6.9
CVE-2025-43487 - Poly Clariti Manager - Multiple Security Vulnerabilities
A potential privilege escalation through Sudo vulnerability has been identified in the Poly Clariti Manager for versions prior to 10.12.2. The firmware flaw does not properly implement access controls. HP has addressed the issue in the latest software update.
4.3
CVE-2025-54139 - HAX CMS' application pages are vulnerable to clickjacking
HAX CMS allows users to manage their microsite universe with a NodeJS or PHP backend. In haxcms-nodejs versions 11.0.12 and below and in haxcms-php versions 11.0.7 and below, all pages within the HAX CMS application do not contain headers to prevent other websites from loading the site within an ifβ¦
5.7
CVE-2025-43486 - Poly Clariti Manager - Multiple Security Vulnerabilities
A potential stored cross-site scripting vulnerability has been identified in the Poly Clariti Manager for versions prior to 10.12.1. The website allows user input to be stored and rendered without proper sanitization. HP has addressed the issue in the latest software update.
5.7
CVE-2025-43485 - Poly Clariti Manager - Multiple Security Vulnerabilities
A potential security vulnerability has been identified in the Poly Clariti Manager for versions prior to 10.12.2. The vulnerability could potentially allow a privileged user to retrieve credentials from the log files. HP has addressed the issue in the latest software update.
6
CVE-2025-43484 - Poly Clariti Manager - Multiple Security Vulnerabilities
A potential reflected cross-site scripting vulnerability has been identified in the Poly Clariti Manager for versions prior to 10.12.1. The website does not validate or sanitize the user input before rendering it in the response. HP has addressed the issue in the latest software update.
5.9
CVE-2025-43483 - Poly Clariti Manager - Multiple Security Vulnerabilities
A potential security vulnerability has been identified in the Poly Clariti Manager for versions prior to 10.12.1. The vulnerability could allow the retrieval of hardcoded cryptographic keys. HP has addressed the issue in the latest software update.
7.3
CVE-2025-43022 - Poly Clariti Manager - Multiple Security Vulnerabilities
A potential SQL injection vulnerability has been identified in the Poly Clariti Manager for versions prior to 10.12.1. The vulnerability could allow a privileged user to execute SQL commands. HP has addressed the issue in the latest software update.
5.9
CVE-2025-43021 - Poly Clariti Manager - Multiple Security Vulnerabilities
A potential security vulnerability has been identified in the Poly Clariti Manager for versions prior to 10.12.1. The vulnerability could allow the use and retrieval of the default password. HP has addressed the issue in the latest software update.
5.7
CVE-2025-43020 - Poly Clariti Manager - Multiple Security Vulnerabilities
A potential command injection vulnerability has been identified in the Poly Clariti Manager for versions prior to 10.12.2. The vulnerability could allow a privileged user to submit arbitrary input. HP has addressed the issue in the latest software update.
8.6
CVE-2025-7766 - Lantronix Provisioning Manager Improper Restriction of XML External Entity Reference
LantronixΒ Provisioning Manager is vulnerable to XML external entity attacks in configuration files supplied by network devices, leading to unauthenticated remote code execution on hosts with Provisioning Manager installed.