Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

3cx

About This Vendor

3cx is a technology vendor producing software and infrastructure products. As a software provider, 3cx's broad product portfolio across multiple domains—including operating systems, cloud infrastructure, enterprise applications, databases, networking, and security tools—creates a large attack surface. Additionally, long support cycles, widespread deployment, and continuous feature development contribute to the accumulation of discovered vulnerabilities over time. Major vendors typically report higher CVE counts not necessarily due to inferior security, but because of greater exposure to security research, responsible disclosure practices, and the sheer complexity of maintaining multiple product lines and legacy systems. Regular security assessments and patching of 3cx's products are critical for organizations running their software in production environments.

Vulnerability Trends for This Vendor

SecUtils has indexed 34 known vulnerabilities from 3cx. This includes 6 critical-severity issues and 10 high-severity issues that represent significant risk. These vulnerabilities affect 106 distinct products across 3cx's portfolio, demonstrating the breadth of the vendor's product ecosystem and the importance of comprehensive patch management strategies. Disclosure dates span from 2009 through 2024, indicating decades of continuous security attention and research. Organizations deploying 3cx products should maintain active vulnerability monitoring, prioritize critical patches, and implement compensating controls where patches cannot be applied immediately.

ID Date Published Last Modified Severity (CVSSv3) Severity (CVSSv2) Exploit Available
CVE-2008-6894 2009-08-03 2025-04-09 - 4.3 Likely
CVE-2008-6895 2009-08-03 2025-04-09 - 7.8 Likely
CVE-2008-6896 2009-08-03 2025-04-09 - 5.0 Likely
CVE-2017-2187 2017-06-09 2025-04-20 6.1 4.3 Likely
CVE-2017-15359 2017-10-18 2025-04-20 6.5 4.0 Likely
CVE-2018-7654 2018-03-04 2024-11-21 6.5 4.0 Likely
CVE-2018-9864 2018-04-09 2024-11-21 6.1 4.3 Likely
CVE-2018-11105 2018-05-15 2024-11-21 6.1 4.3 Likely
CVE-2018-12426 2018-07-02 2024-11-21 9.8 7.5 Likely
CVE-2018-14905 2018-08-03 2024-11-21 6.1 4.3 Likely
CVE-2018-14906 2018-08-03 2024-11-21 6.1 4.3 Likely
CVE-2018-14907 2018-08-03 2024-11-21 5.3 5.0 Likely
CVE-2018-18460 2018-10-18 2024-11-21 6.1 4.3 Likely
CVE-2019-9913 2019-03-22 2024-11-21 6.1 4.3 Likely
CVE-2019-11185 2019-06-03 2024-11-21 9.8 7.5 Likely
CVE-2019-13176 2019-08-08 2024-11-21 7.5 5.0 Likely
CVE-2019-14935 2019-08-12 2024-11-21 7.8 4.6 Unknown
CVE-2016-10879 2019-08-12 2024-11-21 6.1 4.3 Likely
CVE-2017-18508 2019-08-12 2024-11-21 6.1 4.3 Likely
CVE-2019-14950 2019-08-12 2024-11-21 6.1 4.3 Likely
CVE-2017-18507 2019-08-13 2024-11-21 6.1 4.3 Likely
CVE-2014-10386 2019-08-22 2024-11-21 6.1 4.3 Likely
CVE-2019-12498 2020-03-20 2024-11-21 9.8 7.5 Likely
CVE-2021-45490 2022-03-28 2024-11-21 9.1 6.4 Likely
CVE-2021-45491 2022-03-28 2024-11-21 6.5 4.0 Likely
CVE-2022-28005 2022-05-06 2024-11-21 9.8 5.0 Likely
CVE-2022-27438 2022-06-06 2024-11-21 8.1 5.1 Unknown
CVE-2019-9971 2022-06-07 2024-11-21 8.8 9.0 Likely
CVE-2019-9972 2022-06-07 2024-11-21 8.8 9.0 Likely
CVE-2023-29059 2023-03-30 2025-05-05 7.8 - -
CVE-2022-48482 2023-05-02 2025-01-30 7.5 - -
CVE-2022-48483 2023-05-02 2025-01-30 7.5 - -
CVE-2023-49954 2023-12-25 2025-04-23 9.8 - -
CVE-2023-27362 2024-05-03 2025-08-13 7.8 - -

How SecUtils Normalizes Vendor Data

SecUtils aggregates National Vulnerability Database (NVD) and MITRE records for 3cx by normalizing vendor identifiers across diverse data sources, mapping vendor names to their associated product lines, and collecting all known vulnerabilities under a unified vendor context. For every CVE associated with 3cx's products, we extract and structure Common Platform Enumeration (CPE) data, Common Weakness Enumeration (CWE) categories, CVSS severity metrics, and reference links to enable rapid vulnerability identification and asset correlation. This record contains no exploit code, proof-of-concept instructions, or attack methodologies—only defensive intelligence necessary for patch management, risk assessment, and vendor vulnerability tracking.