Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2987▼ 96 respecto a la semana anterior
Críticas / altas1458▲ 101 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
41 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.8) | 1.7% | 💥 Exploit | Polycom Realpresence Resource Manager | 19/9/2017 | 17/6/2026 | Polycom RealPresence Resource Manager (aka RPRM) before 8.4 allows local users to have unspecified impact via vectors related to weak passwords. | |
| Modificada | Alta (7.8) | 0.55% | — | Polycom Btoe Connector | 28/8/2017 | 17/6/2026 | Polycom BToE Connector before 3.0.0 uses weak permissions (Everyone: Full Control) for "Program Files (x86)\polycom\polycom btoe connector\plcmbtoesrv.exe," which allows local users to gain privileges via a Trojan horse file. | |
| Modificada | Alta (8.8) | 1.6% | — | Polycom Unified Communications Software | 25/8/2017 | 17/6/2026 | Polycom SoundStation IP, VVX, and RealPresence Trio that are running software older than UCS 4.0.12, 5.4.5 rev AG, 5.4.7, 5.5.2, or 5.6.0 are affected by a vulnerability in their UCS web application. This vulnerability could allow an authenticated remote attacker to read a segment of the phone's memory which could… | |
| Modificada | Baja (3.5) | 0.83% | — | Polycom Realpresence Cloudaxis Suite | 3/9/2015 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in Polycom RealPresence CloudAXIS Suite before 1.7.0 allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors. | |
| Modificada | Media (4.3) | 1.1% | — | Polycom HDX System Software | 1/1/2013 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in the web management interface on Polycom HDX Video End Points with UC APL software before 2.7.1.1_J, and commercial software before 3.0.5, allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. | |
| Modificada | Alta (7.8) | 2.2% | — | Polycom Soundpoint IP 601 | 22/6/2007 | 16/6/2026 | Buffer overflow in the Polycom SoundPoint IP 601 SIP phone with BootROM 3.0.x+ and SIP version 1.6.3.0067 allows remote attackers to cause a denial of service (device hang or reboot) via an INVITE message with a long Via header. | |
| Modificada | Alta (7.8) | 1.8% | — | Polycom Soundpoint IP 650 | 22/6/2007 | 16/6/2026 | Buffer overflow in the HTTP server on the Polycom SoundPoint IP 601 SIP phone with BootROM 3.0.x+ allows remote attackers to cause a denial of service (device reboot) via a malformed CGI parameter. | |
| Modificada | Alta (7.8) | 1.8% | — | Polycom Soundpoint IP 301 | 11/10/2006 | 16/6/2026 | Polycom SoundPoint IP 301 VoIP Desktop Phone, firmware version 1.4.1.0040, allows remote attackers to cause a denial of service (reboot) via (1) a long URL sent to the HTTP daemon and (2) unspecified manipulations as demonstrated by the Nessus http_fingerprinting_hmap.nasl script. | |
| Modificada | Media (5) | 1.3% | — | Polycom Mgc-100Polycom Mgc-25Polycom Mgc-50 | 18/8/2003 | 16/6/2026 | Polycom MGC 25 allows remote attackers to cause a denial of service (crash) via a large number of "user" requests to the control port 5003, as demonstrated using the blast TCP stress tester. | |
| Modificada | Alta (10) | 1.8% | — | Polycom Viewstation 128Polycom Viewstation 512Polycom Viewstation DCPPolycom Viewstation FX Vs4000+4 | 7/1/2003 | 16/6/2026 | Polycom ViewStation before 7.2.4 has a default null password for the administrator account, which allows arbitrary users to conduct unauthorized activities. | |
| Modificada | Alta (7.5) | 2.2% | — | Polycom Viewstation 128Polycom Viewstation 512Polycom Viewstation DCPPolycom Viewstation FX Vs4000+4 | 7/1/2003 | 16/6/2026 | The Telnet service for Polycom ViewStation before 7.2.4 does not restrict the number of failed login attempts, which makes it easier for remote attackers to guess usernames and passwords via a brute force attack. | |
| Modificada | Media (5) | 1.6% | — | Polycom Viewstation 128Polycom Viewstation 512Polycom Viewstation DCPPolycom Viewstation FX Vs4000+4 | 7/1/2003 | 16/6/2026 | The Telnet service for Polycom ViewStation before 7.2.4 allows remote attackers to cause a denial of service (crash) via long or malformed ICMP packets. | |
| Modificada | Media (5) | 1.6% | — | Polycom Viewstation 128Polycom Viewstation 512Polycom Viewstation DCPPolycom Viewstation FX Vs4000+4 | 7/1/2003 | 16/6/2026 | The Telnet service for Polycom ViewStation before 7.2.4 allows remote attackers to cause a denial of service (crash) via multiple connections to the server. | |
| Modificada | Alta (7.5) | 1.6% | — | Polycom Viewstation 128Polycom Viewstation 512Polycom Viewstation DCPPolycom Viewstation FX Vs4000+4 | 7/1/2003 | 16/6/2026 | The Web server for Polycom ViewStation before 7.2.4 allows remote attackers to bypass authentication and read files via Unicode encoded requests. | |
| Modificada | Media (5) | 7.5% | 💥 Exploit | Polycom Viavideo | 31/12/2002 | 16/6/2026 | Buffer overflow in the web server of Polycom ViaVideo 2.2 and 3.0 allows remote attackers to cause a denial of service (crash) via a long HTTP GET request. | |
| Modificada | Media (5) | 7.1% | 💥 Exploit | Polycom Viavideo | 31/12/2002 | 16/6/2026 | The web server for Polycom ViaVideo 2.2 and 3.0 allows remote attackers to cause a denial of service (CPU consumption) by sending incomplete HTTP requests and leaving the connections open. |