CVEInsight.
TrendingZero-DayExploreBrowseSearchSaved
CVEInsight.

Free vulnerability intelligence for developers, security teams, and researchers. Data sourced from public databases for informational purposes only.

Explore

HomeTrendingZero-Day WatchAttack TypesBrowse CVEsSearch

Legal

Privacy PolicyTerms of ServiceData Disclaimer

© 2026CVEInsight. For informational use only — not a substitute for professional security advice.

CVE data sourced from NVD / NIST & public disclosures.

Search Vulnerabilities

 Software

Searching vulnerabilities affecting “avaya”

52 vulnerabilities found for “avaya”

Page 1 of 3

CVE-2025-49186
MEDIUM5.3

The product does not implement sufficient measures to prevent multiple failed authentication attempts within a short time frame, making it susceptible to brute-force attacks.

avaya / media_server+5
Network
Published Jun 12, 2025
Page 1 of 3
CVE-2024-7480
MEDIUM4.2

An Improper access control vulnerability was found in Avaya Aura System Manager which could allow a command-line interface (CLI) user with administrative privileges to read arbitrary files on the system. Affected versions include 10.1.x.x and 10.2.x.x. Versions prior to 10.1 are end of manufacturer support.

avaya / aura_system_manager+1
Local
Published Aug 8, 2024
CVE-2024-7477
MEDIUM6.5

A SQL injection vulnerability was found which could allow a command line interface (CLI) user with administrative privileges to execute arbitrary queries against the Avaya Aura System Manager database.  Affected versions include 10.1.x.x and 10.2.x.x. Versions prior to 10.1 are end of manufacturer support.

avaya / aura_system_manager+1
Local
Published Aug 8, 2024
CVE-2023-3722
HIGH8.6

An OS command injection vulnerability was found in the Avaya Aura Device Services Web application which could allow remote code execution as the Web server user via a malicious uploaded file. This issue affects Avaya Aura Device Services version 8.1.4.0 and earlier.

avaya / aura_device_services
Network
Published Jul 19, 2023
CVE-2023-31186
MEDIUM5.3

Avaya IX Workforce Engagement v15.2.7.1195 - User Enumeration - Observable Response Discrepancy

avaya / ix_workforce_engagement
Network
Published May 30, 2023
CVE-2023-31187
MEDIUM6.5

Avaya IX Workforce Engagement v15.2.7.1195 - CWE-522: Insufficiently Protected Credentials

avaya / ix_workforce_engagement
Network
Published May 30, 2023
CVE-2023-32218
MEDIUM6.1

Avaya IX Workforce Engagement v15.2.7.1195 - CWE-601: URL Redirection to Untrusted Site ('Open Redirect')

avaya / ix_workforce_engagement
Network
Published May 30, 2023
CVE-2022-2975
HIGH7.7

A vulnerability related to weak permissions was detected in Avaya Aura Application Enablement Services web application, allowing an administrative user to modify accounts leading to execution of arbitrary code as the root user. This issue affects Application Enablement Services versions 8.0.0.0 through 8.1.3.4 and 10.1.0.0 through 10.1.0.1. Versions prior to 8.0.0.0 are end of manufacturing support and were not evaluated.

avaya / aura_application_enablement_services+1
Local
Published Oct 6, 2022
CVE-2021-25654
MEDIUM6.2

An arbitrary code execution vulnerability was discovered in Avaya Aura Device Services that may potentially allow a local user to execute specially crafted scripts. Affects 7.0 through 8.1.4.0 versions of Avaya Aura Device Services.

avaya / aura_device_services
Network
Published Jun 25, 2021
CVE-2021-25649
MEDIUM4.9

An information disclosure vulnerability was discovered in the directory and file management of Avaya Aura Utility Services. This vulnerability may potentially allow any local user to access system functionality and configuration information that should only be available to a privileged user. Affects all 7.x versions of Avaya Aura Utility Services

avaya / aura_utility_services
Network
Published Jun 24, 2021
CVE-2021-25650
HIGH7.7

