Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2737▼ 484 respecto a la semana anterior
Críticas / altas1302▼ 187 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)227▼ 275 respecto a la semana anterior
645 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Crítica (9.8) | 0.90% | — | Printerlogic Vasion PrintPrinterlogic Virtual Appliance | 5/3/2025 | 17/6/2026 | Vasion Print (formerly PrinterLogic) before Virtual Appliance Host 22.0.933 Application 20.0.2368 allows Unauthenticated Driver Package Editing V-2024-008. | |
| Modificada | Crítica (9.8) | 0.90% | — | Printerlogic Vasion PrintPrinterlogic Virtual Appliance | 5/3/2025 | 17/6/2026 | Vasion Print (formerly PrinterLogic) before Virtual Appliance Host 22.0.951 Application 20.0.2368 allows Unauthenticated APIs for Single-Sign On V-2024-009. | |
| Analizada | Crítica (9.8) | 0.74% | — | Printerlogic Vasion PrintPrinterlogic Virtual Appliance | 5/3/2025 | 17/6/2026 | Vasion Print (formerly PrinterLogic) before Virtual Appliance Host 22.0.1002 Application 20.0.2614 allows SQL Injection V-2024-012. | |
| Modificada | Alta (8.8) | 0.78% | — | Printerlogic Vasion PrintPrinterlogic Virtual Appliance | 5/3/2025 | 17/6/2026 | Vasion Print (formerly PrinterLogic) before Virtual Appliance Host 22.0.1002 Application 20.0.2614 allows Privilege Escalation V-2024-015. | |
| Modificada | Crítica (9.8) | 0.90% | — | Printerlogic Vasion PrintPrinterlogic Virtual Appliance | 5/3/2025 | 17/6/2026 | Vasion Print (formerly PrinterLogic) before Virtual Appliance Host 22.0.1002 Application 20.0.2614 allows Hardcoded Password V-2024-013. | |
| Modificada | Media (6.1) | 0.53% | — | Printerlogic Vasion PrintPrinterlogic Virtual Appliance | 5/3/2025 | 17/6/2026 | Vasion Print (formerly PrinterLogic) before Virtual Appliance Host 22.0.1002 Application 20.0.2614 allows Cross-Site Scripting V-2024-016. | |
| Aplazada | Alta (7.7) | 0.74% | — | HelloprintAI | 3/3/2025 | 17/6/2026 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in helloprint Helloprint helloprint allows Path Traversal.This issue affects Helloprint: from n/a through <= 2.0.7. | |
| Aplazada | Alta (8.6) | 0.72% | — | HelloprintAI | 3/3/2025 | 17/6/2026 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in helloprint Helloprint helloprint allows Path Traversal.This issue affects Helloprint: from n/a through <= 2.0.7. | |
| Analizada | Alta (7.1) | 0.38% | — | Sprintexperts WP Extra Fields | 26/2/2025 | 17/6/2026 | The WP Extra Fields WordPress plugin through 1.0.1 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin. | |
| Aplazada | Media (5.3) | 0.62% | — | Pcl6 V4 Printer DriverAIUFR II V4 Printer DriverAILipslx V4 Printer DriverAI | 26/2/2025 | 17/6/2026 | Out-of-bounds vulnerability in slope processing during curve rendering in Generic PCL6 V4 Printer Driver / Generic UFR II V4 Printer Driver / Generic LIPSLX V4 Printer Driver. | |
| Aplazada | Media (5.3) | 0.62% | — | Pcl6 V4 Printer DriverAIUFR II V4 Printer DriverAILipslx V4 Printer DriverAI | 26/2/2025 | 17/6/2026 | Out-of-bounds vulnerability due to improper memory release during image rendering in Generic PCL6 V4 Printer Driver / Generic UFR II V4 Printer Driver / Generic LIPSLX V4 Printer Driver. | |
| Aplazada | Media (5.3) | 0.62% | — | Pcl6 V4 Printer DriverAIUFR II V4 Printer DriverAILipslx V4 Printer DriverAI | 26/2/2025 | 17/6/2026 | Out-of-bounds vulnerability in curve segmentation processing of Generic PCL6 V4 Printer Driver / Generic UFR II V4 Printer Driver / Generic LIPSLX V4 Printer Driver. | |
| Aplazada | Media (6.5) | 0.28% | — | Webandprint AR FOR WordpressAI | 25/2/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in webandprint AR For WordPress ar-for-wordpress allows DOM-Based XSS.This issue affects AR For WordPress: from n/a through <= 7.7. | |
