Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2684▼ 86 respecto a la semana anterior
Críticas / altas1444▲ 301 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)64▼ 462 respecto a la semana anterior
122 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (6.5) | 0.15% | — | PolylangAI | 30/9/2026 | 30/9/2026 | Contributor Cross Site Scripting (XSS) in Polylang <= 3.8.9 versions. | |
| Aplazada | Alta (8.7) | 0.78% | — | PolyaxonAI | 15/9/2026 | 24/9/2026 | Polyaxon through 2.16.4 renders operation specification fields with an unsandboxed Jinja2 environment during server-side run preparation, allowing authenticated users to execute arbitrary code. Attackers can submit runs with Jinja2 payloads in queue, namespace, conditions, presets, or dependencies fields to execute… | |
| Aplazada | Media (6.8) | 0.13% | — | Asrock Polychrome SyncAIAsrock Polychrome RGBAI | 14/9/2026 | 18/9/2026 | ASRock Polychrome SYNC/RGB software utility developed by ASRock Inc. has an Improper Access Control vulnerability. Authenticated local attackers can send a specially crafted IOCTL request to cause the driver to write to improperly restricted I/O ports, resulting in a forced operating system reboot. | |
| Aplazada | Media (6.8) | 0.14% | — | Asrock Polychrome Sync RGBAI | 14/9/2026 | 18/9/2026 | ASRock Polychrome SYNC/RGB software utility developed by ASRock Inc. has an Untrusted Pointer Dereference vulnerability. Authenticated local attackers can send a specially crafted IOCTL request to cause the driver to dereference an unvalidated pointer, resulting in an operating system crash. | |
| Aplazada | Media (4.3) | 0.29% | — | Chouby PolylangAIChouby Polylang PROAI | 23/7/2026 | 6/8/2026 | Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in Chouby Polylang and Chouby Polylang Pro allows Retrieve Embedded Sensitive Data. This issue affects Polylang: through 3.8.5; Polylang Pro: through 3.8.5. | |
| Pendiente de análisis | Media (6.9) | 0.54% | — | Symfony Polyfill-intl-idnAI | 14/7/2026 | 15/7/2026 | Symfony Polyfill backports PHP features and provides compatibility layers for extensions and functions. From 1.17.1 until 1.38.1, symfony/polyfill-intl-idn accepts xn-- labels whose Punycode payload is empty or decodes to ASCII-only code points because Idn::process() does not enforce the UTS #46 revision 33… | |
| Pendiente de análisis | Alta (8.2) | 0.43% | — | Poly CCXAIPoly TrioAIPoly Edge EAI | 1/7/2026 | 2/7/2026 | The following Poly Voice IP devices, CCX, Trio, and Edge E, might be inoperable if they connect to a malicious SIP server and receive malformed data. HP is releasing updates to mitigate these potential vulnerabilities. | |
| Pendiente de análisis | Crítica (9.2) | 32% | — | Poly VoiceAI | 1/6/2026 | 31/8/2026 | — | |
| Pendiente de análisis | Crítica (9.8) | 3.0% | — | Universal-robots PolyscopeAI | 8/5/2026 | 17/6/2026 | OS command injection in Dashboard Server interface in Universal Robots PolyScope versions prior to 5.25.1 allows unauthenticated attacker to craft commands that will execute code on the robot's OS. | |
| Pendiente de análisis | Alta (8.2) | 0.09% | — | Poly VoiceAI | 3/3/2026 | 17/6/2026 | An embedded test key and certificate could be extracted from a Poly Voice device using specialized reverse engineering tools. This extracted certificate could be accepted by a SIP service provider if the service provider does not perform proper validation of the device certificate. | |
| Aplazada | Media (6.5) | 0.29% | — | Hyyan Woo-poly-integrationAI | 23/1/2026 | 17/6/2026 | Missing Authorization vulnerability in Hyyan Abo Fakher Hyyan WooCommerce Polylang Integration woo-poly-integration allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Hyyan WooCommerce Polylang Integration: from n/a through <= 1.5.0. | |
| Aplazada | Media (4.3) | 0.13% | — | Richardevcom Add-polylang-support-for-customizerAI | 22/1/2026 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in richardevcom Add Polylang support for Customizer add-polylang-support-for-customizer allows Cross Site Request Forgery.This issue affects Add Polylang support for Customizer: from n/a through <= 1.4.5. | |
