Vulnerabilities
Summary — last 7 days
New vulnerabilities2,751▲ 29 vs. last week
Critical / high1,468▲ 334 vs. last week
New active exploitation (KEV)7▼ 3 vs. last week
Unscored (no CVSS)85▼ 441 vs. last week
47 results, sorted by published date (most recent first)
| CVE | Status | Severity | EPSS | Active exploitation | Affected technologies | Published ▼ | Modified | Description |
|---|---|---|---|---|---|---|---|---|
| Awaiting Analysis | High (8.2) | 0.43% | — | Poly CCXAIPoly TrioAIPoly Edge EAI | 7/1/2026 | 7/2/2026 | The following Poly Voice IP devices, CCX, Trio, and Edge E, might be inoperable if they connect to a malicious SIP server and receive malformed data. HP is releasing updates to mitigate these potential vulnerabilities. | |
| Deferred | Critical (9.8) | 0.48% | — | Gladinet Triofox Cloud Server Agent Access ServiceAI | 5/27/2026 | 6/17/2026 | Gladinet Triofox Cloud Server Agent Access Service (GladServerAgentService.exe) listens on TCP port 7878 and processes remote HTTP messages with URL paths starting with /resources, /status, /sysinfo, /woshome, /Settings, /schedule, or /DavCache. | |
| Deferred | High (7.5) | 0.46% | — | Triofox Server AgentAI | 5/27/2026 | 6/17/2026 | Function calls to WOSCommonUtil.dll!WOSSysInfoGetDeviceInterface() in various DLLs (i.e., WOSProfileMgrModule.dll, WOSWebDavModule.dll) can return a NULL pointer (i.e., when no user is logged into the Triofox Server Agent Management Console). The returned NULL pointer is not checked before being dereferenced. | |
| Deferred | High (7.5) | 0.46% | — | Wptrio Betterdocs PROAI | 5/7/2026 | 6/17/2026 | The BetterDocs Pro plugin for WordPress is vulnerable to SQL Injection via the `get_current_letter_docs` and `docs_sort_by_letter` AJAX actions in all versions up to, and including, 3.7.0. This is due to the `limit` POST parameter being interpolated directly into a SQL query string before being passed to… | |
| Deferred | High (8.1) | 0.52% | — | Ancorathemes TriompherAI | 3/25/2026 | 6/17/2026 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in AncoraThemes Triompher triompher allows PHP Local File Inclusion.This issue affects Triompher: from n/a through <= 1.1.0. | |
| Deferred | Critical (10) | 0.61% | — | Synectix LAN 232 TrioAI | 2/4/2026 | 6/17/2026 | The Synectix LAN 232 TRIO 3-Port serial to ethernet adapter exposes its web management interface without requiring authentication, allowing unauthenticated users to modify critical device settings or factory reset the device. | |
| Analyzed | High (7.1) | 53% | ⚠ Active exploitation | Gladinet CentrestackGladinet Triofox | 12/12/2025 | 6/17/2026 | Gladinet CentreStack and Triofox prior to version 16.12.10420.56791 used hardcoded values for their implementation of the AES cryptoscheme. This degrades security for public exposed endpoints that may make use of it and may offer arbitrary local file inclusion when provided a specially crafted request without… | |
| Analyzed | Critical (9.1) | 95% | ⚠ Active exploitation | Gladinet Triofox | 11/10/2025 | 6/17/2026 | Triofox versions prior to 16.7.10368.56560, are vulnerable to an Improper Access Control flaw that allows access to initial setup pages even after setup is complete. | |
| Analyzed | High (7.5) | 92% | ⚠ Active exploitation | Gladinet CentrestackGladinet Triofox | 10/9/2025 | 6/17/2026 | In the default installation and configuration of Gladinet CentreStack and TrioFox, there is an unauthenticated Local File Inclusion Flaw that allows unintended disclosure of system files. Exploitation of this vulnerability has been observed in the wild. This issue impacts Gladinet CentreStack and Triofox: All versions… | |
| Deferred | Medium (5.4) | 0.26% | — | Optimod 5950AIOptimod 5950hdAIOptimod 5750AIOptimod 5750hdAI+1 | 10/6/2025 | 6/17/2026 | A stored cross-site scripting (XSS) vulnerability in Optimod 5950 - Optimod 5950HD - Optimod 5750 - Optimod 5750HD - Optimod Trio - Optimod version 1.0.0.33 - System version 2.5.26, allows remote attackers to execute arbitrary JavaScript in the web browser of a user, by including a malicious payload into the logs… | |
| Deferred | High (8.9) | 0.35% | — | Orban Optimod 5950AIOrban Optimod 5950hdAIOrban Optimod 5750AIOrban Optimod 5750hdAI+1 | 10/6/2025 | 6/17/2026 | An issue in Orban Optimod 5950, Optimod 5950HD, Optimod 5750, Optimod 5750HD, Optimod Trio Optimod version 1.0.0.33 - System version 2.5.26 allows a remote attacker to escalate privileges via the application stores user privilege/role information in client-side browser storage | |
| Deferred | Medium (6.5) | 0.25% | — | Wptrio Conditional Shipping FOR WoocommerceAI | 4/16/2025 | 6/17/2026 | Cross-Site Request Forgery (CSRF) vulnerability in WP Trio Conditional Shipping for WooCommerce conditional-shipping-for-woocommerce allows Cross Site Request Forgery.This issue affects Conditional Shipping for WooCommerce: from n/a through <= 3.4.0. | |
