Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2684▼ 86 respecto a la semana anterior
Críticas / altas1444▲ 301 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)64▼ 462 respecto a la semana anterior
–

122 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaMedia (6.5)0.15%—PolylangAI30/9/202630/9/2026
Contributor Cross Site Scripting (XSS) in Polylang <= 3.8.9 versions.
AplazadaAlta (8.7)0.78%—PolyaxonAI15/9/202624/9/2026
Polyaxon through 2.16.4 renders operation specification fields with an unsandboxed Jinja2 environment during server-side run preparation, allowing authenticated users to execute arbitrary code. Attackers can submit runs with Jinja2 payloads in queue, namespace, conditions, presets, or dependencies fields to execute…
AplazadaMedia (6.8)0.13%—Asrock Polychrome SyncAIAsrock Polychrome RGBAI14/9/202618/9/2026
ASRock Polychrome SYNC/RGB software utility developed by ASRock Inc. has an Improper Access Control vulnerability. Authenticated local attackers can send a specially crafted IOCTL request to cause the driver to write to improperly restricted I/O ports, resulting in a forced operating system reboot.
AplazadaMedia (6.8)0.14%—Asrock Polychrome Sync RGBAI14/9/202618/9/2026
ASRock Polychrome SYNC/RGB software utility developed by ASRock Inc. has an Untrusted Pointer Dereference vulnerability. Authenticated local attackers can send a specially crafted IOCTL request to cause the driver to dereference an unvalidated pointer, resulting in an operating system crash.
AplazadaMedia (4.3)0.29%—Chouby PolylangAIChouby Polylang PROAI23/7/20266/8/2026
Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in Chouby Polylang and Chouby Polylang Pro allows Retrieve Embedded Sensitive Data. This issue affects Polylang: through 3.8.5; Polylang Pro: through 3.8.5.
Pendiente de análisisMedia (6.9)0.54%—Symfony Polyfill-intl-idnAI14/7/202615/7/2026
Symfony Polyfill backports PHP features and provides compatibility layers for extensions and functions. From 1.17.1 until 1.38.1, symfony/polyfill-intl-idn accepts xn-- labels whose Punycode payload is empty or decodes to ASCII-only code points because Idn::process() does not enforce the UTS #46 revision 33…
Pendiente de análisisAlta (8.2)0.43%—Poly CCXAIPoly TrioAIPoly Edge EAI1/7/20262/7/2026
The following Poly Voice IP devices, CCX, Trio, and Edge E, might be inoperable if they connect to a malicious SIP server and receive malformed data. HP is releasing updates to mitigate these potential vulnerabilities.
Pendiente de análisisCrítica (9.2)32%—Poly VoiceAI1/6/202631/8/2026
—
Pendiente de análisisCrítica (9.8)3.0%—Universal-robots PolyscopeAI8/5/202617/6/2026
OS command injection in Dashboard Server interface in Universal Robots PolyScope versions prior to 5.25.1 allows unauthenticated attacker to craft commands that will execute code on the robot's OS.
Pendiente de análisisAlta (8.2)0.09%—Poly VoiceAI3/3/202617/6/2026
An embedded test key and certificate could be extracted from a Poly Voice device using specialized reverse engineering tools. This extracted certificate could be accepted by a SIP service provider if the service provider does not perform proper validation of the device certificate.
AplazadaMedia (6.5)0.29%—Hyyan Woo-poly-integrationAI23/1/202617/6/2026
Missing Authorization vulnerability in Hyyan Abo Fakher Hyyan WooCommerce Polylang Integration woo-poly-integration allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Hyyan WooCommerce Polylang Integration: from n/a through <= 1.5.0.
AplazadaMedia (4.3)0.13%—Richardevcom Add-polylang-support-for-customizerAI22/1/202617/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in richardevcom Add Polylang support for Customizer add-polylang-support-for-customizer allows Cross Site Request Forgery.This issue affects Add Polylang support for Customizer: from n/a through <= 1.4.5.
