Home/Product/cisco unified contact center express
Product

cisco unified contact center express

47 known vulnerabilities across versions
Vulnerabilities are listed by affected version. Select any CVE for the full briefing and its intelligence graph.
CVE-2025-20376
< 12.5\(1\)_su03_es07
A vulnerability in the web UI of Cisco Unified CCX could allow an authenticated, remote attacker to upload and execute arbitrary f
6.5MEDIUM
CVE-2025-20375
< 12.5\(1\)_su03_es07
A vulnerability in the web UI of Cisco Unified CCX could allow an authenticated, remote attacker to upload and execute arbitrary f
6.5MEDIUM
CVE-2025-20374
< 12.5\(1\)_su03_es07
A vulnerability in the web UI of Cisco Unified CCX could allow an authenticated, remote attacker to perform a directory traversal
4.9MEDIUM
CVE-2025-20358
< 12.5\(1\)_su03_es07
A vulnerability in the Contact Center Express (CCX) Editor application of Cisco Unified CCX could allow an unauthenticated, remote
9.4CRITICAL
CVE-2025-20354
< 12.5\(1\)_su03_es07
A vulnerability in the Java Remote Method Invocation (RMI) process of Cisco Unified CCX could allow an unauthenticated, remote att
9.8CRITICAL
CVE-2025-20288
all versions
A vulnerability in the web-based management interface of Cisco Unified Intelligence Center could allow an unauthenticated, remote
5.8MEDIUM
CVE-2025-20274
all versions
A vulnerability in the web-based management interface of Cisco Unified Intelligence Center could allow an authenticated, remote at
6.3MEDIUM
CVE-2025-20279
all versions
A vulnerability in the web-based management interface of Cisco Unified CCX could allow an authenticated, remote attacker to conduc
4.8MEDIUM
CVE-2025-20278
all versions
A vulnerability in the CLI of multiple Cisco Unified Communications products could allow an authenticated, local attacker to execu
6.0MEDIUM
CVE-2025-20277
all versions
A vulnerability in the web-based management interface of Cisco Unified CCX could allow an authenticated, local attacker to execute
3.4LOW
CVE-2025-20276
all versions
A vulnerability in the web-based management interface of Cisco Unified CCX could allow an authenticated, remote attacker to execut
3.8LOW
CVE-2025-20275
all versions
A vulnerability in the file opening process of Cisco Unified Contact Center Express (Unified CCX) Editor could allow an unauthenti
5.3MEDIUM
CVE-2025-20129
all versions
A vulnerability in the web-based chat interface of Cisco Customer Collaboration Platform (CCP), formerly Cisco SocialMiner, could
4.3MEDIUM
CVE-2025-20114
all versions
A vulnerability in the API of Cisco Unified Intelligence Center could allow an authenticated, remote attacker to perform a horizon
4.3MEDIUM
CVE-2025-20113
all versions
A vulnerability in Cisco Unified Intelligence Center could allow an authenticated, remote attacker to elevate privileges to Admini
7.1HIGH
CVE-2024-20253
all versions
A vulnerability in multiple Cisco Unified Communications and Contact Center Solutions products could allow an unauthenticated, rem
9.9CRITICAL
CVE-2023-20232
< 12.5\(1\)_su2_es05
A vulnerability in the Tomcat implementation for Cisco Unified Contact Center Express (Unified CCX) could allow an unauthenticated
5.3MEDIUM
CVE-2023-20096
< 12.5\(1\)su3
A vulnerability in the web-based management interface of Cisco Unified Contact Center Express (Unified CCX) could allow an authent
5.4MEDIUM
CVE-2023-20062
all versions
Multiple vulnerabilities in Cisco Unified Intelligence Center could allow an authenticated, remote attacker to collect sensitive i
6.5MEDIUM
CVE-2023-20061
all versions
Multiple vulnerabilities in Cisco Unified Intelligence Center could allow an authenticated, remote attacker to collect sensitive i
6.5MEDIUM
CVE-2023-20058
< 12.5\(1\)_su2_es05
A vulnerability in the web-based management interface of Cisco Unified Intelligence Center could allow an unauthenticated, remote
6.1MEDIUM
CVE-2022-20658
all versions
A vulnerability in the web-based management interface of Cisco Unified Contact Center Management Portal (Unified CCMP) and Cisco U
9.6CRITICAL
CVE-2021-44228
< 12.5\(1\)
Apache Log4j2 2.0-beta9 through 2.15.0 (excluding security releases 2.12.2, 2.12.3, and 2.3.1) JNDI features used in configuration
10.0CRITICAL
CVE-2021-1395
<= 12.5\(1\)
A vulnerability in the web-based management interface of Cisco Unified Intelligence Center could allow an unauthenticated, remote
4.7MEDIUM
CVE-2021-1463
