Products › End-user applications
End-user applications
Collaboration, telephony and video conferencing
Intranets, wikis, teamwork tools, IP telephony and video conferencing.
For example: SharePoint, Confluence, Mitel, FreePBX.
-
17 vulnerabilities added in the last 12 months
-
53 exploited vulnerabilities in the catalog, in total
-
2 added in the last 30 days
Pace of additions
| Period | Vulnerabilities added |
|---|---|
| Sep 4, 2025 to Oct 3, 2025 | 0 |
| Oct 4, 2025 to Nov 2, 2025 | 1 |
| Nov 3, 2025 to Dec 2, 2025 | 0 |
| Dec 3, 2025 to Jan 1, 2026 | 0 |
| Jan 2, 2026 to Jan 31, 2026 | 1 |
| Feb 1, 2026 to Mar 2, 2026 | 2 |
| Mar 3, 2026 to Apr 1, 2026 | 1 |
| Apr 2, 2026 to May 1, 2026 | 2 |
| May 2, 2026 to May 31, 2026 | 0 |
| Jun 1, 2026 to Jun 30, 2026 | 1 |
| Jul 1, 2026 to Jul 30, 2026 | 4 |
| Jul 31, 2026 to Aug 29, 2026 | 3 |
| Aug 30, 2026 to Sep 28, 2026 (in progress) | 2 |
Affected brands
In alphabetical order, with their number of vulnerabilities in this category.
- Alcatel-Lucent Enterprise 1 vulnerability
- Atlassian 11 vulnerabilities
- Cisco 3 vulnerabilities · 2 in the last 12 months
- Fortinet 1 vulnerability
- Grandstream 1 vulnerability
- Ignite Realtime 1 vulnerability
- Microsoft 17 vulnerabilities · 8 in the last 12 months
- Mitel 7 vulnerabilities
- PlaySMS 1 vulnerability
- Sangoma 4 vulnerabilities · 3 in the last 12 months
- Srimax 1 vulnerability
- TrueConf 3 vulnerabilities · 3 in the last 12 months
- XWiki 1 vulnerability · 1 in the last 12 months
- Yealink 1 vulnerability
A high count also reflects how widely a product is deployed and how much attackers care about it: it is not a security rating.
See also
- Email 70 vulnerabilities
Patch first
In the order of the main list (Patch first): recent additions first, then the most severe. The number is the rank within this category.
Rank 1Microsoft SharePoint Server
CVE-2026-65660Recently addedHunt for compromise (CISA)
Microsoft SharePoint Code Injection Vulnerability
Added to the catalog less than 30 days ago: ranked by date added.
- Added
- Sep 25, 2026
- CISA deadline
- 3 days
- CVSS severity
- 8.8 (high)
Rank 2Sangoma Switchvox
CVE-2026-9586Recently addedHunt for compromise (CISA)
Sangoma Switchvox SQL Injection Vulnerability
Added to the catalog less than 30 days ago: ranked by date added.
- Added
- Sep 2, 2026
- CISA deadline
- 3 days
- CVSS severity
- 9.8 (critical)
Rank 3TrueConf Server
CVE-2026-72529Hunt for compromise (CISA)
TrueConf Server Missing Authentication for Critical Function Vulnerability
Added in the last 12 months: ranked by severity.
- Added
- Aug 20, 2026
- CISA deadline
- 3 days
- CVSS severity
- 9.8 (critical)
Rank 4Microsoft SharePoint Server
CVE-2026-50522Hunt for compromise (CISA)
Microsoft SharePoint Deserialization of Untrusted Data Vulnerability
Added in the last 12 months: ranked by severity.
- Added
- Jul 22, 2026
- CISA deadline
- 3 days
- CVSS severity
- 9.8 (critical)
Rank 5Microsoft SharePoint Server
CVE-2026-58644Hunt for compromise (CISA)
Microsoft SharePoint Deserialization of Untrusted Data Vulnerability
Added in the last 12 months: ranked by severity.
