Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2970▼ 106 respecto a la semana anterior
Críticas / altas1447▲ 86 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
123 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (8.8) | 1.6% | — | Polycom Unified Communications Software | 25/8/2017 | 17/6/2026 | Polycom SoundStation IP, VVX, and RealPresence Trio that are running software older than UCS 4.0.12, 5.4.5 rev AG, 5.4.7, 5.5.2, or 5.6.0 are affected by a vulnerability in their UCS web application. This vulnerability could allow an authenticated remote attacker to read a segment of the phone's memory which could… | |
| Modificada | Baja (3.5) | 0.83% | — | Polycom Realpresence Cloudaxis Suite | 3/9/2015 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in Polycom RealPresence CloudAXIS Suite before 1.7.0 allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors. | |
| Modificada | Baja (3.5) | 0.94% | — | Panopoly Magic Project Panopoly Magic | 26/2/2015 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in the live preview in the Panopoly Magic module before 7.x-1.17 for Drupal allows remote authenticated users to inject arbitrary web script or HTML via a pane title. | |
| Modificada | Media (4.3) | 1.6% | — | Polylang Plugin Project Polylang | 10/7/2014 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in the Polylang plugin before 1.5.2 for WordPress allows remote attackers to inject arbitrary web script or HTML via vectors related to a user description. NOTE: some of these details are obtained from third party information. | |
| Modificada | Media (4.3) | 1.1% | — | Polycom HDX System Software | 1/1/2013 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in the web management interface on Polycom HDX Video End Points with UC APL software before 2.7.1.1_J, and commercial software before 3.0.5, allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. | |
| Modificada | Alta (7.5) | 2.3% | — | Polyvision Roomwizard FirmwarePolyvision Roomwizard | 12/1/2011 | 16/6/2026 | The PolyVision RoomWizard with firmware 3.2.3 has a default password of roomwizard for the administrator account, which makes it easier for remote attackers to obtain console access via an HTTP session, a different vulnerability than CVE-2010-0214. | |
| Modificada | Media (5) | 1.9% | — | Polyvision Roomwizard FirmwarePolyvision Roomwizard | 12/1/2011 | 16/6/2026 | The administrative interface on the PolyVision RoomWizard with firmware 3.2.3 places the Sync Connector Active Directory (AD) credentials in a web form that is accessed over HTTP on port 80, which allows remote attackers to obtain sensitive information by reading the HTML source code corresponding to the… | |
| Modificada | Alta (7.5) | 1.0% | 💥 Exploit | Polypager | 6/8/2008 | 16/6/2026 | SQL injection vulnerability in PolyPager 1.0 rc2 and earlier allows remote attackers to execute arbitrary SQL commands via the nr parameter to the default URI. | |
| Modificada | Media (4.3) | 1.5% | 💥 Exploit | Polypager | 6/8/2008 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in PolyPager 1.0 rc2 and earlier allows remote attackers to inject arbitrary web script or HTML via the nr parameter to the default URI. | |
| Modificada | Media (4.3) | 0.85% | — | Polymita Technologies BPM SuitePolymita Technologies Collageportal | 17/3/2008 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in the search feature in Polymita BPM-Suite and CollagePortal allow remote attackers to inject arbitrary web script or HTML via the (1) _q and (2) lucene_index_field_value parameters. NOTE: the provenance of this information is unknown; the details are obtained… | |
| Modificada | Alta (7.8) | 1.8% | — | Polycom Soundpoint IP 650 | 22/6/2007 | 16/6/2026 | Buffer overflow in the HTTP server on the Polycom SoundPoint IP 601 SIP phone with BootROM 3.0.x+ allows remote attackers to cause a denial of service (device reboot) via a malformed CGI parameter. | |
