Products › End-user applications
End-user applications
Collaboration, telephony and video conferencing
Intranets, wikis, teamwork tools, IP telephony and video conferencing.
For example: SharePoint, Confluence, Mitel, FreePBX.
-
17 vulnerabilities added in the last 12 months
-
53 exploited vulnerabilities in the catalog, in total
-
1 added in the last 30 days
Pace of additions
| Period | Vulnerabilities added |
|---|---|
| Sep 9, 2025 to Oct 8, 2025 | 0 |
| Oct 9, 2025 to Nov 7, 2025 | 1 |
| Nov 8, 2025 to Dec 7, 2025 | 0 |
| Dec 8, 2025 to Jan 6, 2026 | 0 |
| Jan 7, 2026 to Feb 5, 2026 | 3 |
| Feb 6, 2026 to Mar 7, 2026 | 0 |
| Mar 8, 2026 to Apr 6, 2026 | 2 |
| Apr 7, 2026 to May 6, 2026 | 1 |
| May 7, 2026 to Jun 5, 2026 | 0 |
| Jun 6, 2026 to Jul 5, 2026 | 2 |
| Jul 6, 2026 to Aug 4, 2026 | 3 |
| Aug 5, 2026 to Sep 3, 2026 | 4 |
| Sep 4, 2026 to Oct 3, 2026 (in progress) | 1 |
Affected brands
In alphabetical order, with their number of vulnerabilities in this category.
- Alcatel-Lucent Enterprise 1 vulnerability
- Atlassian 11 vulnerabilities
- Cisco 3 vulnerabilities · 2 in the last 12 months
- Fortinet 1 vulnerability
- Grandstream 1 vulnerability
- Ignite Realtime 1 vulnerability
- Microsoft 17 vulnerabilities · 8 in the last 12 months
- Mitel 7 vulnerabilities
- PlaySMS 1 vulnerability
- Sangoma 4 vulnerabilities · 3 in the last 12 months
- Srimax 1 vulnerability
- TrueConf 3 vulnerabilities · 3 in the last 12 months
- XWiki 1 vulnerability · 1 in the last 12 months
- Yealink 1 vulnerability
A high count also reflects how widely a product is deployed and how much attackers care about it: it is not a security rating.
See also
- Email 71 vulnerabilities
Patch first
In the order of the main list (Patch first): recent additions first, then the most severe. The number is the rank within this category.
- Rank 1
Microsoft SharePoint ServerCVE-2026-65660
Microsoft SharePoint Code Injection Vulnerability
Recently addedHunt for compromise (CISA)
CVSS severity 8.8high
Added Sep 25, 2026
- Rank 2
Sangoma SwitchvoxCVE-2026-9586
Sangoma Switchvox SQL Injection Vulnerability
Hunt for compromise (CISA)
CVSS severity 9.8critical
Added Sep 2, 2026
- Rank 3
TrueConf ServerCVE-2026-72529
TrueConf Server Missing Authentication for Critical Function Vulnerability
Hunt for compromise (CISA)
CVSS severity 9.8critical
Added Aug 20, 2026
- Rank 4
Microsoft SharePoint ServerCVE-2026-50522
Microsoft SharePoint Deserialization of Untrusted Data Vulnerability
Hunt for compromise (CISA)
CVSS severity 9.8critical
Added Jul 22, 2026
- Rank 5
Microsoft SharePoint ServerCVE-2026-58644
Microsoft SharePoint Deserialization of Untrusted Data Vulnerability
Hunt for compromise (CISA)
CVSS severity 9.8critical
Added Jul 16, 2026
- Rank 6
Microsoft SharePoint ServerCVE-2026-56164
Microsoft SharePoint Server Missing Authentication for Critical Function Vulnerability
Hunt for compromise (CISA)
CVSS severity 9.8critical
Added Jul 14, 2026
- Rank 7
Microsoft SharePoint ServerCVE-2026-20963
Microsoft SharePoint Deserialization of Untrusted Data Vulnerability
CVSS severity 9.8critical
Added Mar 18, 2026
- Rank 8
Sangoma FreePBXCVE-2019-19006
Sangoma FreePBX Improper Authentication Vulnerability
CVE from 2019, added in 2026
CVSS severity 9.8critical
Added Feb 3, 2026
- Rank 9
Cisco Unified Communications ManagerCVE-2026-20045
Cisco Unified Communications Products Code Injection Vulnerability
CVSS severity 9.8critical
Added Jan 21, 2026
- Rank 10
XWiki PlatformCVE-2025-24893
XWiki Platform Eval Injection Vulnerability
CVSS severity 9.8critical
Added Oct 30, 2025
Show 43 more vulnerabilities
- Rank 11
Microsoft SharePoint ServerCVE-2026-55040
Microsoft SharePoint Weak Authentication Vulnerability
Hunt for compromise (CISA)