- Added
- Jul 16, 2026
- CISA deadline
- 3 days
- CVSS severity
- 9.8 (critical)
Rank 6Microsoft SharePoint Server
CVE-2026-56164Hunt for compromise (CISA)
Microsoft SharePoint Server Missing Authentication for Critical Function Vulnerability
Added in the last 12 months: ranked by severity.
- Added
- Jul 14, 2026
- CISA deadline
- 3 days
- CVSS severity
- 9.8 (critical)
Rank 7Microsoft SharePoint Server
CVE-2026-20963Microsoft SharePoint Deserialization of Untrusted Data Vulnerability
Added in the last 12 months: ranked by severity.
- Added
- Mar 18, 2026
- CISA deadline
- 3 days
- CVSS severity
- 9.8 (critical)
Rank 8Sangoma FreePBX
CVE-2019-19006CVE from 2019, added in 2026
Sangoma FreePBX Improper Authentication Vulnerability
Added in the last 12 months: ranked by severity.
- Added
- Feb 3, 2026
- CISA deadline
- 21 days
- CVSS severity
- 9.8 (critical)
Rank 9Cisco Unified Communications Manager
CVE-2026-20045Cisco Unified Communications Products Code Injection Vulnerability
Added in the last 12 months: ranked by severity.
- Added
- Jan 21, 2026
- CISA deadline
- 21 days
- CVSS severity
- 9.8 (critical)
Rank 10XWiki Platform
CVE-2025-24893XWiki Platform Eval Injection Vulnerability
Added in the last 12 months: ranked by severity.
- Added
- Oct 30, 2025
- CISA deadline
- 21 days
- CVSS severity
- 9.8 (critical)
Show 43 more vulnerabilities
Rank 11Microsoft SharePoint Server
CVE-2026-55040Hunt for compromise (CISA)
Microsoft SharePoint Weak Authentication Vulnerability
Added in the last 12 months: ranked by severity.
- Added
- Aug 18, 2026
- CISA deadline
- 3 days
- CVSS severity
- 9.1 (critical)
Rank 12TrueConf Server
CVE-2026-72530TrueConf Server Code Injection Vulnerability
Added in the last 12 months: ranked by severity.
- Added
- Aug 20, 2026
- CISA deadline
- 14 days
- CVSS severity
- 9.0 (critical)
Rank 13Microsoft SharePoint Server
CVE-2026-45659Hunt for compromise (CISA)Ransomware
Microsoft SharePoint Server Deserialization of Untrusted Data Vulnerability
Added in the last 12 months: ranked by severity.
- Added
- Jul 1, 2026
- CISA deadline
- 3 days
- CVSS severity
- 8.8 (high)
Rank 14Cisco Unified Communications Manager
CVE-2026-20230Cisco Unified Communications Manager Server-Side Request Forgery (SSRF) Vulnerability
Added in the last 12 months: ranked by severity.
- Added
- Jun 25, 2026
- CISA deadline
- 3 days
- CVSS severity
- 8.6 (high)
Rank 15TrueConf Client
CVE-2026-3502TrueConf Client Download of Code Without Integrity Check Vulnerability
Added in the last 12 months: ranked by severity.
- Added
- Apr 2, 2026
- CISA deadline
- 14 days
- CVSS severity
- 7.8 (high)
Rank 16Sangoma FreePBX
CVE-2025-64328Sangoma FreePBX OS Command Injection Vulnerability
Added in the last 12 months: ranked by severity.
- Added
- Feb 3, 2026
- CISA deadline
- 21 days
- CVSS severity
- 7.2 (high)
Rank 17Microsoft SharePoint Server
CVE-2026-32201Microsoft SharePoint Server Improper Input Validation Vulnerability
Added in the last 12 months: ranked by severity.