| Aplazada | Media (6.5) | 0.24% | — | Fujifilm Docuprint Cp225wAIFujifilm Docuprint Cp228wAIFujifilm Docuprint Cm225fwAIFujifilm Docuprint Cm228fwAI | 18/2/2025 | 17/6/2026 | Out-of-bounds write vulnerability exists in DocuPrint CP225w 01.22.01 and earlier, DocuPrint CP228w 01.22.01 and earlier, DocuPrint CM225fw 01.10.01 and earlier, and DocuPrint CM228fw 01.10.01 and earlier. If an affected MFP processes a specially crafted printer job file, a denial-of-service (DoS) condition may occur. | |
| Aplazada | Crítica (9.3) | 0.25% | — | Lexmark Print Management ClientAI | 11/2/2025 | 17/6/2026 | A Reliance on Untrusted Inputs in a Security Decision vulnerability has been identified in the Lexmark Print Management Client. | |
| Aplazada | Alta (7.8) | 0.14% | — | NDD Print SolutionAI | 5/2/2025 | 17/6/2026 | A Time-of-Check to Time-of-Use (TOCTOU) vulnerability has been identified in the driver of the NDD Print solution, which could allow an unprivileged user to exploit this flaw and gain SYSTEM-level access on the device. The vulnerability affects version 5.24.3 and before of the software. | |
| Analizada | Media (6.6) | 0.37% | — | Print Anything Project Print Anything | 9/1/2025 | 17/6/2026 | Vulnerability in Drupal Print Anything.This issue affects Print Anything: *.*. | |
| Aplazada | Media (4.3) | 0.28% | — | Print Invoice AND Delivery Notes FOR WoocommerceAI | 24/12/2024 | 17/6/2026 | The Print Invoice & Delivery Notes for WooCommerce plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'wcdn_remove_shoplogo' AJAX action in all versions up to, and including, 5.4.0. This makes it possible for authenticated attackers, with Subscriber-level… | |
| Aplazada | Media (5.7) | 0.30% | — | HP Linux Imaging AND PrintingAI | 19/12/2024 | 17/6/2026 | The HP Linux Imaging and Printing (HPLIP) software may potentially be affected by memory buffer overflow. | |
| Aplazada | Media (4.3) | 0.53% | — | Printful Integration FOR WoocommerceAI | 13/12/2024 | 17/6/2026 | Missing Authorization vulnerability in printful Printful Integration for WooCommerce printful-shipping-for-woocommerce allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Printful Integration for WooCommerce: from n/a through <= 2.2.3. | |
| Modificada | Media (6.5) | 0.60% | — | Tychesoftwares Print Invoice & Delivery Notes FOR Woocommerce | 13/12/2024 | 17/6/2026 | Missing Authorization vulnerability in Tyche Softwares Print Invoice & Delivery Notes for WooCommerce allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Print Invoice & Delivery Notes for WooCommerce: from n/a through 4.7.2. | |
| Aplazada | Baja (3.7) | 0.39% | — | Webandprint ARAI | 13/12/2024 | 17/6/2026 | The AR for WordPress plugin for WordPress is vulnerable to unauthorized double extension file upload due to a missing capability check on the set_ar_featured_image() function in all versions up to, and including, 7.3. This makes it possible for unauthenticated attackers to upload php files leveraging a double… | |
| Aplazada | Alta (8.1) | 1.1% | — | Print Science DesignerAI | 12/12/2024 | 17/6/2026 | The Print Science Designer plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 1.3.152 via deserialization of untrusted input through the 'designer-saved-projects' cookie. This makes it possible for unauthenticated attackers to inject a PHP Object. No known POP chain is… | |
| Analizada | Media (4.3) | 0.20% | — | Wp3dprinting 3dprint Lite | 6/12/2024 | 17/6/2026 | The 3DPrint Lite WordPress plugin before 2.1 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack. | |
| Aplazada | Media (6.5) | 0.23% | — | Nopeamedia Print PDF Generator AND PublisherAI | 18/11/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in verkkovaraani Print PDF Generator and Publisher nopeamedia allows Stored XSS.This issue affects Print PDF Generator and Publisher: from n/a through <= 1.1.6. |