Products: 7
    Vulnerabilities: 8
    Known Exploited: 0
    0
    Critical Level Threats
    3
    High Level Threats
    4
    Medium Level Threats
    0
    Low Level Threats

    Vulnerabilities

    100806040200
    JanFebMarAprMayJunJulAugSepOctNovDec
    Critical Level Threats
    High Level Threats
    Medium Level Threats
    Low Level Threats

    Products Security index

    Actions
    Items Per Page

    Vulnerabilities

    CVE-2025-70420

    DO NOT USE THIS CVE RECORD. ConsultIDs: none. Reason: This record was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none.

    Last Modified: Jun 10, 2026
    Published: Apr 21, 2026

    CVE-2023-23208

    Genesys Administrator Extension (GAX) before 9.0.105.15 is vulnerable to Cross Site Scripting (XSS) via the Business Structure page of the iWD plugin, aka GAX-11261.

    Last Modified: Nov 21, 2024
    Published: Aug 13, 2023

    CVE-2023-29930

    An issue was found in Genesys CIC Polycom phone provisioning TFTP Server all version allows a remote attacker to execute arbitrary code via the login crednetials to the TFTP server configuration page.

    Last Modified: Jan 27, 2025
    Published: May 10, 2023

    CVE-2022-37775

    Genesys PureConnect Interaction Web Tools Chat Service (up to at least 26- September- 2019) allows XSS within the Printable Chat History via the participant -> name JSON POST parameter.

    Last Modified: Nov 21, 2024
    Published: Sep 16, 2022

    CVE-2021-26787

    A cross site scripting (XSS) vulnerability in Genesys Workforce Management 8.5.214.20 can occur (during record deletion) via the Time-off parameter.

    Last Modified: Jul 05, 2026
    Published: Dec 15, 2021
    Items Per Page