- Added
- Apr 14, 2026
- CISA deadline
- 14 days
- CVSS severity
- 6.5 (medium)
Rank 18Sangoma FreePBX
CVE-2025-57819Sangoma FreePBX Authentication Bypass Vulnerability
Added more than a year ago: ranked by severity.
- Added
- Aug 29, 2025
- CISA deadline
- 21 days
- CVSS severity
- 9.8 (critical)
Rank 19Microsoft SharePoint Server
CVE-2025-53770Ransomware
Microsoft SharePoint Deserialization of Untrusted Data Vulnerability
Added more than a year ago: ranked by severity.
- Added
- Jul 20, 2025
- CISA deadline
- 1 day
- CVSS severity
- 9.8 (critical)
Rank 20Fortinet FortiVoice / FortiFone
CVE-2025-32756Fortinet Multiple Products Stack-Based Buffer Overflow Vulnerability
Added more than a year ago: ranked by severity.
- Added
- May 14, 2025
- CISA deadline
- 21 days
- CVSS severity
- 9.8 (critical)
Rank 21Atlassian Confluence Server / Data Center
CVE-2023-22527Ransomware
Atlassian Confluence Data Center and Server Template Injection Vulnerability
Added more than a year ago: ranked by severity.
- Added
- Jan 24, 2024
- CISA deadline
- 21 days
- CVSS severity
- 9.8 (critical)
Rank 22Microsoft SharePoint Server
CVE-2023-29357Ransomware
Microsoft SharePoint Server Privilege Escalation Vulnerability
Added more than a year ago: ranked by severity.
- Added
- Jan 10, 2024
- CISA deadline
- 21 days
- CVSS severity
- 9.8 (critical)
Rank 23Atlassian Confluence Server / Data Center
CVE-2023-22518Ransomware
Atlassian Confluence Data Center and Server Improper Authorization Vulnerability
Added more than a year ago: ranked by severity.
- Added
- Nov 7, 2023
- CISA deadline
- 21 days
- CVSS severity
- 9.8 (critical)
Rank 24Atlassian Confluence Server / Data Center
CVE-2023-22515Ransomware
Atlassian Confluence Data Center and Server Broken Access Control Vulnerability
Added more than a year ago: ranked by severity.
- Added
- Oct 5, 2023
- CISA deadline
- 8 days
- CVSS severity
- 9.8 (critical)
Rank 25Atlassian Confluence Server / Data Center
CVE-2022-26138Atlassian Questions For Confluence App Hard-coded Credentials Vulnerability
Added more than a year ago: ranked by severity.
- Added
- Jul 29, 2022
- CISA deadline
- 21 days
- CVSS severity
- 9.8 (critical)
Rank 26Mitel MiVoice Connect
CVE-2022-29499Ransomware
Mitel MiVoice Connect Data Validation Vulnerability
Added more than a year ago: ranked by severity.
- Added
- Jun 27, 2022
- CISA deadline
- 21 days
- CVSS severity
- 9.8 (critical)
Rank 27Atlassian Confluence Server / Data Center
CVE-2022-26134Ransomware
Atlassian Confluence Server and Data Center Remote Code Execution Vulnerability
Added more than a year ago: ranked by severity.
- Added
- Jun 2, 2022
- CISA deadline
- 4 days
- CVSS severity
- 9.8 (critical)
Rank 28Alcatel-Lucent Enterprise OmniPCX Enterprise
CVE-2007-3010CVE from 2007, added in 2022
Alcatel OmniPCX Enterprise Remote Code Execution Vulnerability
Added more than a year ago: ranked by severity.
- Added
- Apr 15, 2022
- CISA deadline
- 21 days
- CVSS severity
- 9.8 (critical)
Rank 29Mitel MiCollab
CVE-2022-26143MiCollab, MiVoice Business Express Access Control Vulnerability
Added more than a year ago: ranked by severity.