A privilege escalation vulnerability was discovered in Avaya Aura Utility Services that may potentially allow a local user to execute specially crafted scripts as a privileged user. Affects all 7.x versions of Avaya Aura Utility Services

avaya / aura_utility_services
Network
Published Jun 24, 2021
CVE-2021-25653
HIGH8.0

A privilege escalation vulnerability was discovered in Avaya Aura Appliance Virtualization Platform Utilities (AVPU) that may potentially allow a local user to escalate privileges. Affects 8.0.0.0 through 8.1.3.1 versions of AVPU.

avaya / aura_appliance_virtualization_platform
Network
Published Jun 24, 2021
CVE-2021-25652
MEDIUM4.9

An information disclosure vulnerability was discovered in the directory and file management of Avaya Aura Appliance Virtualization Platform Utilities (AVPU). This vulnerability may potentially allow any local user to access system functionality and configuration information that should only be available to a privileged user. Affects versions 8.0.0.0 through 8.1.3.1 of AVPU.

avaya / aura_appliance_virtualization_platform
Network
Published Jun 24, 2021
CVE-2021-25651
HIGH8.0

A privilege escalation vulnerability was discovered in Avaya Aura Utility Services that may potentially allow a local user to escalate privileges. Affects all 7.x versions of Avaya Aura Utility Services

avaya / aura_utility_services
Network
Published Jun 24, 2021
CVE-2020-7032
MEDIUM6.5

An XML external entity (XXE) vulnerability in Avaya WebLM admin interface allows authenticated users to read arbitrary files or conduct server-side request forgery (SSRF) attacks via a crafted DTD in an XML request. Affected versions of Avaya WebLM include: 7.0 through 7.1.3.6 and 8.0 through 8.1.2.

avaya / aura_system_manager+3
Network
Published Nov 13, 2020
CVE-2019-7004
MEDIUM5.4

A Cross-Site Scripting (XSS) vulnerability in the WebUI component of IP Office Application Server could allow unauthorized code execution and potentially disclose sensitive information. All product versions 11.x are affected. Product versions prior to 11.0, including unsupported versions, were not evaluated.

avaya / ip_office_application_server
Network
Published Dec 12, 2019
CVE-2016-5285
HIGH7.5

A Null pointer dereference vulnerability exists in Mozilla Network Security Services due to a missing NULL check in PK11_SignWithSymKey / ssl3_ComputeRecordMACConstantTime, which could let a remote malicious user cause a Denial of Service.

mozilla / nss+98
Network
Published Nov 15, 2019
CVE-2019-7003
CRITICAL10.0

A SQL injection vulnerability in the reporting component of Avaya Control Manager could allow an unauthenticated attacker to execute arbitrary SQL commands and retrieve sensitive data related to other users on the system. Affected versions of Avaya Control Manager include 7.x and 8.0.x versions prior to 8.0.4.0. Unsupported versions not listed here were not evaluated.

avaya / control_manager
Network
Published Jul 11, 2019
CVE-2019-7001
CRITICAL9.9

A SQL injection vulnerability in the WebUI component of IP Office Contact Center could allow an authenticated attacker to retrieve or alter sensitive data related to other users on the system. Affected versions of IP Office Contact Center include all 9.x and 10.x versions prior to 10.1.2.2.2-11201.1908. Unsupported versions not listed here were not evaluated.

avaya / ip_office_contact_center+1
Network
Published Apr 4, 2019
CVE-2018-15615
HIGH7.2

A vulnerability in the Supervisor component of Avaya Call Management System allows local administrative user to extract sensitive information from users connecting to a remote CMS host. Affected versions of CMS Supervisor include R17.0.x and R18.0.x.

avaya / call_management_system_supervisor+2
Local
Published Sep 24, 2018