Skip to content
Signals
NVD · CVE-2026-64604 · In the Linux kernel, the following vulnerability has been resolved: KVM: VMX: Grab vmcs12 on CR8 interception update iff vCPU is in guest mode When updating CR8NVD · CVE-2026-64603 · In the Linux kernel, the following vulnerability has been resolved: platform/x86: intel-hid: Protect ACPI notify handler against recursion Since commit e2ffcda1NVD · CVE-2026-64602 · In the Linux kernel, the following vulnerability has been resolved: iio: adc: spear: Initialize completion before requesting IRQ In the report from Jaeyoung ChuNVD · CVE-2026-64601 · In the Linux kernel, the following vulnerability has been resolved: ALSA: us144mkii: capture_urb_complete: redundant usb_anchor_urb corrupts anchor list on eachCISA KEV · CVE-2026-63077 · 9.8 · JetBrains TeamCity Deserialization of Untrusted Data Vulnerability · Added 2026-08-05 · Due 2026-08-08CISA KEV · CVE-2026-18556 · 7.4 · N-able N-central Authentication Bypass Using an Alternate Path or Channel Vulnerability · Added 2026-08-04 · Due 2026-08-07NVD · CVE-2026-64604 · In the Linux kernel, the following vulnerability has been resolved: KVM: VMX: Grab vmcs12 on CR8 interception update iff vCPU is in guest mode When updating CR8NVD · CVE-2026-64603 · In the Linux kernel, the following vulnerability has been resolved: platform/x86: intel-hid: Protect ACPI notify handler against recursion Since commit e2ffcda1NVD · CVE-2026-64602 · In the Linux kernel, the following vulnerability has been resolved: iio: adc: spear: Initialize completion before requesting IRQ In the report from Jaeyoung ChuNVD · CVE-2026-64601 · In the Linux kernel, the following vulnerability has been resolved: ALSA: us144mkii: capture_urb_complete: redundant usb_anchor_urb corrupts anchor list on eachCISA KEV · CVE-2026-63077 · 9.8 · JetBrains TeamCity Deserialization of Untrusted Data Vulnerability · Added 2026-08-05 · Due 2026-08-08CISA KEV · CVE-2026-18556 · 7.4 · N-able N-central Authentication Bypass Using an Alternate Path or Channel Vulnerability · Added 2026-08-04 · Due 2026-08-07

Vendors · polycom

polycom

· 1 Critical

Total CVEs

39

Critical

1

Products

107

Search All CVEs →

39

Products (107)