| Modificada | Alta (7.8) | 2.2% | — | Polycom Soundpoint IP 601 | 22/6/2007 | 16/6/2026 | Buffer overflow in the Polycom SoundPoint IP 601 SIP phone with BootROM 3.0.x+ and SIP version 1.6.3.0067 allows remote attackers to cause a denial of service (device hang or reboot) via an INVITE message with a long Via header. | |
| Modificada | Alta (7.8) | 1.8% | — | Polycom Soundpoint IP 301 | 11/10/2006 | 16/6/2026 | Polycom SoundPoint IP 301 VoIP Desktop Phone, firmware version 1.4.1.0040, allows remote attackers to cause a denial of service (reboot) via (1) a long URL sent to the HTTP daemon and (2) unspecified manipulations as demonstrated by the Nessus http_fingerprinting_hmap.nasl script. | |
| Modificada | Media (6.8) | 1.3% | — | Polopoly | 22/12/2005 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in Polopoly 9 and earlier allows remote attackers to inject arbitrary web script or HTML via unspecified search parameters. NOTE: the vendor has disputed this vulnerability, stating that the "XSS flaw was only part of the custom implementation of the [polopoly] site". As of… | |
| Modificada | Baja (2.1) | 0.33% | — | Polygen | 6/9/2005 | 16/6/2026 | Polygen before 1.0.6 generates precompiled grammar objects with world-writable permissions, which allows local users to cause a denial of service (disk consumption) and possibly perform other unauthorized activities. | |
| Modificada | Media (5) | 1.3% | — | Polycom Mgc-100Polycom Mgc-25Polycom Mgc-50 | 18/8/2003 | 16/6/2026 | Polycom MGC 25 allows remote attackers to cause a denial of service (crash) via a large number of "user" requests to the control port 5003, as demonstrated using the blast TCP stress tester. | |
| Modificada | Media (5) | 1.6% | — | Polycom Viewstation 128Polycom Viewstation 512Polycom Viewstation DCPPolycom Viewstation FX Vs4000+4 | 7/1/2003 | 16/6/2026 | The Telnet service for Polycom ViewStation before 7.2.4 allows remote attackers to cause a denial of service (crash) via multiple connections to the server. | |
| Modificada | Media (5) | 1.6% | — | Polycom Viewstation 128Polycom Viewstation 512Polycom Viewstation DCPPolycom Viewstation FX Vs4000+4 | 7/1/2003 | 16/6/2026 | The Telnet service for Polycom ViewStation before 7.2.4 allows remote attackers to cause a denial of service (crash) via long or malformed ICMP packets. | |
| Modificada | Alta (10) | 1.8% | — | Polycom Viewstation 128Polycom Viewstation 512Polycom Viewstation DCPPolycom Viewstation FX Vs4000+4 | 7/1/2003 | 16/6/2026 | Polycom ViewStation before 7.2.4 has a default null password for the administrator account, which allows arbitrary users to conduct unauthorized activities. | |
| Modificada | Alta (7.5) | 1.6% | — | Polycom Viewstation 128Polycom Viewstation 512Polycom Viewstation DCPPolycom Viewstation FX Vs4000+4 | 7/1/2003 | 16/6/2026 | The Web server for Polycom ViewStation before 7.2.4 allows remote attackers to bypass authentication and read files via Unicode encoded requests. | |
| Modificada | Alta (7.5) | 2.2% | — | Polycom Viewstation 128Polycom Viewstation 512Polycom Viewstation DCPPolycom Viewstation FX Vs4000+4 | 7/1/2003 | 16/6/2026 | The Telnet service for Polycom ViewStation before 7.2.4 does not restrict the number of failed login attempts, which makes it easier for remote attackers to guess usernames and passwords via a brute force attack. | |
| Modificada | Media (5) | 7.1% | 💥 Exploit | Polycom Viavideo | 31/12/2002 | 16/6/2026 | The web server for Polycom ViaVideo 2.2 and 3.0 allows remote attackers to cause a denial of service (CPU consumption) by sending incomplete HTTP requests and leaving the connections open. | |
| Modificada | Media (5) | 7.5% | 💥 Exploit | Polycom Viavideo | 31/12/2002 | 16/6/2026 | Buffer overflow in the web server of Polycom ViaVideo 2.2 and 3.0 allows remote attackers to cause a denial of service (crash) via a long HTTP GET request. |