Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2970▼ 106 respecto a la semana anterior
Críticas / altas1447▲ 86 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
–

123 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (8.8)1.6%—Polycom Unified Communications Software25/8/201717/6/2026
Polycom SoundStation IP, VVX, and RealPresence Trio that are running software older than UCS 4.0.12, 5.4.5 rev AG, 5.4.7, 5.5.2, or 5.6.0 are affected by a vulnerability in their UCS web application. This vulnerability could allow an authenticated remote attacker to read a segment of the phone's memory which could…
ModificadaBaja (3.5)0.83%—Polycom Realpresence Cloudaxis Suite3/9/201517/6/2026
Cross-site scripting (XSS) vulnerability in Polycom RealPresence CloudAXIS Suite before 1.7.0 allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors.
ModificadaBaja (3.5)0.94%—Panopoly Magic Project Panopoly Magic26/2/201517/6/2026
Cross-site scripting (XSS) vulnerability in the live preview in the Panopoly Magic module before 7.x-1.17 for Drupal allows remote authenticated users to inject arbitrary web script or HTML via a pane title.
ModificadaMedia (4.3)1.6%—Polylang Plugin Project Polylang10/7/201417/6/2026
Cross-site scripting (XSS) vulnerability in the Polylang plugin before 1.5.2 for WordPress allows remote attackers to inject arbitrary web script or HTML via vectors related to a user description. NOTE: some of these details are obtained from third party information.
ModificadaMedia (4.3)1.1%—Polycom HDX System Software1/1/201316/6/2026
Cross-site scripting (XSS) vulnerability in the web management interface on Polycom HDX Video End Points with UC APL software before 2.7.1.1_J, and commercial software before 3.0.5, allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
ModificadaAlta (7.5)2.3%—Polyvision Roomwizard FirmwarePolyvision Roomwizard12/1/201116/6/2026
The PolyVision RoomWizard with firmware 3.2.3 has a default password of roomwizard for the administrator account, which makes it easier for remote attackers to obtain console access via an HTTP session, a different vulnerability than CVE-2010-0214.
ModificadaMedia (5)1.9%—Polyvision Roomwizard FirmwarePolyvision Roomwizard12/1/201116/6/2026
The administrative interface on the PolyVision RoomWizard with firmware 3.2.3 places the Sync Connector Active Directory (AD) credentials in a web form that is accessed over HTTP on port 80, which allows remote attackers to obtain sensitive information by reading the HTML source code corresponding to the…
ModificadaAlta (7.5)1.0%💥 ExploitPolypager6/8/200816/6/2026
SQL injection vulnerability in PolyPager 1.0 rc2 and earlier allows remote attackers to execute arbitrary SQL commands via the nr parameter to the default URI.
ModificadaMedia (4.3)1.5%💥 ExploitPolypager6/8/200816/6/2026
Cross-site scripting (XSS) vulnerability in PolyPager 1.0 rc2 and earlier allows remote attackers to inject arbitrary web script or HTML via the nr parameter to the default URI.
ModificadaMedia (4.3)0.85%—Polymita Technologies BPM SuitePolymita Technologies Collageportal17/3/200816/6/2026
Multiple cross-site scripting (XSS) vulnerabilities in the search feature in Polymita BPM-Suite and CollagePortal allow remote attackers to inject arbitrary web script or HTML via the (1) _q and (2) lucene_index_field_value parameters. NOTE: the provenance of this information is unknown; the details are obtained…
ModificadaAlta (7.8)1.8%—Polycom Soundpoint IP 65022/6/200716/6/2026
Buffer overflow in the HTTP server on the Polycom SoundPoint IP 601 SIP phone with BootROM 3.0.x+ allows remote attackers to cause a denial of service (device reboot) via a malformed CGI parameter.