unified communications software6 CVEsviewstation mp5 CVEsviewstation h.3235 CVEsviewstation fx vs40005 CVEsviewstation dcp5 CVEsviewstation v.355 CVEsviewstation 5125 CVEsviewstation 1285 CVEsrealpresence resource manager5 CVEsviewstation sp 3845 CVEstrio 85003 CVEshdx system software3 CVEshdx 90062 CVEshdx video end points2 CVEsbetter together over ethernet connector2 CVEshdx 40022 CVEshdx 45002 CVEshdx 60002 CVEshdx 70012 CVEshdx 70022 CVEshdx 80002 CVEshdx 80022 CVEshdx 80042 CVEshdx 80062 CVEshdx 90022 CVEshdx 90042 CVEsqdx 60002 CVEsqdx 6000 firmware2 CVEsrealpresence debut2 CVEsrealpresence debut firmware2 CVEssoundpoint ip 3012 CVEssoundpoint ip 6012 CVEssoundpoint ip 6502 CVEstrio 8500 firmware2 CVEsuc apl2 CVEsviavideo2 CVEsvvx 5002 CVEsvvx 500 firmware2 CVEsvvx 6012 CVEsvvx 601 firmware2 CVEssoundpoint ip 3311 CVEssoundpoint ip 3351 CVEssoundpoint ip 4301 CVEssoundpoint ip 4501 CVEssoundpoint ip 5001 CVEssoundpoint ip 5011 CVEssoundpoint ip 5501 CVEssoundpoint ip 5601 CVEssoundpoint ip 6001 CVEsvvx6011 CVEsvvx 4001 CVEssoundpoint ip 6701 CVEssoundpoint pro se-2201 CVEssoundpoint pro se-2251 CVEssoundstation21 CVEssoundstation2 avaya 24901 CVEssoundstation2 direct connect for nortel1 CVEssoundstation2w1 CVEssoundstation duo1 CVEssoundstation ip1 CVEssoundstation ip 40001 CVEssoundstation ip 50001 CVEssoundstation ip 60001 CVEssoundstation ip 70001 CVEssoundstation ip 7000 video integration1 CVEssoundstation vtx 10001 CVEsobihai obi10221 CVEsvvx 400 firmware1 CVEstrio 88001 CVEsvvx 4101 CVEsmgc-501 CVEsunited communications software1 CVEsvvx 410 firmware1 CVEsmgc-251 CVEsmgc-1001 CVEshdx1 CVEsgroup series1 CVEsc81 CVEsc161 CVEsc121 CVEsbtoe connector1 CVEsvvx1 CVEsvvx1501 CVEsvvx2011 CVEsvvx2501 CVEsvvx3001 CVEsvvx3011 CVEsvvx3101 CVEsvvx3111 CVEsvvx3501 CVEsvvx4001 CVEsvvx4011 CVEsvvx4101 CVEspano1 CVEsvvx4111 CVEsvvx4501 CVEsrealpresence cloudaxis suite1 CVEsvvx5001 CVEsvvx5011 CVEsobihai obi1022 firmware1 CVEsrealpresence trio1 CVEsrealpresence web suite1 CVEssoundpoint ip 3001 CVEsvvx6001 CVEssoundpoint ip 3201 CVEssoundpoint ip 3211 CVEssoundpoint ip 3301 CVEs

Recent Vulnerabilities

View all 39
CVE-2021-41322HIGH 8.8

Poly VVX 400/410 5.3.1 allows low-privileged users to change the Admin password by modifying a POST parameter to 120 during the password reset process.

CVE-2019-11355HIGH 7.2

An issue was discovered in Poly (formerly Polycom) HDX 3.1.13. A feature exists that allows the creation of a server / client certificate, or the upload of the user certificate, on the administrator's page. The value received from the user is the factor value of a shell script on the equipment. By entering a special character (such as a single quote) in a CN or other CSR field, one can insert a command into a factor value. A system command can be executed as root.

CVE-2012-6611CRITICAL 9.8

An issue was discovered in Polycom Web Management Interface G3/HDX 8000 HD with Durango 2.6.0 4740 software and embedded Polycom Linux Development Platform 2.14.g3. It has a blank administrative password by default, and can be successfully used without setting this password.

CVE-2012-6610HIGH 8.8

Polycom HDX Video End Points before 3.0.4 and UC APL before 2.7.1.J allows remote authenticated users to execute arbitrary commands as demonstrated by a ; (semicolon) to the ping command feature.

CVE-2012-6609HIGH 7.5

Directory traversal vulnerability in a_getlog.cgi in Polycom HDX Video End Points before 3.0.4 and UC APL before 2.7.1.J allows remote attackers to read arbitrary files via a .. (dot dot) in the name parameter.

CVE-2019-14259

On the Polycom Obihai Obi1022 VoIP phone with firmware 5.1.11, a command injection (missing input validation) issue in the NTP server IP address field for the "Time Service Settings web" interface allows an authenticated remote attacker in the same network to trigger OS commands via shell commands in a POST request.

CVE-2019-12948

A vulnerability in the web-based management interface of VVX, Trio, SoundStructure, SoundPoint, and SoundStation phones running Polycom UC Software, if exploited, could allow an authenticated, remote attacker with admin privileges to cause a denial of service (DoS) condition or execute arbitrary code.

