Vulnerabilities

Summary — last 7 days

New vulnerabilities2,751▲ 29 vs. last week
Critical / high1,468▲ 334 vs. last week
New active exploitation (KEV)7▼ 3 vs. last week
Unscored (no CVSS)85▼ 441 vs. last week
–

47 results, sorted by published date (most recent first)

CVEStatusSeverityEPSS Active exploitationAffected technologiesPublished ▼Modified Description
Awaiting AnalysisHigh (8.2)0.43%—Poly CCXAIPoly TrioAIPoly Edge EAI7/1/20267/2/2026
The following Poly Voice IP devices, CCX, Trio, and Edge E, might be inoperable if they connect to a malicious SIP server and receive malformed data. HP is releasing updates to mitigate these potential vulnerabilities.
DeferredCritical (9.8)0.48%—Gladinet Triofox Cloud Server Agent Access ServiceAI5/27/20266/17/2026
Gladinet Triofox Cloud Server Agent Access Service (GladServerAgentService.exe) listens on TCP port 7878 and processes remote HTTP messages with URL paths starting with /resources, /status, /sysinfo, /woshome, /Settings, /schedule, or /DavCache.
DeferredHigh (7.5)0.46%—Triofox Server AgentAI5/27/20266/17/2026
Function calls to WOSCommonUtil.dll!WOSSysInfoGetDeviceInterface() in various DLLs (i.e., WOSProfileMgrModule.dll, WOSWebDavModule.dll) can return a NULL pointer (i.e., when no user is logged into the Triofox Server Agent Management Console). The returned NULL pointer is not checked before being dereferenced.
DeferredHigh (7.5)0.46%—Wptrio Betterdocs PROAI5/7/20266/17/2026
The BetterDocs Pro plugin for WordPress is vulnerable to SQL Injection via the `get_current_letter_docs` and `docs_sort_by_letter` AJAX actions in all versions up to, and including, 3.7.0. This is due to the `limit` POST parameter being interpolated directly into a SQL query string before being passed to…
DeferredHigh (8.1)0.52%—Ancorathemes TriompherAI3/25/20266/17/2026
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in AncoraThemes Triompher triompher allows PHP Local File Inclusion.This issue affects Triompher: from n/a through <= 1.1.0.
DeferredCritical (10)0.61%—Synectix LAN 232 TrioAI2/4/20266/17/2026
The Synectix LAN 232 TRIO 3-Port serial to ethernet adapter exposes its web management interface without requiring authentication, allowing unauthenticated users to modify critical device settings or factory reset the device.
AnalyzedHigh (7.1)53%⚠ Active exploitationGladinet CentrestackGladinet Triofox12/12/20256/17/2026
Gladinet CentreStack and Triofox prior to version 16.12.10420.56791 used hardcoded values for their implementation of the AES cryptoscheme. This degrades security for public exposed endpoints that may make use of it and may offer arbitrary local file inclusion when provided a specially crafted request without…
AnalyzedCritical (9.1)95%⚠ Active exploitationGladinet Triofox11/10/20256/17/2026
Triofox versions prior to 16.7.10368.56560, are vulnerable to an Improper Access Control flaw that allows access to initial setup pages even after setup is complete.
AnalyzedHigh (7.5)92%⚠ Active exploitationGladinet CentrestackGladinet Triofox10/9/20256/17/2026
In the default installation and configuration of Gladinet CentreStack and TrioFox, there is an unauthenticated Local File Inclusion Flaw that allows unintended disclosure of system files. Exploitation of this vulnerability has been observed in the wild. This issue impacts Gladinet CentreStack and Triofox: All versions…
DeferredMedium (5.4)0.26%—Optimod 5950AIOptimod 5950hdAIOptimod 5750AIOptimod 5750hdAI+110/6/20256/17/2026
A stored cross-site scripting (XSS) vulnerability in Optimod 5950 - Optimod 5950HD - Optimod 5750 - Optimod 5750HD - Optimod Trio - Optimod version 1.0.0.33 - System version 2.5.26, allows remote attackers to execute arbitrary JavaScript in the web browser of a user, by including a malicious payload into the logs…
DeferredHigh (8.9)0.35%—Orban Optimod 5950AIOrban Optimod 5950hdAIOrban Optimod 5750AIOrban Optimod 5750hdAI+110/6/20256/17/2026
An issue in Orban Optimod 5950, Optimod 5950HD, Optimod 5750, Optimod 5750HD, Optimod Trio Optimod version 1.0.0.33 - System version 2.5.26 allows a remote attacker to escalate privileges via the application stores user privilege/role information in client-side browser storage
DeferredMedium (6.5)0.25%—Wptrio Conditional Shipping FOR WoocommerceAI4/16/20256/17/2026
Cross-Site Request Forgery (CSRF) vulnerability in WP Trio Conditional Shipping for WooCommerce conditional-shipping-for-woocommerce allows Cross Site Request Forgery.This issue affects Conditional Shipping for WooCommerce: from n/a through <= 3.4.0.