AnalizadaAlta (8.1)0.40%—HP Poly VideoosHP Poly Tcos16/12/202530/9/2026
In limited scenarios, sensitive data might be written to the log file if an admin uses Microsoft Teams Admin Center (TAC) to make device configuration changes. The affected log file is visible only to users with admin credentials. This is limited to Microsoft TAC and does not affect configuration changes made using…
AplazadaAlta (8.8)0.36%—Chouby PolylangAI31/10/202517/6/2026
Deserialization of Untrusted Data vulnerability in Chouby Polylang polylang allows Object Injection.This issue affects Polylang: from n/a through <= 3.7.3.
AnalizadaAlta (7.3)0.29%—HP Poly Lens Desktop9/9/202517/6/2026
A vulnerability in the Poly Lens Desktop application running on the Windows platform might allow modifications to the filesystem, which might lead to SYSTEM level privileges being granted.
AnalizadaBaja (2)0.25%—HP Poly Clariti Manager23/7/202517/6/2026
A potential security vulnerability has been identified in the Poly Clariti Manager for versions prior to 10.12.1. The vulnerability could deserialize untrusted data without validation. HP has addressed the issue in the latest software update.
AnalizadaBaja (2)0.19%—HP Poly Clariti Manager23/7/202517/6/2026
A potential security vulnerability has been identified in the Poly Clariti Manager for versions prior to 10.12.2. The vulnerability could allow a bypass of the application's XSS filter by submitting untrusted characters. HP has addressed the issue in the latest software update.
AnalizadaMedia (6.9)0.23%—HP Poly Clariti Manager23/7/202517/6/2026
A potential privilege escalation through Sudo vulnerability has been identified in the Poly Clariti Manager for versions prior to 10.12.2. The firmware flaw does not properly implement access controls. HP has addressed the issue in the latest software update.
AnalizadaMedia (5.7)0.19%—HP Poly Clariti Manager23/7/202517/6/2026
A potential stored cross-site scripting vulnerability has been identified in the Poly Clariti Manager for versions prior to 10.12.1. The website allows user input to be stored and rendered without proper sanitization. HP has addressed the issue in the latest software update.
AnalizadaMedia (5.7)0.18%—HP Poly Clariti Manager23/7/202517/6/2026
A potential security vulnerability has been identified in the Poly Clariti Manager for versions prior to 10.12.2. The vulnerability could potentially allow a privileged user to retrieve credentials from the log files. HP has addressed the issue in the latest software update.
AnalizadaMedia (6)0.19%—HP Poly Clariti Manager23/7/202517/6/2026
A potential reflected cross-site scripting vulnerability has been identified in the Poly Clariti Manager for versions prior to 10.12.1. The website does not validate or sanitize the user input before rendering it in the response. HP has addressed the issue in the latest software update.
AnalizadaMedia (5.9)0.15%—HP Poly Clariti Manager23/7/202517/6/2026
A potential security vulnerability has been identified in the Poly Clariti Manager for versions prior to 10.12.1. The vulnerability could allow the retrieval of hardcoded cryptographic keys. HP has addressed the issue in the latest software update.
AnalizadaAlta (7.3)0.32%—HP Poly Clariti Manager22/7/202517/6/2026
A potential SQL injection vulnerability has been identified in the Poly Clariti Manager for versions prior to 10.12.1. The vulnerability could allow a privileged user to execute SQL commands. HP has addressed the issue in the latest software update.
AnalizadaMedia (5.9)0.15%—HP Poly Clariti Manager22/7/202517/6/2026
A potential security vulnerability has been identified in the Poly Clariti Manager for versions prior to 10.12.1. The vulnerability could allow the use and retrieval of the default password. HP has addressed the issue in the latest software update.
AnalizadaMedia (5.7)0.25%—HP Poly Clariti Manager22/7/202517/6/2026
A potential command injection vulnerability has been identified in the Poly Clariti Manager for versions prior to 10.12.2. The vulnerability could allow a privileged user to submit arbitrary input. HP has addressed the issue in the latest software update.