CVSS severity 9.1critical
Added Aug 18, 2026
- Rank 12
TrueConf ServerCVE-2026-72530
TrueConf Server Code Injection Vulnerability
CVSS severity 9.0critical
Added Aug 20, 2026
- Rank 13
Microsoft SharePoint ServerCVE-2026-45659
Microsoft SharePoint Server Deserialization of Untrusted Data Vulnerability
Hunt for compromise (CISA)Ransomware
CVSS severity 8.8high
Added Jul 1, 2026
- Rank 14
Cisco Unified Communications ManagerCVE-2026-20230
Cisco Unified Communications Manager Server-Side Request Forgery (SSRF) Vulnerability
CVSS severity 8.6high
Added Jun 25, 2026
- Rank 15
TrueConf ClientCVE-2026-3502
TrueConf Client Download of Code Without Integrity Check Vulnerability
CVSS severity 7.8high
Added Apr 2, 2026
- Rank 16
Sangoma FreePBXCVE-2025-64328
Sangoma FreePBX OS Command Injection Vulnerability
CVSS severity 7.2high
Added Feb 3, 2026
- Rank 17
Microsoft SharePoint ServerCVE-2026-32201
Microsoft SharePoint Server Improper Input Validation Vulnerability
CVSS severity 6.5medium
Added Apr 14, 2026
- Rank 18
Sangoma FreePBXCVE-2025-57819
Sangoma FreePBX Authentication Bypass Vulnerability
CVSS severity 9.8critical
Added Aug 29, 2025
- Rank 19
Microsoft SharePoint ServerCVE-2025-53770
Microsoft SharePoint Deserialization of Untrusted Data Vulnerability
Ransomware
CVSS severity 9.8critical
Added Jul 20, 2025
- Rank 20
Fortinet FortiVoice / FortiFoneCVE-2025-32756
Fortinet Multiple Products Stack-Based Buffer Overflow Vulnerability
CVSS severity 9.8critical
Added May 14, 2025
- Rank 21
Atlassian Confluence Server / Data CenterCVE-2023-22527
Atlassian Confluence Data Center and Server Template Injection Vulnerability
Ransomware
CVSS severity 9.8critical
Added Jan 24, 2024
- Rank 22
Microsoft SharePoint ServerCVE-2023-29357
Microsoft SharePoint Server Privilege Escalation Vulnerability
Ransomware
CVSS severity 9.8critical
Added Jan 10, 2024
- Rank 23
Atlassian Confluence Server / Data CenterCVE-2023-22518
Atlassian Confluence Data Center and Server Improper Authorization Vulnerability
Ransomware
CVSS severity 9.8critical
Added Nov 7, 2023
- Rank 24
Atlassian Confluence Server / Data CenterCVE-2023-22515
Atlassian Confluence Data Center and Server Broken Access Control Vulnerability
Ransomware
CVSS severity 9.8critical
Added Oct 5, 2023
- Rank 25
Atlassian Confluence Server / Data CenterCVE-2022-26138
Atlassian Questions For Confluence App Hard-coded Credentials Vulnerability
CVSS severity 9.8critical
Added Jul 29, 2022
- Rank 26
Mitel MiVoice ConnectCVE-2022-29499
Mitel MiVoice Connect Data Validation Vulnerability
Ransomware
CVSS severity 9.8critical
Added Jun 27, 2022
- Rank 27
Atlassian Confluence Server / Data CenterCVE-2022-26134
Atlassian Confluence Server and Data Center Remote Code Execution Vulnerability
Ransomware
CVSS severity 9.8critical
Added Jun 2, 2022
- Rank 28
Alcatel-Lucent Enterprise OmniPCX EnterpriseCVE-2007-3010
Alcatel OmniPCX Enterprise Remote Code Execution Vulnerability
CVE from 2007, added in 2022
CVSS severity 9.8critical
Added Apr 15, 2022
- Rank 29
Mitel MiCollabCVE-2022-26143
MiCollab, MiVoice Business Express Access Control Vulnerability
CVSS severity 9.8critical
Added Mar 25, 2022
- Rank 30
Atlassian Jira Server / Data CenterCVE-2019-11581
Atlassian Jira Server and Data Center Server-Side Template Injection Vulnerability
CVE from 2019, added in 2022
CVSS severity 9.8critical
Added Mar 7, 2022
- Rank 31
Grandstream UCM6200CVE-2020-5722
Grandstream Networks UCM6200 Series SQL Injection Vulnerability
CVE from 2020, added in 2022
CVSS severity 9.8critical
Added Jan 28, 2022
- Rank 32
Microsoft SharePoint ServerCVE-2019-0604
Microsoft SharePoint Remote Code Execution Vulnerability
RansomwareCVE from 2019, added in 2021
CVSS severity 9.8critical
Added Nov 3, 2021
- Rank 33