- Added
- Mar 25, 2022
- CISA deadline
- 21 days
- CVSS severity
- 9.8 (critical)
Rank 30Atlassian Jira Server / Data Center
CVE-2019-11581CVE from 2019, added in 2022
Atlassian Jira Server and Data Center Server-Side Template Injection Vulnerability
Added more than a year ago: ranked by severity.
- Added
- Mar 7, 2022
- CISA deadline
- 184 days
- CVSS severity
- 9.8 (critical)
Rank 31Grandstream UCM6200
CVE-2020-5722CVE from 2020, added in 2022
Grandstream Networks UCM6200 Series SQL Injection Vulnerability
Added more than a year ago: ranked by severity.
- Added
- Jan 28, 2022
- CISA deadline
- 181 days
- CVSS severity
- 9.8 (critical)
Rank 32Microsoft SharePoint Server
CVE-2019-0604RansomwareCVE from 2019, added in 2021
Microsoft SharePoint Remote Code Execution Vulnerability
Added more than a year ago: ranked by severity.
- Added
- Nov 3, 2021
- CISA deadline
- 181 days
- CVSS severity
- 9.8 (critical)
Rank 33Atlassian Confluence Server / Data Center
CVE-2019-3396RansomwareCVE from 2019, added in 2021
Atlassian Confluence Server and Data Center Server-Side Template Injection Vulnerability
Added more than a year ago: ranked by severity.
- Added
- Nov 3, 2021
- CISA deadline
- 181 days
- CVSS severity
- 9.8 (critical)
Rank 34Cisco IP Phones
CVE-2020-3161Cisco IP Phones Web Server Remote Code Execution and Denial-of-Service Vulnerability
Added more than a year ago: ranked by severity.
- Added
- Nov 3, 2021
- CISA deadline
- 181 days
- CVSS severity
- 9.8 (critical)
Rank 35PlaySMS
CVE-2020-8644PlaySMS Server-Side Template Injection Vulnerability
Added more than a year ago: ranked by severity.
- Added
- Nov 3, 2021
- CISA deadline
- 181 days
- CVSS severity
- 9.8 (critical)
Rank 36Atlassian Confluence Server / Data Center
CVE-2021-26084Ransomware
Atlassian Confluence Server and Data Center Object-Graph Navigation Language (OGNL) Injection Vulnerability
Added more than a year ago: ranked by severity.
- Added
- Nov 3, 2021
- CISA deadline
- 14 days
- CVSS severity
- 9.8 (critical)
Rank 37Yealink Device Management
CVE-2021-27561Yealink Device Management Server-Side Request Forgery (SSRF) Vulnerability
Added more than a year ago: ranked by severity.
- Added
- Nov 3, 2021
- CISA deadline
- 14 days
- CVSS severity
- 9.8 (critical)
Rank 38Mitel MiCollab
CVE-2024-41713Ransomware
Mitel MiCollab Path Traversal Vulnerability
Added more than a year ago: ranked by severity.
- Added
- Jan 7, 2025
- CISA deadline
- 21 days
- CVSS severity
- 9.1 (critical)
Rank 39Microsoft SharePoint Server
CVE-2025-49704Ransomware
Microsoft SharePoint Code Injection Vulnerability
Added more than a year ago: ranked by severity.
- Added
- Jul 22, 2025
- CISA deadline
- 1 day
- CVSS severity
- 8.8 (high)
Rank 40Srimax Output Messenger
CVE-2025-27920Srimax Output Messenger Directory Traversal Vulnerability
Added more than a year ago: ranked by severity.
- Added
- May 19, 2025
- CISA deadline
- 21 days
- CVSS severity
- 8.8 (high)
Rank 41Atlassian Confluence Server / Data Center
CVE-2019-3398CVE from 2019, added in 2021
Atlassian Confluence Server and Data Center Path Traversal Vulnerability
Added more than a year ago: ranked by severity.