ModificadaAlta (7.8)2.2%—Polycom Soundpoint IP 60122/6/200716/6/2026
Buffer overflow in the Polycom SoundPoint IP 601 SIP phone with BootROM 3.0.x+ and SIP version 1.6.3.0067 allows remote attackers to cause a denial of service (device hang or reboot) via an INVITE message with a long Via header.
ModificadaAlta (7.8)1.8%—Polycom Soundpoint IP 30111/10/200616/6/2026
Polycom SoundPoint IP 301 VoIP Desktop Phone, firmware version 1.4.1.0040, allows remote attackers to cause a denial of service (reboot) via (1) a long URL sent to the HTTP daemon and (2) unspecified manipulations as demonstrated by the Nessus http_fingerprinting_hmap.nasl script.
ModificadaMedia (6.8)1.3%—Polopoly22/12/200516/6/2026
Cross-site scripting (XSS) vulnerability in Polopoly 9 and earlier allows remote attackers to inject arbitrary web script or HTML via unspecified search parameters. NOTE: the vendor has disputed this vulnerability, stating that the "XSS flaw was only part of the custom implementation of the [polopoly] site". As of…
ModificadaBaja (2.1)0.33%—Polygen6/9/200516/6/2026
Polygen before 1.0.6 generates precompiled grammar objects with world-writable permissions, which allows local users to cause a denial of service (disk consumption) and possibly perform other unauthorized activities.
ModificadaMedia (5)1.3%—Polycom Mgc-100Polycom Mgc-25Polycom Mgc-5018/8/200316/6/2026
Polycom MGC 25 allows remote attackers to cause a denial of service (crash) via a large number of "user" requests to the control port 5003, as demonstrated using the blast TCP stress tester.
ModificadaMedia (5)1.6%—Polycom Viewstation 128Polycom Viewstation 512Polycom Viewstation DCPPolycom Viewstation FX Vs4000+47/1/200316/6/2026
The Telnet service for Polycom ViewStation before 7.2.4 allows remote attackers to cause a denial of service (crash) via multiple connections to the server.
ModificadaMedia (5)1.6%—Polycom Viewstation 128Polycom Viewstation 512Polycom Viewstation DCPPolycom Viewstation FX Vs4000+47/1/200316/6/2026
The Telnet service for Polycom ViewStation before 7.2.4 allows remote attackers to cause a denial of service (crash) via long or malformed ICMP packets.
ModificadaAlta (10)1.8%—Polycom Viewstation 128Polycom Viewstation 512Polycom Viewstation DCPPolycom Viewstation FX Vs4000+47/1/200316/6/2026
Polycom ViewStation before 7.2.4 has a default null password for the administrator account, which allows arbitrary users to conduct unauthorized activities.
ModificadaAlta (7.5)1.6%—Polycom Viewstation 128Polycom Viewstation 512Polycom Viewstation DCPPolycom Viewstation FX Vs4000+47/1/200316/6/2026
The Web server for Polycom ViewStation before 7.2.4 allows remote attackers to bypass authentication and read files via Unicode encoded requests.
ModificadaAlta (7.5)2.2%—Polycom Viewstation 128Polycom Viewstation 512Polycom Viewstation DCPPolycom Viewstation FX Vs4000+47/1/200316/6/2026
The Telnet service for Polycom ViewStation before 7.2.4 does not restrict the number of failed login attempts, which makes it easier for remote attackers to guess usernames and passwords via a brute force attack.
ModificadaMedia (5)7.1%💥 ExploitPolycom Viavideo31/12/200216/6/2026
The web server for Polycom ViaVideo 2.2 and 3.0 allows remote attackers to cause a denial of service (CPU consumption) by sending incomplete HTTP requests and leaving the connections open.
ModificadaMedia (5)7.5%💥 ExploitPolycom Viavideo31/12/200216/6/2026
Buffer overflow in the web server of Polycom ViaVideo 2.2 and 3.0 allows remote attackers to cause a denial of service (crash) via a long HTTP GET request.
Orbitaley — Vulnerabilidades