Atlassian Confluence Server / Data CenterCVE-2019-3396
Atlassian Confluence Server and Data Center Server-Side Template Injection Vulnerability
RansomwareCVE from 2019, added in 2021
CVSS severity 9.8critical
Added Nov 3, 2021
- Rank 34
Cisco IP PhonesCVE-2020-3161
Cisco IP Phones Web Server Remote Code Execution and Denial-of-Service Vulnerability
CVSS severity 9.8critical
Added Nov 3, 2021
- Rank 35
PlaySMSCVE-2020-8644
PlaySMS Server-Side Template Injection Vulnerability
CVSS severity 9.8critical
Added Nov 3, 2021
- Rank 36
Atlassian Confluence Server / Data CenterCVE-2021-26084
Atlassian Confluence Server and Data Center Object-Graph Navigation Language (OGNL) Injection Vulnerability
Ransomware
CVSS severity 9.8critical
Added Nov 3, 2021
- Rank 37
Yealink Device ManagementCVE-2021-27561
Yealink Device Management Server-Side Request Forgery (SSRF) Vulnerability
CVSS severity 9.8critical
Added Nov 3, 2021
- Rank 38
Mitel MiCollabCVE-2024-41713
Mitel MiCollab Path Traversal Vulnerability
Ransomware
CVSS severity 9.1critical
Added Jan 7, 2025
- Rank 39
Microsoft SharePoint ServerCVE-2025-49704
Microsoft SharePoint Code Injection Vulnerability
Ransomware
CVSS severity 8.8high
Added Jul 22, 2025
- Rank 40
Srimax Output MessengerCVE-2025-27920
Srimax Output Messenger Directory Traversal Vulnerability
CVSS severity 8.8high
Added May 19, 2025
- Rank 41
Atlassian Confluence Server / Data CenterCVE-2019-3398
Atlassian Confluence Server and Data Center Path Traversal Vulnerability
CVE from 2019, added in 2021
CVSS severity 8.8high
Added Nov 3, 2021
- Rank 42
Microsoft SharePoint ServerCVE-2020-1147
Microsoft .NET Framework, SharePoint, and Visual Studio Remote Code Execution Vulnerability
CVSS severity 7.8high
Added Nov 3, 2021
- Rank 43
Ignite Realtime OpenfireCVE-2023-32315
Ignite Realtime Openfire Path Traversal Vulnerability
CVSS severity 7.5high
Added Aug 24, 2023
- Rank 44
Mitel SIP Phones (6800 / 6900)CVE-2024-41710
Mitel SIP Phones Argument Injection Vulnerability
CVSS severity 7.2high
Added Feb 12, 2025
- Rank 45
Microsoft SharePoint ServerCVE-2024-38094
Microsoft SharePoint Deserialization Vulnerability
Ransomware
CVSS severity 7.2high
Added Oct 22, 2024
- Rank 46
Microsoft SharePoint ServerCVE-2023-24955
Microsoft SharePoint Server Code Injection Vulnerability
Ransomware
CVSS severity 7.2high
Added Mar 26, 2024
- Rank 47
Mitel MiVoice ConnectCVE-2022-40765
Mitel MiVoice Connect Command Injection Vulnerability
Ransomware
CVSS severity 6.8medium
Added Feb 21, 2023
- Rank 48
Mitel MiVoice ConnectCVE-2022-41223
Mitel MiVoice Connect Code Injection Vulnerability
Ransomware
CVSS severity 6.8medium
Added Feb 21, 2023
- Rank 49
Microsoft SharePoint ServerCVE-2025-49706
Microsoft SharePoint Improper Authentication Vulnerability
Ransomware
CVSS severity 6.5medium
Added Jul 22, 2025
- Rank 50
Atlassian Jira Server / Data CenterCVE-2021-26086
Atlassian Jira Server and Data Center Path Traversal Vulnerability
CVE from 2021, added in 2024
CVSS severity 5.3medium
Added Nov 12, 2024
- Rank 51
Microsoft Skype for Business / LyncCVE-2023-41763
Microsoft Skype for Business Privilege Escalation Vulnerability
CVSS severity 5.3medium
Added Oct 10, 2023
- Rank 52
Atlassian Confluence Server / Data CenterCVE-2021-26085
Atlassian Confluence Server Pre-Authorization Arbitrary File Read Vulnerability
Ransomware
CVSS severity 5.3medium
Added Mar 28, 2022
- Rank 53
Mitel MiCollabCVE-2024-55550
Mitel MiCollab Path Traversal Vulnerability
Ransomware
CVSS severity 2.7low
Added Jan 7, 2025
Follow and verify
Get new vulnerabilities in this category: RSS feed (add it to Outlook, Teams, Slack or your feed reader).
Indicative classification, based on the vendor and product names given by CISA. How products are classified.