Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6673
Adobe 6383
Ibm 6286
Cisco 5751
Debian 3919
Mozilla 2886
Apache 2864
Redhat 2586
HIGH 8.8
CVE-2021-41322
Poly VVX 400/410 5.3.1 allows low-privileged users to change the Admin password by modifying a POST parameter to 120 during the password reset proces…
Vvx 400 Firmware
No fix yet
HIGH 7.2
CVE-2019-11355
An issue was discovered in Poly (formerly Polycom) HDX 3.1.13. A feature exists that allows the creation of a server / client certificate, or the upl…
Hdx System Software
after 3.1.13
CRITICAL 9.8
CVE-2012-6611
An issue was discovered in Polycom Web Management Interface G3/HDX 8000 HD with Durango 2.6.0 4740 software and embedded Polycom Linux Development Pl…
Hdx System Software
after 3.0.5
HIGH 8.8
CVE-2012-6610EPSS 11%
Polycom HDX Video End Points before 3.0.4 and UC APL before 2.7.1.J allows remote authenticated users to execute arbitrary commands as demonstrated b…
Hdx Video End Points
2.7.1.j / 3.0.4+
HIGH 7.5
CVE-2012-6609
Directory traversal vulnerability in a_getlog.cgi in Polycom HDX Video End Points before 3.0.4 and UC APL before 2.7.1.J allows remote attackers to r…
Hdx Video End Points
2.7.1.j / 3.0.4+
HIGH 8.0
CVE-2019-14259
On the Polycom Obihai Obi1022 VoIP phone with firmware 5.1.11, a command injection (missing input validation) issue in the NTP server IP address fiel…
Obihai Obi1022 Firmware
No fix yet
HIGH 8.3
CVE-2019-12948
A vulnerability in the web-based management interface of VVX, Trio, SoundStructure, SoundPoint, and SoundStation phones running Polycom UC Software, …
Unified Communications Software
4.0.14.1580 / 5.8.5.1256+
MEDIUM 6.5
CVE-2019-10689
VVX products using UCS software version 5.9.2 and earlier with Better Together over Ethernet Connector (BToE) application version 3.9.1 and earlier p…
Better Together Over Ethernet Connector
after 5.9.2
MEDIUM 6.8
CVE-2018-10946
An issue was discovered in versions earlier than 1.3.0-66872 for Polycom RealPresence Debut that allows attackers to arbitrarily read the admin user'…
Realpresence Debut Firmware
1.3.0-66872+
CRITICAL 9.8
CVE-2018-15128EPSS 5%
An issue was discovered in Polycom Group Series 6.1.6.1 and earlier, HDX 3.1.12 and earlier, and Pano 1.1.1 and earlier. A remote code execution vuln…
Group Series
after 6.1.6.1
MEDIUM 6.8
CVE-2019-10688
VVX products with software versions including and prior to, UCS 5.9.2 with Better Together over Ethernet Connector (BToE) application 3.9.1, use hard…
Unified Communications Software
after 5.8.0
MEDIUM 6.5
CVE-2018-14934
The Bluetooth subsystem on Polycom Trio devices with software before 5.5.4 has Incorrect Access Control. An attacker can connect without authenticati…
Trio 8500 Firmware
5.5.4+
MEDIUM 6.1
CVE-2018-14935
The Web administration console on Polycom Trio devices with software before 5.5.4 has XSS.
Trio 8500 Firmware
5.5.4+
MEDIUM 5.9
CVE-2018-18568
Polycom VVX 500 and 601 devices 5.8.0.12848 and earlier allows man-in-the-middle attackers to obtain sensitive credential information by leveraging f…
Unified Communications Software
after 5.8.0.12848
MEDIUM 5.3
CVE-2018-18566
The SIP service in Polycom VVX 500 and 601 devices 5.8.0.12848 and earlier allow remote attackers to obtain sensitive phone configuration information…
Unified Communications Software
after 5.8.0.12848
HIGH 7.5
CVE-2018-12592
Polycom RealPresence Web Suite before 2.2.0 does not block a user's video for a few seconds upon joining a meeting (when the user has explicitly chos…
Realpresence Web Suite
2.2.0+
HIGH 8.8
CVE-2018-7565
CSRF exists on Polycom QDX 6000 devices.
Qdx 6000 Firmware
No fix yet
MEDIUM 6.1
CVE-2018-7564
Stored XSS exists on Polycom QDX 6000 devices.
Qdx 6000 Firmware
Mitigation only
CRITICAL 9.8
CVE-2015-4683EPSS 7%
Polycom RealPresence Resource Manager (aka RPRM) before 8.4 allows attackers to obtain sensitive information and potentially gain privileges by lever…
Realpresence Resource Manager
after 8.3.2
HIGH 7.8
CVE-2015-4681
Polycom RealPresence Resource Manager (aka RPRM) before 8.4 allows local users to have unspecified impact via vectors related to weak passwords.
Realpresence Resource Manager
after 8.3.2
HIGH 7.0
CVE-2015-4685
Polycom RealPresence Resource Manager (aka RPRM) before 8.4 allows local users with access to the plcm account to gain privileges via a script in /va…
Realpresence Resource Manager
after 8.3.2
MEDIUM 6.5
CVE-2015-4682EPSS 5%
Polycom RealPresence Resource Manager (aka RPRM) before 8.4 allows remote authenticated users to obtain the installation path via an HTTP POST reques…
Realpresence Resource Manager
after 8.3.2
MEDIUM 6.5
CVE-2015-4684
Multiple directory traversal vulnerabilities in Polycom RealPresence Resource Manager (aka RPRM) before 8.4 allow (1) remote authenticated users to r…
Realpresence Resource Manager
after 8.3.2
HIGH 7.8
CVE-2015-8300
Polycom BToE Connector before 3.0.0 uses weak permissions (Everyone: Full Control) for "Program Files (x86)\polycom\polycom btoe connector\plcmbtoesr…
Btoe Connector
after 2.3.0
HIGH 8.8
CVE-2017-12857
Polycom SoundStation IP, VVX, and RealPresence Trio that are running software older than UCS 4.0.12, 5.4.5 rev AG, 5.4.7, 5.5.2, or 5.6.0 are affecte…
Unified Communications Software
after 5.5.1
HIGH 7.8
CVE-2007-3368
Buffer overflow in the HTTP server on the Polycom SoundPoint IP 601 SIP phone with BootROM 3.0.x+ allows remote attackers to cause a denial of servic…
Soundpoint Ip 650
Mitigation only
HIGH 7.8
CVE-2007-3369
Buffer overflow in the Polycom SoundPoint IP 601 SIP phone with BootROM 3.0.x+ and SIP version 1.6.3.0067 allows remote attackers to cause a denial o…
Soundpoint Ip 601
Mitigation only
HIGH 7.8
CVE-2006-5233
Polycom SoundPoint IP 301 VoIP Desktop Phone, firmware version 1.4.1.0040, allows remote attackers to cause a denial of service (reboot) via (1) a lo…
Soundpoint Ip 301
Mitigation only
MEDIUM 5.0
CVE-2003-0556
Polycom MGC 25 allows remote attackers to cause a denial of service (crash) via a large number of "user" requests to the control port 5003, as demons…
Mgc 100
Mitigation only
HIGH 10.0
CVE-2002-0626
Polycom ViewStation before 7.2.4 has a default null password for the administrator account, which allows arbitrary users to conduct unauthorized acti…
Viewstation 128
Patch available