Known Vulnerabilities for 3cx Web Server by 3cx
Listed below are 3 of the newest known vulnerabilities associated with "3cx Web Server" by "3cx".
These CVEs are retrieved based on exact matches on listed software, hardware, and vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed software information are still displayed.
Data on known vulnerable versions is also displayed based on information from known CPEs
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2026-57940 json | HTMLy 3.1.1 contains a Server-Side Request Forgery (SSRF) vulnerability in the RSS feed import functionality. The function ge... | Not Provided | 2026-06-26 | 2026-06-26 |
| CVE-2026-57918 json | libnfs through 6.0.2 before 935b8db has an xid integer underflow in READ_IOVEC in rpc_read_from_socket in lib/socket.c during... | Not Provided | 2026-06-26 | 2026-06-26 |
| CVE-2026-57627 json | Subscriber Server Side Request Forgery (SSRF) in Kirki <= 6.0.11 versions. | Not Provided | 2026-06-26 | 2026-06-26 |
| CVE-2026-57535 json | Content injected to PDF rendering contexts could, in many places, include HTML content including |
Not Provided | 2026-06-25 | 2026-06-25 |
| CVE-2026-57527 json | Zed Attack Proxy (ZAP) ViewState add-on before version 4 contains an insecure deserialization vulnerability that allows attac... | Not Provided | 2026-06-26 | 2026-06-26 |
| CVE-2026-57522 json | Bitwarden Server before 2026.5.0 contains a JSON injection vulnerability in IntegrationTemplateProcessor.ReplaceTokens(), whi... | Not Provided | 2026-06-25 | 2026-06-26 |
| CVE-2026-57521 json | Bitwarden Server before 2026.5.0 contains a broken access control vulnerability that allows any authenticated user to access ... | Not Provided | 2026-06-25 | 2026-06-26 |
| CVE-2026-57520 json | Bitwarden Server before 2026.5.0 contains a privilege escalation vulnerability that allows authenticated Custom users with Ma... | Not Provided | 2026-06-25 | 2026-06-25 |
| CVE-2026-57303 json | Jenkins Assembla Plugin 1.4 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks, allow... | Not Provided | 2026-06-24 | 2026-06-24 |
| CVE-2026-57300 json | A missing permission check in Jenkins MCP Server Plugin 0.177.v629fdb_2557fe and earlier allows attackers with Item/Read perm... | Not Provided | 2026-06-24 | 2026-06-24 |