- Added
- Nov 3, 2021
- CISA deadline
- 181 days
- CVSS severity
- 8.8 (high)
Rank 42Microsoft SharePoint Server
CVE-2020-1147Microsoft .NET Framework, SharePoint, and Visual Studio Remote Code Execution Vulnerability
Added more than a year ago: ranked by severity.
- Added
- Nov 3, 2021
- CISA deadline
- 181 days
- CVSS severity
- 7.8 (high)
Rank 43Ignite Realtime Openfire
CVE-2023-32315Ignite Realtime Openfire Path Traversal Vulnerability
Added more than a year ago: ranked by severity.
- Added
- Aug 24, 2023
- CISA deadline
- 21 days
- CVSS severity
- 7.5 (high)
Rank 44Mitel SIP Phones (6800 / 6900)
CVE-2024-41710Mitel SIP Phones Argument Injection Vulnerability
Added more than a year ago: ranked by severity.
- Added
- Feb 12, 2025
- CISA deadline
- 21 days
- CVSS severity
- 7.2 (high)
Rank 45Microsoft SharePoint Server
CVE-2024-38094Ransomware
Microsoft SharePoint Deserialization Vulnerability
Added more than a year ago: ranked by severity.
- Added
- Oct 22, 2024
- CISA deadline
- 21 days
- CVSS severity
- 7.2 (high)
Rank 46Microsoft SharePoint Server
CVE-2023-24955Ransomware
Microsoft SharePoint Server Code Injection Vulnerability
Added more than a year ago: ranked by severity.
- Added
- Mar 26, 2024
- CISA deadline
- 21 days
- CVSS severity
- 7.2 (high)
Rank 47Mitel MiVoice Connect
CVE-2022-40765Ransomware
Mitel MiVoice Connect Command Injection Vulnerability
Added more than a year ago: ranked by severity.
- Added
- Feb 21, 2023
- CISA deadline
- 21 days
- CVSS severity
- 6.8 (medium)
Rank 48Mitel MiVoice Connect
CVE-2022-41223Ransomware
Mitel MiVoice Connect Code Injection Vulnerability
Added more than a year ago: ranked by severity.
- Added
- Feb 21, 2023
- CISA deadline
- 21 days
- CVSS severity
- 6.8 (medium)
Rank 49Microsoft SharePoint Server
CVE-2025-49706Ransomware
Microsoft SharePoint Improper Authentication Vulnerability
Added more than a year ago: ranked by severity.
- Added
- Jul 22, 2025
- CISA deadline
- 1 day
- CVSS severity
- 6.5 (medium)
Rank 50Atlassian Jira Server / Data Center
CVE-2021-26086CVE from 2021, added in 2024
Atlassian Jira Server and Data Center Path Traversal Vulnerability
Added more than a year ago: ranked by severity.
- Added
- Nov 12, 2024
- CISA deadline
- 21 days
- CVSS severity
- 5.3 (medium)
Rank 51Microsoft Skype for Business / Lync
CVE-2023-41763Microsoft Skype for Business Privilege Escalation Vulnerability
Added more than a year ago: ranked by severity.
- Added
- Oct 10, 2023
- CISA deadline
- 21 days
- CVSS severity
- 5.3 (medium)
Rank 52Atlassian Confluence Server / Data Center
CVE-2021-26085Ransomware
Atlassian Confluence Server Pre-Authorization Arbitrary File Read Vulnerability
Added more than a year ago: ranked by severity.
- Added
- Mar 28, 2022
- CISA deadline
- 21 days
- CVSS severity
- 5.3 (medium)
Rank 53Mitel MiCollab
CVE-2024-55550Ransomware
Mitel MiCollab Path Traversal Vulnerability
Added more than a year ago: ranked by severity.
- Added
- Jan 7, 2025
- CISA deadline
- 21 days
- CVSS severity
- 2.7 (low)
Follow and verify
Get new vulnerabilities in this category: RSS feed (add it to Outlook, Teams, Slack or your feed reader).
Indicative classification, based on the vendor and product names given by CISA. How products are classified.