CVE-2019-10689

VVX products using UCS software version 5.9.2 and earlier with Better Together over Ethernet Connector (BToE) application version 3.9.1 and earlier provides insufficient authentication between the BToE application and the BToE component, resulting in leakage of sensitive information.

CVE-2018-10947

An issue was discovered in versions earlier than 1.3.2 for Polycom RealPresence Debut where the admin cookie is reset only after a Debut is rebooted.

CVE-2018-10946

An issue was discovered in versions earlier than 1.3.0-66872 for Polycom RealPresence Debut that allows attackers to arbitrarily read the admin user's password via the admin web UI.

CVE-2018-15128

An issue was discovered in Polycom Group Series 6.1.6.1 and earlier, HDX 3.1.12 and earlier, and Pano 1.1.1 and earlier. A remote code execution vulnerability exists in the content sharing functionality because of a Buffer Overflow via crafted packets.

CVE-2019-10688

VVX products with software versions including and prior to, UCS 5.9.2 with Better Together over Ethernet Connector (BToE) application 3.9.1, use hard-coded credentials to establish connections between the host application and the device.

CVE-2018-14935

The Web administration console on Polycom Trio devices with software before 5.5.4 has XSS.

CVE-2018-14934

The Bluetooth subsystem on Polycom Trio devices with software before 5.5.4 has Incorrect Access Control. An attacker can connect without authentication and subsequently record audio from the device microphone.

CVE-2018-18568MEDIUM 5.9

Polycom VVX 500 and 601 devices 5.8.0.12848 and earlier allows man-in-the-middle attackers to obtain sensitive credential information by leveraging failure to validate X.509 certificates when used with an on-premise installation with Skype for Business.

CVE-2018-18566MEDIUM 5.3

The SIP service in Polycom VVX 500 and 601 devices 5.8.0.12848 and earlier allow remote attackers to obtain sensitive phone configuration information by leveraging use with an on-premise installation with Skype for Business.

CVE-2018-12592

Polycom RealPresence Web Suite before 2.2.0 does not block a user's video for a few seconds upon joining a meeting (when the user has explicitly chosen to turn off the video using a specific option). During those seconds, a meeting invitee may unknowingly be on camera with other participants able to view.

CVE-2018-7565

CSRF exists on Polycom QDX 6000 devices.

CVE-2018-7564

Stored XSS exists on Polycom QDX 6000 devices.

CVE-2015-4685

Polycom RealPresence Resource Manager (aka RPRM) before 8.4 allows local users with access to the plcm account to gain privileges via a script in /var/polycom/cma/upgrade/scripts, related to a sudo misconfiguration.

CVE-2015-4684

Multiple directory traversal vulnerabilities in Polycom RealPresence Resource Manager (aka RPRM) before 8.4 allow (1) remote authenticated users to read arbitrary files via a .. (dot dot) in the Modifier parameter to PlcmRmWeb/FileDownload; or remote authenticated administrators to upload arbitrary files via the (2) Filename or (3) SE_FNAME parameter to PlcmRmWeb/FileUpload or to read and remove arbitrary files via the (4) filePathName parameter in an importSipUriReservations SOAP request to PlcmRmWeb/JUserManager.

CVE-2015-4683

Polycom RealPresence Resource Manager (aka RPRM) before 8.4 allows attackers to obtain sensitive information and potentially gain privileges by leveraging use of session identifiers as parameters with HTTP GET requests.

CVE-2015-4682

Polycom RealPresence Resource Manager (aka RPRM) before 8.4 allows remote authenticated users to obtain the installation path via an HTTP POST request to PlcmRmWeb/JConfigManager.

CVE-2015-4681

Polycom RealPresence Resource Manager (aka RPRM) before 8.4 allows local users to have unspecified impact via vectors related to weak passwords.

CVE-2015-8300

Polycom BToE Connector before 3.0.0 uses weak permissions (Everyone: Full Control) for "Program Files (x86)\polycom\polycom btoe connector\plcmbtoesrv.exe," which allows local users to gain privileges via a Trojan horse file.