. Affected versions include all versions prior to 11.1.3.1.

CVE-2023-7031MEDIUM 5.7

Insecure Direct Object Reference vulnerabilities were discovered in the Avaya Aura Experience Portal Manager which may allow partial information disclosure to an authenticated non-privileged user. Affected versions include 8.0.x and 8.1.x, prior to 8.1.2 patch 0402. Versions prior to 8.0 are end of manufacturer support.

CVE-2023-3722HIGH 8.6

An OS command injection vulnerability was found in the Avaya Aura Device Services Web application which could allow remote code execution as the Web server user via a malicious uploaded file. This issue affects Avaya Aura Device Services version 8.1.4.0 and earlier.

CVE-2023-3527MEDIUM 6.8

A CSV injection vulnerability was found in the Avaya Call Management System (CMS) Supervisor web application which allows a user with administrative privileges to input crafted data which, when exported to a CSV file, may attempt arbitrary command execution on the system used to open the file by a spreadsheet software such as Microsoft Excel.  

CVE-2023-32218MEDIUM 6.1

Avaya IX Workforce Engagement v15.2.7.1195 - CWE-601: URL Redirection to Untrusted Site ('Open Redirect')

CVE-2023-31187MEDIUM 6.5

Avaya IX Workforce Engagement v15.2.7.1195 - CWE-522: Insufficiently Protected Credentials

CVE-2023-31186MEDIUM 5.3

Avaya IX Workforce Engagement v15.2.7.1195 - User Enumeration - Observable Response Discrepancy

CVE-2022-38168CRITICAL 9.1

Broken Access Control in User Authentication in Avaya Scopia Pathfinder 10 and 20 PTS version 8.3.7.0.4 allows remote unauthenticated attackers to bypass the login page, access sensitive information, and reset user passwords via URL modification.

CVE-2022-2249HIGH 7.7

Privilege escalation related vulnerabilities were discovered in Avaya Aura Communication Manager that may allow local administrative users to escalate their privileges. This issue affects Communication Manager versions 8.0.0.0 through 8.1.3.3 and 10.1.0.0.

CVE-2022-2975HIGH 7.7

A vulnerability related to weak permissions was detected in Avaya Aura Application Enablement Services web application, allowing an administrative user to modify accounts leading to execution of arbitrary code as the root user. This issue affects Application Enablement Services versions 8.0.0.0 through 8.1.3.4 and 10.1.0.0 through 10.1.0.1. Versions prior to 8.0.0.0 are end of manufacturing support and were not evaluated.

CVE-2021-25657HIGH 7.8

A privilege escalation vulnerability was discovered in Avaya IP Office Admin Lite and USB Creator that may potentially allow a local user to escalate privileges. This issue affects Admin Lite and USB Creator 11.1 Feature Pack 2 Service Pack 1 and earlier versions.

CVE-2021-25654MEDIUM 6.2

An arbitrary code execution vulnerability was discovered in Avaya Aura Device Services that may potentially allow a local user to execute specially crafted scripts. Affects 7.0 through 8.1.4.0 versions of Avaya Aura Device Services.

CVE-2021-25656MEDIUM 5.3

Stored XSS injection vulnerabilities were discovered in the Avaya Aura Experience Portal Web management which could allow an authenticated user to potentially disclose sensitive information. Affected versions include 7.0 through 7.2.3 (without hotfix) and 8.0.0 (without hotfix).

CVE-2021-25655MEDIUM 4.4

A vulnerability in the system Service Menu component of Avaya Aura Experience Portal may allow URL Redirection to any untrusted site through a crafted attack. Affected versions include 7.0 through 7.2.3 (without hotfix) and 8.0.0 (without hotfix).

CVE-2021-25653HIGH 8.0

A privilege escalation vulnerability was discovered in Avaya Aura Appliance Virtualization Platform Utilities (AVPU) that may potentially allow a local user to escalate privileges. Affects 8.0.0.0 through 8.1.3.1 versions of AVPU.

CVE-2021-25652MEDIUM 4.9

An information disclosure vulnerability was discovered in the directory and file management of Avaya Aura Appliance Virtualization Platform Utilities (AVPU). This vulnerability may potentially allow any local user to access system functionality and configuration information that should only be available to a privileged user. Affects versions 8.0.0.0 through 8.1.3.1 of AVPU.

CVE-2021-25651HIGH 8.0

A privilege escalation vulnerability was discovered in Avaya Aura Utility Services that may potentially allow a local user to escalate privileges. Affects all 7.x versions of Avaya Aura Utility Services

CVE-2021-25650HIGH 7.7

A privilege escalation vulnerability was discovered in Avaya Aura Utility Services that may potentially allow a local user to execute specially crafted scripts as a privileged user. Affects all 7.x versions of Avaya Aura Utility Services