VendorsCiscounified_contact_center_express12.5\(1\)
Vulnerabilities

Cisco Unified Contact Center Express 12.5\(1\)

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

13CVEs
CVE-2021-44228
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
Published 2021-12-10 · Analyzed
10.0KEV3 PoCEPSS 1.000
CVE-2024-20253
A vulnerability in multiple Cisco Unified Communications and Contact Center Solutions products could allow an unauthenticated, remote attacker to execute arbitrary code on an affected device. This vulnerability is due to the improper processing of user-provided data that is being read into memory. An attacker could exploit this vulnerability by sending a crafted message to a listening port of an affected device. A successful exploit could allow the attacker to execute arbitrary commands on the underlying operating system with the privileges of the web services user. With access to the underlying operating system, the attacker could also establish root access on the affected device.
Published 2024-01-26 · Modified
10.0EPSS 0.024
CVE-2025-20274
Cisco Unified Intelligence Center Arbitrary File Upload Vulnerability
Published 2025-07-16 · Analyzed
8.8EPSS 0.004
CVE-2025-20275
Cisco Unified Contact Center Express Editor Remote Code Execution Vulnerability
Published 2025-06-04 · Analyzed
7.8EPSS 0.002
CVE-2025-20276
Cisco Unified Contact Center Express Remote Code Execution Vulnerability
Published 2025-06-04 · Analyzed
7.2EPSS 0.004
CVE-2025-20113
Cisco Unified Intelligence Center Privilege Escalation Vulnerability
Published 2025-05-21 · Analyzed
7.1EPSS 0.004
CVE-2025-20278
Cisco Unified Communications Products Command Injection Vulnerability
Published 2025-06-04 · Analyzed
6.7EPSS 0.002
CVE-2025-20277
Cisco Unified Contact Center Express Path Traversal Vulnerability
Published 2025-06-04 · Analyzed
6.7EPSS 0.002
CVE-2025-20288
Cisco Unified Intelligence Center Server-Side Request Forgery Vulnerability
Published 2025-07-16 · Analyzed
5.8EPSS 0.003
CVE-2025-20129
Cisco Customer Collaboration Platform Information Disclosure Vulnerability
Published 2025-06-04 · Analyzed
5.4EPSS 0.003
CVE-2019-12626
Cisco Unified Contact Center Express Stored Cross-Site Scripting Vulnerability
Published 2019-08-21 · Modified
4.8EPSS 0.008
CVE-2025-20279
Cisco Unifed Contact Center Express Stored Cross-Site Scripting Vulnerability
Published 2025-06-04 · Analyzed
4.8EPSS 0.003
CVE-2025-20114
Cisco Unified Intelligence Center Insecure Direct Object Reference Vulnerability
Published 2025-05-21 · Analyzed
4.3EPSS 0.003