CVE Browser

Search and filter CVEs by severity, ecosystem, EPSS score, and more.

Clear
More filters (active)

Page 1 (more results available)

CVE-2025-34093 HIGH

Polycom HDX Series Telnet Command Injection via lan traceroute

CVSS 7.5 EPSS 2.89% Jul 10, 2025
CVE-2021-41322 HIGH

Poly VVX 400/410 5.3.1 allows low-privileged users to change the Admin password by modifying a POST parameter to 120 during the password reset process.

CVSS 8.8 EPSS 1.70% Oct 4, 2021
CVE-2019-11355 HIGH

An issue was discovered in Poly (formerly Polycom) HDX 3.1.13. A feature exists that allows the creation of a server / client certificate, or the upload of the…

CVSS 7.2 EPSS 1.08% Mar 12, 2020
CVE-2012-6611 CRITICAL

An issue was discovered in Polycom Web Management Interface G3/HDX 8000 HD with Durango 2.6.0 4740 software and embedded Polycom Linux Development Platform 2.1…

CVSS 9.8 EPSS 3.14% Feb 10, 2020
CVE-2012-6609 HIGH

Directory traversal vulnerability in a_getlog.cgi in Polycom HDX Video End Points before 3.0.4 and UC APL before 2.7.1.J allows remote attackers to read arbitr…

CVSS 7.5 EPSS 2.12% Jan 28, 2020
CVE-2012-6610 HIGH

Polycom HDX Video End Points before 3.0.4 and UC APL before 2.7.1.J allows remote authenticated users to execute arbitrary commands as demonstrated by a ; (sem…

CVSS 8.8 EPSS 10.88% Jan 28, 2020
CVE-2019-14259 HIGH

On the Polycom Obihai Obi1022 VoIP phone with firmware 5.1.11, a command injection (missing input validation) issue in the NTP server IP address field for the…

CVSS 8.0 EPSS 2.80% Aug 1, 2019
CVE-2019-12948 HIGH

A vulnerability in the web-based management interface of VVX, Trio, SoundStructure, SoundPoint, and SoundStation phones running Polycom UC Software, if exploit…

CVSS 8.3 EPSS 1.73% Jul 29, 2019
CVE-2019-10689 MEDIUM

VVX products using UCS software version 5.9.2 and earlier with Better Together over Ethernet Connector (BToE) application version 3.9.1 and earlier provides in…

CVSS 6.5 EPSS 0.72% Jun 24, 2019
CVE-2018-10947 LOW

An issue was discovered in versions earlier than 1.3.2 for Polycom RealPresence Debut where the admin cookie is reset only after a Debut is rebooted.

CVSS 3.1 EPSS 0.42% Jun 13, 2019
CVE-2018-10946 MEDIUM

An issue was discovered in versions earlier than 1.3.0-66872 for Polycom RealPresence Debut that allows attackers to arbitrarily read the admin user's password…

CVSS 6.8 EPSS 0.49% Jun 13, 2019
CVE-2018-15128 CRITICAL

An issue was discovered in Polycom Group Series 6.1.6.1 and earlier, HDX 3.1.12 and earlier, and Pano 1.1.1 and earlier. A remote code execution vulnerability…

CVSS 9.8 EPSS 5.24% May 13, 2019
CVE-2019-10688 MEDIUM

VVX products with software versions including and prior to, UCS 5.9.2 with Better Together over Ethernet Connector (BToE) application 3.9.1, use hard-coded cre…

CVSS 6.8 EPSS 0.32% Apr 23, 2019
CVE-2018-14935 MEDIUM

The Web administration console on Polycom Trio devices with software before 5.5.4 has XSS.

CVSS 6.1 EPSS 0.65% Nov 15, 2018
CVE-2018-14934 MEDIUM

The Bluetooth subsystem on Polycom Trio devices with software before 5.5.4 has Incorrect Access Control. An attacker can connect without authentication and sub…

CVSS 6.5 EPSS 0.54% Nov 15, 2018
CVE-2018-18568 MEDIUM

Polycom VVX 500 and 601 devices 5.8.0.12848 and earlier allows man-in-the-middle attackers to obtain sensitive credential information by leveraging failure to…

CVSS 5.9 EPSS 0.73% Oct 24, 2018
CVE-2018-18566 MEDIUM

The SIP service in Polycom VVX 500 and 601 devices 5.8.0.12848 and earlier allow remote attackers to obtain sensitive phone configuration information by levera…

CVSS 5.3 EPSS 2.75% Oct 24, 2018
CVE-2018-12592 HIGH

Polycom RealPresence Web Suite before 2.2.0 does not block a user's video for a few seconds upon joining a meeting (when the user has explicitly chosen to turn…

CVSS 7.5 EPSS 1.44% Jun 20, 2018
CVE-2018-7565 HIGH

CSRF exists on Polycom QDX 6000 devices.

CVSS 8.8 EPSS 0.45% Mar 7, 2018
CVE-2018-7564 MEDIUM

Stored XSS exists on Polycom QDX 6000 devices.

CVSS 6.1 EPSS 0.64% Mar 7, 2018
CVE-2015-4685 HIGH

Polycom RealPresence Resource Manager (aka RPRM) before 8.4 allows local users with access to the plcm account to gain privileges via a script in /var/polycom/…

CVSS 7.0 EPSS 1.20% Sep 19, 2017
CVE-2015-4684 MEDIUM

Multiple directory traversal vulnerabilities in Polycom RealPresence Resource Manager (aka RPRM) before 8.4 allow (1) remote authenticated users to read arbitr…

CVSS 6.5 EPSS 4.93% Sep 19, 2017
CVE-2015-4683 CRITICAL

Polycom RealPresence Resource Manager (aka RPRM) before 8.4 allows attackers to obtain sensitive information and potentially gain privileges by leveraging use…

CVSS 9.8 EPSS 6.87% Sep 19, 2017
CVE-2015-4682 MEDIUM

Polycom RealPresence Resource Manager (aka RPRM) before 8.4 allows remote authenticated users to obtain the installation path via an HTTP POST request to PlcmR…

CVSS 6.5 EPSS 5.23% Sep 19, 2017
CVE-2015-4681 HIGH

Polycom RealPresence Resource Manager (aka RPRM) before 8.4 allows local users to have unspecified impact via vectors related to weak passwords.

CVSS 7.8 EPSS 1.70% Sep 19, 2017

Showing 1 to 25 CVEs · page 1 (more available)