<= 12.0\(1\)
A vulnerability in the web-based management interface of Cisco Unified Intelligence Center Software could allow an unauthenticated
6.1MEDIUM
CVE-2019-1888
all versions
A vulnerability in the Administration Web Interface of Cisco Unified Contact Center Express (Unified CCX) could allow an authentic
7.2HIGH
CVE-2020-3267
< 12.5\(1\)
A vulnerability in the API subsystem of Cisco Unified Contact Center Express (Unified CCX) could allow an authenticated, remote at
7.1HIGH
CVE-2020-3280
>= 12.0 and < 12.0\(1\)es03
A vulnerability in the Java Remote Management Interface of Cisco Unified Contact Center Express (Unified CCX) could allow an unaut
9.8CRITICAL
CVE-2020-3177
all versions
A vulnerability in the Tool for Auto-Registered Phones Support (TAPS) of Cisco Unified Communications Manager (UCM) and Cisco Unif
7.5HIGH
CVE-2019-15278
all versions
A vulnerability in the web-based management interface of Cisco Finesse could allow an unauthenticated, remote attacker to bypass a
6.1MEDIUM
CVE-2019-15259
< 11.6\(2\)
A vulnerability in Cisco Unified Contact Center Express (UCCX) Software could allow an unauthenticated, remote attacker to conduct
6.1MEDIUM
CVE-2019-12633
< 11.6\(2\)es04
A vulnerability in Cisco Unified Contact Center Express (Unified CCX) could allow an unauthenticated, remote attacker to bypass ac
7.5HIGH
CVE-2019-12626
all versions
A vulnerability in the web-based management interface of Cisco Unified Contact Center Express (Unified CCX) could allow an authent
4.8MEDIUM
CVE-2018-0403
all versions
Multiple vulnerabilities in the web-based management interface of Cisco Unified Contact Center Express (Unified CCX) could allow a
9.8CRITICAL
CVE-2018-0402
all versions
Multiple vulnerabilities in the web-based management interface of Cisco Unified Contact Center Express (Unified CCX) could allow a
8.8HIGH
CVE-2018-0401
all versions
Multiple vulnerabilities in the web-based management interface of Cisco Unified Contact Center Express (Unified CCX) could allow a
6.1MEDIUM
CVE-2018-0400
all versions
Multiple vulnerabilities in the web-based management interface of Cisco Unified Contact Center Express (Unified CCX) could allow a
6.1MEDIUM
CVE-2017-6779
>= 11.6 and < 11.6\(1\)
Multiple Cisco products are affected by a vulnerability in local file management for certain system log files of Cisco collaborati
7.5HIGH
CVE-2017-12337
all versions
A vulnerability in the upgrade mechanism of Cisco collaboration products based on the Cisco Voice Operating System software platfo
9.8CRITICAL
CVE-2017-6722
all versions
A vulnerability in the Extensible Messaging and Presence Protocol (XMPP) service of Cisco Unified Contact Center Express (UCCx) co
6.1MEDIUM
CVE-2016-6427
all versions
Cross-site request forgery (CSRF) vulnerability in Cisco Unified Intelligence Center (CUIC) 8.5.4 through 9.1(1), as used in Unifi
8.8HIGH
CVE-2016-6425
all versions
Cross-site scripting (XSS) vulnerability in Cisco Unified Intelligence Center (CUIC) 8.5.4 through 9.1(1), as used in Unified Cont
6.1MEDIUM
CVE-2016-6426
all versions
The j_spring_security_switch_user function in Cisco Unified Intelligence Center (CUIC) 8.5.4 through 9.1(1), as used in Unified Co
7.5HIGH
CVE-2016-1298
all versions
Multiple cross-site scripting (XSS) vulnerabilities in Cisco Unified Contact Center Express 10.0(1), 10.5(1), 10.6(1), and 11.0(1)
6.1MEDIUM
CVE-2011-2583
all versions
Cisco Unified Contact Center Express (aka CCX) 8.0 and 8.5 allows remote attackers to cause a denial of service via network traffi
CVE-2010-1571
all versions
Directory traversal vulnerability in the bootstrap service in Cisco Unified Contact Center Express (UCCX) 7.0 before 7.0(1)SR4 and
CVE-2010-1570
all versions
The computer telephony integration (CTI) server component in Cisco Unified Contact Center Express (UCCX) 7.0 before 7.0(1)SR4 and
Vulnerabilities
CISA KEV catalog
CWE weaknesses
CAPEC attack patterns
Package vulnerabilities
Threat intelligence
Threat actors
Tools & malware
ATT&CK techniques
IOCs
Detection & defense
Sigma rules
YARA rules
Atomic Red Team tests
D3FEND countermeasures
Compliance
NIST 800-53
ISO 27001:2022
SOC 2 TSC
PCI-DSS v4.0
CIS Controls v8.1
About
All capabilities
Live statistics
Data sources
Privacy policy
Terms of service
threatengine.sh  ·  Open-source threat intelligence platform  ·  100+ authoritative sources  ·  Every fact traces to its origin