Skip to main content

Vendor/product archive

mitel / micollab CVEs

Beta · best-effort

47 CVEs tagged to mitel / micollab11 Critical, 11 High, 23 Medium, 2 Low, 0 Unrated.

CVE-2025-52914

Published Aug 8, 2025

A vulnerability in the Suite Applications Services component of Mitel MiCollab 10.0 through SP1 FP1 (10.0.1.101) could allow an authenticated attacker to conduct a SQL Injection a…

CVSS 8.8 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2024-55550

Published Dec 10, 2024

Mitel MiCollab through 9.8 SP2 could allow an authenticated attacker with administrative privilege to conduct a local file read, due to insufficient input sanitization. A successf…

CVSS 2.7 · Low
evidence mentions
7
Buzz score
55.3
KEV listed
Vendor/product tagsBeta · best-effort

CVE-2024-47224

Published Oct 21, 2024

A vulnerability in the AWV (Audio, Web and Video Conferencing) component of Mitel MiCollab through 9.8 SP1 FP2 (9.8.1.201) could allow an unauthenticated attacker to conduct a CRL…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-41713

Published Oct 21, 2024

A vulnerability in the NuPoint Unified Messaging (NPM) component of Mitel MiCollab through 9.8 SP1 FP2 (9.8.1.201) could allow an unauthenticated attacker to conduct a path traver…

CVSS 9.1 · Critical
evidence mentions
12
Buzz score
60.1
KEV listed
Vendor/product tagsBeta · best-effort

CVE-2024-41712

Published Oct 21, 2024

A vulnerability in the Web Conferencing Component of Mitel MiCollab through 9.8.1.5 could allow an authenticated attacker to conduct a command injection attack, due to insufficien…

CVSS 6.6 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-35287

Published Oct 21, 2024

A vulnerability in the NuPoint Messenger (NPM) component of Mitel MiCollab through version 9.8 SP1 (9.8.1.5) could allow an authenticated attacker with administrative privilege to…

CVSS 6.7 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-35286

Published Oct 21, 2024

A vulnerability in NuPoint Messenger (NPM) of Mitel MiCollab through 9.8.0.33 allows an unauthenticated attacker to conduct a SQL injection attack due to insufficient sanitization…

CVSS 9.8 · Critical
evidence mentions
2
Buzz score
17.5
Vendor/product tagsBeta · best-effort

CVE-2024-35285

Published Oct 21, 2024

A vulnerability in NuPoint Messenger (NPM) of Mitel MiCollab through 9.8.0.33 allows an unauthenticated attacker to conduct a command injection attack due to insufficient paramete…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2024-30160

Published Oct 21, 2024

A vulnerability in the Suite Applications Services component of Mitel MiCollab through 9.7.1.110 could allow an authenticated attacker with administrative privileges to conduct a…

CVSS 4.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-30159

Published Oct 21, 2024

A vulnerability in the web conferencing component of Mitel MiCollab through 9.7.1.110 could allow an authenticated attacker with administrative privileges to conduct a Stored Cros…

CVSS 4.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-30158

Published Oct 21, 2024

A vulnerability in the web conferencing component of Mitel MiCollab through 9.7.1.110 could allow an authenticated attacker with administrative privileges to conduct a SQL Injecti…

CVSS 7.2 · High
Vendor/product tagsBeta · best-effort

CVE-2024-30157

Published Oct 21, 2024

A vulnerability in the Suite Applications Services component of Mitel MiCollab through 9.7.1.110 could allow an authenticated attacker with administrative privileges to conduct a…

CVSS 7.2 · High
Vendor/product tagsBeta · best-effort

CVE-2024-47912

Published Oct 21, 2024

A vulnerability in the AWV (Audio, Web, and Video) Conferencing component of Mitel MiCollab through 9.8 SP1 FP2 (9.8.1.201) could allow an unauthenticated attacker to perform unau…

CVSS 8.2 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2024-47223

Published Oct 21, 2024

A vulnerability in the AWV (Audio, Web and Video Conferencing) component of Mitel MiCollab through 9.8 SP1 FP2 (9.8.1.201) could allow an unauthenticated attacker to conduct a SQL…

CVSS 9.4 · Critical
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2024-47189

Published Oct 21, 2024

The API Interface of the AWV (Audio, Web and Video Conferencing) component of Mitel MiCollab through 9.8 SP1 FP2 (9.8.1.201) could allow an unauthenticated attacker to conduct SQL…

CVSS 7.7 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2023-25597

Published Apr 14, 2023

A vulnerability in the web conferencing component of Mitel MiCollab through 9.6.2.9 could allow an unauthenticated attacker to download a shared file via a crafted request - inclu…

CVSS 5.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-41326

Published Nov 22, 2022

The web conferencing component of Mitel MiCollab through 9.6.0.13 could allow an unauthenticated attacker to upload arbitrary scripts due to improper authorization controls. A suc…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2022-36452

Published Oct 25, 2022

A vulnerability in the web conferencing component of Mitel MiCollab through 9.5.0.101 could allow an unauthenticated attacker to upload malicious files. A successful exploit could…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2022-36454

Published Oct 25, 2022

A vulnerability in the MiCollab Client API of Mitel MiCollab through 9.5.0.101 could allow an authenticated attacker to modify their profile parameters due to improper authorizati…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-36453

Published Oct 25, 2022

A vulnerability in the MiCollab Client API of Mitel MiCollab 9.1.3 through 9.5.0.101 could allow an authenticated attacker to modify their profile parameters due to improper autho…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2022-36451

Published Oct 25, 2022

A vulnerability in the MiCollab Client server component of Mitel MiCollab through 9.5.0.101 could allow an authenticated attacker to conduct a Server-Side Request Forgery (SSRF) a…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2022-26143

Published Mar 10, 2022

The TP-240 (aka tp240dvr) component in Mitel MiCollab before 9.4 SP1 FP1 and MiVoice Business Express through 8.1 allows remote attackers to obtain sensitive information and cause…

CVSS 9.8 · Critical
evidence mentions
5
Buzz score
50.9
KEV listed
Vendor/product tagsBeta · best-effort
Showing 1-25 of 47 CVEsPage 1 of 2