DeferredMedium (6.5)0.25%—Wptrio Conditional Payments FOR WoocommerceAI4/16/20256/17/2026
Cross-Site Request Forgery (CSRF) vulnerability in WP Trio Conditional Payments for WooCommerce conditional-payments-for-woocommerce allows Cross Site Request Forgery.This issue affects Conditional Payments for WooCommerce: from n/a through <= 3.3.0.
DeferredHigh (7.6)0.58%—Setriosoft Bizcalendar-webAI3/27/20256/17/2026
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in setriosoft bizcalendar-web bizcalendar-web allows SQL Injection.This issue affects bizcalendar-web: from n/a through <= 1.1.0.34.
DeferredMedium (4.3)0.53%—Wptrio Stock Sync FOR WoocommerceAI12/13/20246/17/2026
Missing Authorization vulnerability in Lauri Karisola / WP Trio Stock Sync for WooCommerce allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Stock Sync for WooCommerce: from n/a through 2.3.2.
ModifiedHigh (7.6)0.25%—Poly Trio 8800 FirmwarePoly Trio C60Poly Lens12/29/20236/17/2026
A vulnerability was found in Poly Trio 8500, Trio 8800 and Trio C60. It has been classified as problematic. This affects an unknown part of the component Poly Lens Management Cloud Registration. The manipulation leads to missing authorization. It is possible to launch the attack on the physical device. The exploit has…
ModifiedMedium (6.6)0.26%—Poly Trio 8800 Firmware12/29/20236/17/2026
A vulnerability was found in Poly Trio 8800 7.2.6.0019 and classified as critical. Affected by this issue is some unknown functionality of the component Test Automation Mode. The manipulation leads to backdoor. It is possible to launch the attack on the physical device. The exploit has been disclosed to the public and…
ModifiedMedium (4.9)0.51%—Poly CCX 400 FirmwarePoly CCX 600 FirmwarePoly Trio 8800 FirmwarePoly Trio C60 Firmware12/29/20236/17/2026
A vulnerability has been found in Poly CCX 400, CCX 600, Trio 8800 and Trio C60 and classified as problematic. Affected by this vulnerability is an unknown functionality of the component Web Interface. The manipulation leads to protection mechanism failure. The attack can be launched remotely. The vendor explains that…
ModifiedMedium (6.5)0.46%—Poly CCX 400 FirmwarePoly CCX 600 FirmwarePoly Trio 8800 FirmwarePoly Trio C60 Firmware12/29/20236/17/2026
A vulnerability, which was classified as problematic, was found in Poly Trio 8300, Trio 8500, Trio 8800, Trio C60, CCX 350, CCX 400, CCX 500, CCX 505, CCX 600, CCX 700, EDGE E100, EDGE E220, EDGE E300, EDGE E320, EDGE E350, EDGE E400, EDGE E450, EDGE E500, EDGE E550, VVX 101, VVX 150, VVX 201, VVX 250, VVX 300, VVX…
ModifiedHigh (7.2)3.3%—Poly CCX 400 FirmwarePoly CCX 600 FirmwarePoly Trio 8800 FirmwarePoly Trio C60 Firmware12/29/20236/17/2026
A vulnerability, which was classified as critical, has been found in Poly Trio 8300, Trio 8500, Trio 8800, Trio C60, CCX 350, CCX 400, CCX 500, CCX 505, CCX 600, CCX 700, EDGE E100, EDGE E220, EDGE E300, EDGE E320, EDGE E350, EDGE E400, EDGE E450, EDGE E500, EDGE E550, VVX 101, VVX 150, VVX 201, VVX 250, VVX 300, VVX…
ModifiedHigh (7.5)1.0%—Poly CCX 400 FirmwarePoly CCX 600 FirmwarePoly Trio 8800 FirmwarePoly Trio C60 Firmware12/29/20236/17/2026
A vulnerability classified as problematic was found in Poly CCX 400, CCX 600, Trio 8800 and Trio C60. This vulnerability affects unknown code of the component HTTP Header Handler. The manipulation of the argument Cookie leads to denial of service. The attack can be initiated remotely. The exploit has been disclosed to…
ModifiedMedium (5.9)0.92%—Poly CCX 400 FirmwarePoly CCX 600 FirmwarePoly Trio 8800 FirmwarePoly Trio C60 Firmware12/29/20236/17/2026
A vulnerability classified as problematic has been found in Poly Trio 8300, Trio 8500, Trio 8800, Trio C60, CCX 350, CCX 400, CCX 500, CCX 505, CCX 600, CCX 700, EDGE E100, EDGE E220, EDGE E300, EDGE E320, EDGE E350, EDGE E400, EDGE E450, EDGE E500, EDGE E550, VVX 101, VVX 150, VVX 201, VVX 250, VVX 300, VVX 301, VVX…
ModifiedMedium (6.1)0.38%—Wptrio Stock Sync FOR Woocommerce8/18/20236/17/2026
Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Lauri Karisola / WP Trio Stock Sync for WooCommerce plugin <= 2.4.0 versions.
ModifiedMedium (5.4)0.50%—Poly Trio 8800 Firmware3/8/20237/9/2026
An arbitrary file upload vulnerability in Poly Trio 8800 7.2.2.1094 allows attackers to execute arbitrary code via a crafted ringtone file.
ModifiedMedium (5.4)0.21%—Wptrio Conditional Shipping FOR Woocommerce3/1/20236/17/2026
Cross-Site Request Forgery (CSRF) vulnerability in Lauri Karisola / WP Trio Conditional Shipping for WooCommerce plugin <= 2.3.1 leading to activation/deactivation of plugin rulesets.