| Analizada | Alta (8.1) | 0.40% | — | HP Poly VideoosHP Poly Tcos | 16/12/2025 | 30/9/2026 | In limited scenarios, sensitive data might be written to the log file if an admin uses Microsoft Teams Admin Center (TAC) to make device configuration changes. The affected log file is visible only to users with admin credentials. This is limited to Microsoft TAC and does not affect configuration changes made using… | |
| Aplazada | Alta (8.8) | 0.36% | — | Chouby PolylangAI | 31/10/2025 | 17/6/2026 | Deserialization of Untrusted Data vulnerability in Chouby Polylang polylang allows Object Injection.This issue affects Polylang: from n/a through <= 3.7.3. | |
| Analizada | Alta (7.3) | 0.29% | — | HP Poly Lens Desktop | 9/9/2025 | 17/6/2026 | A vulnerability in the Poly Lens Desktop application running on the Windows platform might allow modifications to the filesystem, which might lead to SYSTEM level privileges being granted. | |
| Analizada | Baja (2) | 0.25% | — | HP Poly Clariti Manager | 23/7/2025 | 17/6/2026 | A potential security vulnerability has been identified in the Poly Clariti Manager for versions prior to 10.12.1. The vulnerability could deserialize untrusted data without validation. HP has addressed the issue in the latest software update. | |
| Analizada | Baja (2) | 0.19% | — | HP Poly Clariti Manager | 23/7/2025 | 17/6/2026 | A potential security vulnerability has been identified in the Poly Clariti Manager for versions prior to 10.12.2. The vulnerability could allow a bypass of the application's XSS filter by submitting untrusted characters. HP has addressed the issue in the latest software update. | |
| Analizada | Media (6.9) | 0.23% | — | HP Poly Clariti Manager | 23/7/2025 | 17/6/2026 | A potential privilege escalation through Sudo vulnerability has been identified in the Poly Clariti Manager for versions prior to 10.12.2. The firmware flaw does not properly implement access controls. HP has addressed the issue in the latest software update. | |
| Analizada | Media (5.7) | 0.19% | — | HP Poly Clariti Manager | 23/7/2025 | 17/6/2026 | A potential stored cross-site scripting vulnerability has been identified in the Poly Clariti Manager for versions prior to 10.12.1. The website allows user input to be stored and rendered without proper sanitization. HP has addressed the issue in the latest software update. | |
| Analizada | Media (5.7) | 0.18% | — | HP Poly Clariti Manager | 23/7/2025 | 17/6/2026 | A potential security vulnerability has been identified in the Poly Clariti Manager for versions prior to 10.12.2. The vulnerability could potentially allow a privileged user to retrieve credentials from the log files. HP has addressed the issue in the latest software update. | |
| Analizada | Media (6) | 0.19% | — | HP Poly Clariti Manager | 23/7/2025 | 17/6/2026 | A potential reflected cross-site scripting vulnerability has been identified in the Poly Clariti Manager for versions prior to 10.12.1. The website does not validate or sanitize the user input before rendering it in the response. HP has addressed the issue in the latest software update. | |
| Analizada | Media (5.9) | 0.15% | — | HP Poly Clariti Manager | 23/7/2025 | 17/6/2026 | A potential security vulnerability has been identified in the Poly Clariti Manager for versions prior to 10.12.1. The vulnerability could allow the retrieval of hardcoded cryptographic keys. HP has addressed the issue in the latest software update. | |
| Analizada | Alta (7.3) | 0.32% | — | HP Poly Clariti Manager | 22/7/2025 | 17/6/2026 | A potential SQL injection vulnerability has been identified in the Poly Clariti Manager for versions prior to 10.12.1. The vulnerability could allow a privileged user to execute SQL commands. HP has addressed the issue in the latest software update. | |
| Analizada | Media (5.9) | 0.15% | — | HP Poly Clariti Manager | 22/7/2025 | 17/6/2026 | A potential security vulnerability has been identified in the Poly Clariti Manager for versions prior to 10.12.1. The vulnerability could allow the use and retrieval of the default password. HP has addressed the issue in the latest software update. | |
| Analizada | Media (5.7) | 0.25% | — | HP Poly Clariti Manager | 22/7/2025 | 17/6/2026 | A potential command injection vulnerability has been identified in the Poly Clariti Manager for versions prior to 10.12.2. The vulnerability could allow a privileged user to submit arbitrary input. HP has addressed the issue in the latest software update. |