Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2614▼ 473 respecto a la semana anterior
Críticas / altas1270▼ 74 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)243▼ 274 respecto a la semana anterior
–

123 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaMedia (5.7)0.25%—HP Poly Clariti Manager22/7/202517/6/2026
A potential command injection vulnerability has been identified in the Poly Clariti Manager for versions prior to 10.12.2. The vulnerability could allow a privileged user to submit arbitrary input. HP has addressed the issue in the latest software update.
AplazadaAlta (7.5)2.9%—Polycom HDX SeriesAI10/7/202517/6/2026
An authenticated command injection vulnerability exists in the Polycom HDX Series command shell interface accessible over Telnet. The lan traceroute command in the devcmds console accepts unsanitized input, allowing attackers to execute arbitrary system commands. By injecting shell metacharacters through the…
AplazadaMedia (6.5)0.24%—PolyaxonAI20/3/202517/6/2026
A Cross-Site Request Forgery (CSRF) vulnerability in polyaxon/polyaxon v2.4.0 allows attackers to perform unauthorized actions in the context of the victim's browser. This includes creating projects, model versions, and artifact versions, or changing settings. The impact of this vulnerability includes potential data…
AplazadaAlta (7.5)1.0%—PolyaxonAI20/3/202517/6/2026
An unauthorized file deletion vulnerability exists in the latest version of the Polyaxon platform, which can lead to denial of service by terminating critical containers. An attacker can delete important files within the containers, such as `polyaxon.sock`, causing the API container to exit unexpectedly. This disrupts…
AplazadaAlta (7.5)4.3%—PolyaxonAI20/3/202517/6/2026
An unauthenticated directory traversal vulnerability exists in Polyaxon, affecting the latest version. This vulnerability allows an attacker to retrieve directory information and file contents from the server without proper authorization, leading to sensitive information disclosure. The issue enables access to system…
AplazadaMedia (5.8)0.27%—PolyAI5/2/202517/6/2026
A vulnerability was discovered in the firmware builds up to 8.2.1.0820 in certain Poly devices. The firmware flaw does not properly prevent path traversal and could lead to information disclosure.
AplazadaAlta (7.5)0.37%—Polycom Realpresence Group 500AI3/2/202517/6/2026
Polycom RealPresence Group 500 <=20 has Insecure Permissions due to automatically loaded cookies. This allows for the use of administrator functions, resulting in the leakage of sensitive user information.
AplazadaMedia (6.5)0.32%—Cloud Whale Interactive Technology LLC Polybuzz IOSAI27/1/202517/6/2026
An issue in Cloud Whale Interactive Technology LLC. PolyBuzz iOS 2.0.20 allows attackers to access sensitive user information via supplying a crafted link.
AnalizadaAlta (7.5)0.40%—HP Poly TC8 FirmwareHP Poly Tc10 FirmwareHP Poly Studio G7500 FirmwareHP Poly Studio X30 Firmware+45/11/202417/6/2026
A potential vulnerability was discovered in certain Poly video conferencing devices. The firmware flaw does not properly sanitize user input. The exploitation of this vulnerability is dependent on a layered attack and cannot be exploited by itself.
AnalizadaCrítica (9.8)0.51%—HP Poly Clariti Manager7/8/202417/6/2026
A vulnerability was discovered in the firmware builds up to 10.10.2.2 in Poly Clariti Manager devices. The firmware flaw does not properly implement access controls.
AnalizadaAlta (8.8)0.52%—HP Poly Clariti Manager6/8/202417/6/2026
A vulnerability was discovered in the firmware builds up to 10.10.2.2 in Poly Clariti Manager devices. The firmware flaw does not properly sanitize User input.
AnalizadaMedia (5.4)0.26%—HP Poly Clariti Manager6/8/202417/6/2026
A vulnerability was discovered in the firmware builds up to 10.10.2.2 in Poly Clariti Manager devices. The flaw does not properly neutralize input during a web page generation.
AnalizadaMedia (6.1)0.28%—HP Poly Clariti Manager6/8/202417/6/2026
A vulnerability was discovered in the firmware builds up to 10.10.2.2 in Poly Clariti Manager devices. The firmware contained multiple XSS vulnerabilities in the version of JavaScript used.
AplazadaAlta (7.2)3.8%—PdocAIPolyfill.ioAI26/6/202417/6/2026
pdoc provides API Documentation for Python Projects. Documentation generated with `pdoc --math` linked to JavaScript files from polyfill.io. The polyfill.io CDN has been sold and now serves malicious code. This issue has been fixed in pdoc 14.5.1.