| Deferred | Medium (6.5) | 0.25% | — | Wptrio Conditional Payments FOR WoocommerceAI | 4/16/2025 | 6/17/2026 | Cross-Site Request Forgery (CSRF) vulnerability in WP Trio Conditional Payments for WooCommerce conditional-payments-for-woocommerce allows Cross Site Request Forgery.This issue affects Conditional Payments for WooCommerce: from n/a through <= 3.3.0. | |
| Deferred | High (7.6) | 0.58% | — | Setriosoft Bizcalendar-webAI | 3/27/2025 | 6/17/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in setriosoft bizcalendar-web bizcalendar-web allows SQL Injection.This issue affects bizcalendar-web: from n/a through <= 1.1.0.34. | |
| Deferred | Medium (4.3) | 0.53% | — | Wptrio Stock Sync FOR WoocommerceAI | 12/13/2024 | 6/17/2026 | Missing Authorization vulnerability in Lauri Karisola / WP Trio Stock Sync for WooCommerce allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Stock Sync for WooCommerce: from n/a through 2.3.2. | |
| Modified | High (7.6) | 0.25% | — | Poly Trio 8800 FirmwarePoly Trio C60Poly Lens | 12/29/2023 | 6/17/2026 | A vulnerability was found in Poly Trio 8500, Trio 8800 and Trio C60. It has been classified as problematic. This affects an unknown part of the component Poly Lens Management Cloud Registration. The manipulation leads to missing authorization. It is possible to launch the attack on the physical device. The exploit has… | |
| Modified | Medium (6.6) | 0.26% | — | Poly Trio 8800 Firmware | 12/29/2023 | 6/17/2026 | A vulnerability was found in Poly Trio 8800 7.2.6.0019 and classified as critical. Affected by this issue is some unknown functionality of the component Test Automation Mode. The manipulation leads to backdoor. It is possible to launch the attack on the physical device. The exploit has been disclosed to the public and… | |
| Modified | Medium (4.9) | 0.51% | — | Poly CCX 400 FirmwarePoly CCX 600 FirmwarePoly Trio 8800 FirmwarePoly Trio C60 Firmware | 12/29/2023 | 6/17/2026 | A vulnerability has been found in Poly CCX 400, CCX 600, Trio 8800 and Trio C60 and classified as problematic. Affected by this vulnerability is an unknown functionality of the component Web Interface. The manipulation leads to protection mechanism failure. The attack can be launched remotely. The vendor explains that… | |
| Modified | Medium (6.5) | 0.46% | — | Poly CCX 400 FirmwarePoly CCX 600 FirmwarePoly Trio 8800 FirmwarePoly Trio C60 Firmware | 12/29/2023 | 6/17/2026 | A vulnerability, which was classified as problematic, was found in Poly Trio 8300, Trio 8500, Trio 8800, Trio C60, CCX 350, CCX 400, CCX 500, CCX 505, CCX 600, CCX 700, EDGE E100, EDGE E220, EDGE E300, EDGE E320, EDGE E350, EDGE E400, EDGE E450, EDGE E500, EDGE E550, VVX 101, VVX 150, VVX 201, VVX 250, VVX 300, VVX… | |
| Modified | High (7.2) | 3.3% | — | Poly CCX 400 FirmwarePoly CCX 600 FirmwarePoly Trio 8800 FirmwarePoly Trio C60 Firmware | 12/29/2023 | 6/17/2026 | A vulnerability, which was classified as critical, has been found in Poly Trio 8300, Trio 8500, Trio 8800, Trio C60, CCX 350, CCX 400, CCX 500, CCX 505, CCX 600, CCX 700, EDGE E100, EDGE E220, EDGE E300, EDGE E320, EDGE E350, EDGE E400, EDGE E450, EDGE E500, EDGE E550, VVX 101, VVX 150, VVX 201, VVX 250, VVX 300, VVX… | |
| Modified | High (7.5) | 1.0% | — | Poly CCX 400 FirmwarePoly CCX 600 FirmwarePoly Trio 8800 FirmwarePoly Trio C60 Firmware | 12/29/2023 | 6/17/2026 | A vulnerability classified as problematic was found in Poly CCX 400, CCX 600, Trio 8800 and Trio C60. This vulnerability affects unknown code of the component HTTP Header Handler. The manipulation of the argument Cookie leads to denial of service. The attack can be initiated remotely. The exploit has been disclosed to… | |
| Modified | Medium (5.9) | 0.92% | — | Poly CCX 400 FirmwarePoly CCX 600 FirmwarePoly Trio 8800 FirmwarePoly Trio C60 Firmware | 12/29/2023 | 6/17/2026 | A vulnerability classified as problematic has been found in Poly Trio 8300, Trio 8500, Trio 8800, Trio C60, CCX 350, CCX 400, CCX 500, CCX 505, CCX 600, CCX 700, EDGE E100, EDGE E220, EDGE E300, EDGE E320, EDGE E350, EDGE E400, EDGE E450, EDGE E500, EDGE E550, VVX 101, VVX 150, VVX 201, VVX 250, VVX 300, VVX 301, VVX… | |
| Modified | Medium (6.1) | 0.38% | — | Wptrio Stock Sync FOR Woocommerce | 8/18/2023 | 6/17/2026 | Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Lauri Karisola / WP Trio Stock Sync for WooCommerce plugin <= 2.4.0 versions. | |
| Modified | Medium (5.4) | 0.50% | — | Poly Trio 8800 Firmware | 3/8/2023 | 7/9/2026 | An arbitrary file upload vulnerability in Poly Trio 8800 7.2.2.1094 allows attackers to execute arbitrary code via a crafted ringtone file. | |
| Modified | Medium (5.4) | 0.21% | — | Wptrio Conditional Shipping FOR Woocommerce | 3/1/2023 | 6/17/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Lauri Karisola / WP Trio Conditional Shipping for WooCommerce plugin <= 2.3.1 leading to activation/deactivation of plugin rulesets. |