CVE Tools

Unified Communications Domain Manager

43 CVEs tracked. None of them is in CISA KEV.

This hub aggregates every CVE we track for Unified Communications Domain Manager, a product in the networking infrastructure space. Use it to gauge the current risk picture and drill into individual advisories.

Unified Communications Domain Manager CVEs per month

Oct 2024 to Sep 2026. Point at a month, or focus the strip and use the arrow keys.
Unified Communications Domain Manager CVEs per month
MonthCVEs
2024-100
2024-110
2024-120
2025-010
2025-020
2025-030
2025-040
2025-050
2025-060
2025-070
2025-080
2025-090
2025-100
2025-110
2025-120
2026-010
2026-020
2026-030
2026-040
2026-050
2026-060
2026-070
2026-080
2026-090

Severity

How the 43 CVEs score on CVSS. Severity is not exploitation: KEV is counted above.

  • Critical49%
  • High25%
  • Medium3786%

Latest CVEs

The 15 most recently published vulnerabilities affecting Unified Communications Domain Manager.

  1. CVE-2019-15968Cisco Unified Communications Domain Manager Persistent Cross-Site Scripting Vulnerability5.4
  2. CVE-2019-1911Cisco Unified Communications Domain Manager Restricted Shell Escape Vulnerability5.3
  3. CVE-2018-0386A vulnerability in Cisco Unified Communications Domain Manager Software could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack on an affected system. The vul...6.1
  4. CVE-2018-0364A vulnerability in the web-based management interface of Cisco Unified Communications Domain Manager could allow an unauthenticated, remote attacker to conduct a cross-site request forgery (CSRF) a...8.8
  5. CVE-2018-0124A vulnerability in Cisco Unified Communications Domain Manager could allow an unauthenticated, remote attacker to bypass security protections, gain elevated privileges, and execute arbitrary code. ...9.8
  6. CVE-2017-12302A vulnerability in the Cisco Unified Communications Manager SQL database interface could allow an authenticated, remote attacker to impact the confidentiality of the system by executing arbitrary S...4.3
  7. CVE-2017-6670A vulnerability in the web-based GUI of Cisco Unified Communications Domain Manager could allow an unauthenticated, remote attacker to redirect a user to a malicious web page, aka an Open Redirect ...6.1
  8. CVE-2017-6668Vulnerabilities in the web-based GUI of Cisco Unified Communications Domain Manager (CUCDM) could allow an authenticated, remote attacker to impact the confidentiality of the system by executing ar...4.9
  9. CVE-2016-1354Cross-site scripting (XSS) vulnerability in Cisco Unified Communications Domain Manager (UCDM) 8.x before 8.1.1 allows remote attackers to inject arbitrary web script or HTML via crafted markup dat...6.1
  10. CVE-2015-6420Serialized-object interfaces in certain Cisco Collaboration and Social Media; Endpoint Clients and Client Software; Network Application, Service, and Acceleration; Network and Content Security Devi...9.8
  11. CVE-2015-6422The self-service application in Cisco Unified Communications Domain Manager (CUCDM) 10.6(1) allows remote authenticated users to cause a denial of service (subapplication outage) via malformed requ...4.0
  12. CVE-2015-6352Cisco Unified Communications Domain Manager before 10.6(1) provides different error messages for pathname access attempts depending on whether the pathname exists, which allows remote attackers to ...4.3
  13. CVE-2015-4196Platform Software before 4.4.5 in Cisco Unified Communications Domain Manager (CDM) 8.x has a hardcoded password for a privileged account, which allows remote attackers to obtain root access by lev...5.0
  14. CVE-2015-4229The web framework in Cisco Unified Communications Domain Manager 8.1(4)ER1 allows remote attackers to obtain sensitive information by visiting a bvsmweb URL, aka Bug ID CSCuq22589.5.0
  15. CVE-2015-0699SQL injection vulnerability in the Interactive Voice Response (IVR) component in Cisco Unified Communications Manager (UCM) 10.5(1.98991.13) allows remote attackers to execute arbitrary SQL command...5.0

Product grouping is registry-driven, with AI assist and human review. How it works

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store