VendorsCiscounified_contact_center_expressall versions
Vulnerabilities

Cisco Unified Contact Center Express

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

48CVEs
CVE-2023-20096
Cisco Unified Contact Center Express Stored Cross-Site Scripting Vulnerability
Published 2023-04-05 · Modified
5.4EPSS 0.005
CVE-2025-20129
Cisco Customer Collaboration Platform Information Disclosure Vulnerability
Published 2025-06-04 · Analyzed
5.4EPSS 0.003
CVE-2023-20232
A vulnerability in the Tomcat implementation for Cisco Unified Contact Center Express (Unified CCX) could allow an unauthenticated, remote attacker to cause a web cache poisoning attack on an affected device. This vulnerability is due to improper input validation of HTTP requests. An attacker could exploit this vulnerability by sending crafted HTTP requests to a specific API endpoint on the Unified CCX Finesse Portal. A successful exploit could allow the attacker to cause the internal WebProxy to redirect users to an attacker-controlled host.
Published 2023-08-16 · Modified
5.3EPSS 0.006
CVE-2011-2583
Cisco Unified Contact Center Express (aka CCX) 8.0 and 8.5 allows remote attackers to cause a denial of service via network traffic, as demonstrated by an SEC-BE-STABLE test case, aka Bug ID CSCth33834.
Published 2012-05-02 · Modified
5.0EPSS 0.023
CVE-2025-20374
Cisco Unified Contact Center Express Arbitrary File Download Vulnerability
Published 2025-11-05 · Analyzed
4.9EPSS 0.011
CVE-2019-12626
Cisco Unified Contact Center Express Stored Cross-Site Scripting Vulnerability
Published 2019-08-21 · Modified
4.8EPSS 0.008
CVE-2025-20279
Cisco Unifed Contact Center Express Stored Cross-Site Scripting Vulnerability
Published 2025-06-04 · Analyzed
4.8EPSS 0.003
CVE-2025-20114
Cisco Unified Intelligence Center Insecure Direct Object Reference Vulnerability
Published 2025-05-21 · Analyzed
4.3EPSS 0.003
← Prev2 / 2