ModificadaAlta (7.8)0.39%—HP Poly Plantronics HUB20/6/202417/6/2026
Poly Plantronics Hub Link Following Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of Poly Plantronics Hub. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this…
AnalizadaMedia (6.7)1.7%—HP Poly Plantronics HUB14/5/202417/6/2026
A privilege escalation exists in the updater for Plantronics Hub 3.25.1 and below.
AnalizadaAlta (8.8)0.50%—HP Poly CCX 350HP Poly CCX 400HP Poly CCX 500HP Poly CCX 505+29/4/202417/6/2026
A vulnerability was discovered in the firmware builds after 8.0.2.3267 and prior to 8.1.3.1301 in CCX devices. A flaw in the firmware build process did not properly restrict access to a resource from an unauthorized actor.
ModificadaCrítica (9.8)0.90%—Glitchedpolygons L8w8jwt8/2/202417/6/2026
l8w8jwt 2.2.1 uses memcmp (which is not constant time) to verify authentication, which makes it easier to bypass authentication via a timing side channel.
ModificadaAlta (7.6)0.25%—Poly Trio 8800 FirmwarePoly Trio C60Poly Lens29/12/202317/6/2026
A vulnerability was found in Poly Trio 8500, Trio 8800 and Trio C60. It has been classified as problematic. This affects an unknown part of the component Poly Lens Management Cloud Registration. The manipulation leads to missing authorization. It is possible to launch the attack on the physical device. The exploit has…
ModificadaMedia (6.6)0.26%—Poly Trio 8800 Firmware29/12/202317/6/2026
A vulnerability was found in Poly Trio 8800 7.2.6.0019 and classified as critical. Affected by this issue is some unknown functionality of the component Test Automation Mode. The manipulation leads to backdoor. It is possible to launch the attack on the physical device. The exploit has been disclosed to the public and…
ModificadaMedia (4.9)0.51%—Poly CCX 400 FirmwarePoly CCX 600 FirmwarePoly Trio 8800 FirmwarePoly Trio C60 Firmware29/12/202317/6/2026
A vulnerability has been found in Poly CCX 400, CCX 600, Trio 8800 and Trio C60 and classified as problematic. Affected by this vulnerability is an unknown functionality of the component Web Interface. The manipulation leads to protection mechanism failure. The attack can be launched remotely. The vendor explains that…
ModificadaMedia (6.5)0.46%—Poly CCX 400 FirmwarePoly CCX 600 FirmwarePoly Trio 8800 FirmwarePoly Trio C60 Firmware29/12/202317/6/2026
A vulnerability, which was classified as problematic, was found in Poly Trio 8300, Trio 8500, Trio 8800, Trio C60, CCX 350, CCX 400, CCX 500, CCX 505, CCX 600, CCX 700, EDGE E100, EDGE E220, EDGE E300, EDGE E320, EDGE E350, EDGE E400, EDGE E450, EDGE E500, EDGE E550, VVX 101, VVX 150, VVX 201, VVX 250, VVX 300, VVX…
ModificadaAlta (7.2)3.3%—Poly CCX 400 FirmwarePoly CCX 600 FirmwarePoly Trio 8800 FirmwarePoly Trio C60 Firmware29/12/202317/6/2026
A vulnerability, which was classified as critical, has been found in Poly Trio 8300, Trio 8500, Trio 8800, Trio C60, CCX 350, CCX 400, CCX 500, CCX 505, CCX 600, CCX 700, EDGE E100, EDGE E220, EDGE E300, EDGE E320, EDGE E350, EDGE E400, EDGE E450, EDGE E500, EDGE E550, VVX 101, VVX 150, VVX 201, VVX 250, VVX 300, VVX…
ModificadaAlta (7.5)1.0%—Poly CCX 400 FirmwarePoly CCX 600 FirmwarePoly Trio 8800 FirmwarePoly Trio C60 Firmware29/12/202317/6/2026
A vulnerability classified as problematic was found in Poly CCX 400, CCX 600, Trio 8800 and Trio C60. This vulnerability affects unknown code of the component HTTP Header Handler. The manipulation of the argument Cookie leads to denial of service. The attack can be initiated remotely. The exploit has been disclosed to…
ModificadaMedia (5.9)0.92%—Poly CCX 400 FirmwarePoly CCX 600 FirmwarePoly Trio 8800 FirmwarePoly Trio C60 Firmware29/12/202317/6/2026
A vulnerability classified as problematic has been found in Poly Trio 8300, Trio 8500, Trio 8800, Trio C60, CCX 350, CCX 400, CCX 500, CCX 505, CCX 600, CCX 700, EDGE E100, EDGE E220, EDGE E300, EDGE E320, EDGE E350, EDGE E400, EDGE E450, EDGE E500, EDGE E550, VVX 101, VVX 150, VVX 201, VVX 250, VVX 300, VVX 301, VVX…