Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2741▼ 480 respecto a la semana anterior
Críticas / altas1308▼ 182 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)226▼ 276 respecto a la semana anterior
645 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Media (6.5) | 0.28% | — | Octoprint | 5/11/2024 | 17/6/2026 | OctoPrint provides a web interface for controlling consumer 3D printers. OctoPrint versions up until and including 1.10.2 contain a vulnerability that allows an attacker that has gained temporary control over an authenticated victim's OctoPrint browser session to retrieve/recreate/delete the user's or - if the victim… | |
| Analizada | Media (6.1) | 0.27% | — | Octoprint | 5/11/2024 | 17/6/2026 | OctoPrint provides a web interface for controlling consumer 3D printers. OctoPrint versions up until and including 1.10.2 contain reflected XSS vulnerabilities in the login dialog and the standalone application key confirmation dialog. An attacker who successfully talked a victim into clicking on a specially crafted… | |
| Modificada | Crítica (9.8) | 0.51% | — | Helloprint | 4/11/2024 | 17/6/2026 | Unrestricted Upload of File with Dangerous Type vulnerability in helloprint Helloprint helloprint allows Upload a Web Shell to a Web Server.This issue affects Helloprint: from n/a through <= 2.0.4. | |
| Analizada | Alta (8.8) | 0.53% | — | Ukrsolution Print Labels With Barcodes | 1/11/2024 | 17/6/2026 | Missing Authorization vulnerability in UkrSolution Print Barcode Labels for your WooCommerce allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Print Barcode Labels for your WooCommerce products/orders: from n/a through 3.4.9. | |
| Analizada | Crítica (9.8) | 0.68% | — | HP Smart Universal Printing Driver | 30/10/2024 | 17/6/2026 | Client / Server PCs with the HP Smart Universal Printing Driver installed are potentially vulnerable to Remote Code Execution and/or Elevation of Privilege. A client using the HP Smart Universal Printing Driver that sends a print job comprised of a malicious XPS file could potentially lead to Remote Code Execution… | |
| Aplazada | Crítica (10) | 1.0% | 💥 PoC | Webandprint AR FOR WoocommerceAI | 30/10/2024 | 17/6/2026 | Unrestricted Upload of File with Dangerous Type vulnerability in webandprint AR For Woocommerce ar-for-woocommerce allows Upload a Web Shell to a Web Server.This issue affects AR For Woocommerce: from n/a through <= 6.3. | |
| Modificada | Crítica (10) | 0.51% | — | Webandprint AR | 28/10/2024 | 17/6/2026 | Unrestricted Upload of File with Dangerous Type vulnerability in webandprint AR For WordPress ar-for-wordpress allows Upload a Web Shell to a Web Server.This issue affects AR For WordPress: from n/a through <= 6.6. | |
| Aplazada | Alta (7.5) | 0.56% | — | Nahimsalami Ahime Image PrinterAI | 16/10/2024 | 17/6/2026 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in nahimsalami Ahime Image Printer ahime-image-printer.This issue affects Ahime Image Printer: from n/a through <= 1.0.0. | |
| Modificada | Media (5.3) | 51% | 💥 Exploit | Openprinting Cups-browsed | 26/9/2024 | 17/6/2026 | CUPS is a standards-based, open-source printing system, and `cups-browsed` contains network printing functionality including, but not limited to, auto-discovering print services and shared printers. `cups-browsed` binds to `INADDR_ANY:631`, causing it to trust any packet from any source, and can cause the… | |
| Modificada | Crítica (9.8) | 64% | 💥 Exploit | Openprinting LibppdDebian Linux | 26/9/2024 | 17/6/2026 | CUPS is a standards-based, open-source printing system, and `libppd` can be used for legacy PPD file support. The `libppd` function `ppdCreatePPDFromIPP2` does not sanitize IPP attributes when creating the PPD buffer. When used in combination with other functions such as `cfGetPrinterAttributes5`, can result in user… | |
| Modificada | Alta (8.6) | 78% | 💥 Exploit | Openprinting Libcupsfilters | 26/9/2024 | 17/6/2026 | CUPS is a standards-based, open-source printing system, and `libcupsfilters` contains the code of the filters of the former `cups-filters` package as library functions to be used for the data format conversion tasks needed in Printer Applications. The `cfGetPrinterAttributes5` function in `libcupsfilters` does not… | |
| Analizada | Alta (7.8) | 0.15% | — | Samsung Universal Print Driver | 11/9/2024 | 17/6/2026 | The Samsung Universal Print Driver for Windows is potentially vulnerable to escalation of privilege allowing the creation of a reverse shell in the tool. This is only applicable for products in the application released or manufactured before 2018. | |
| Analizada | Alta (8.3) | 0.36% | — | Nt-ware Uniflow OnlineNt-ware Uniflow Online Print & ScanNt-ware Uniflow Smartclient | 2/9/2024 | 17/6/2026 | The registration process of uniFLOW Online (NT-ware product) apps, prior to and including version 2024.1.0, can be compromised when email login is enabled on the tenant. Those tenants utilising email login in combination with Microsoft Safe Links or similar are impacted. This vulnerability may allow the attacker to… | |
| Aplazada | Media (6.5) | 0.26% | — | Lenovo PrintersAI | 16/8/2024 | 17/6/2026 | A denial-of-service vulnerability was reported in some Lenovo printers that could allow an unauthenticated attacker on a shared network to deny printer connections until the system is rebooted. | |
| Aplazada | Media (6.5) | 0.26% | — | Lenovo PrintersAI | 16/8/2024 | 17/6/2026 | A denial-of-service vulnerability was reported in some Lenovo printers that could allow an unauthenticated attacker on a shared network to prevent printer services from being reachable until the system is rebooted. | |
| Aplazada | Media (6.5) | 0.26% | — | Lenovo PrintersAI | 16/8/2024 | 17/6/2026 | A denial-of-service vulnerability was reported in some Lenovo printers that could allow an unauthenticated attacker on a shared network to deny printing capabilities until the system is rebooted. | |
| Aplazada | Media (6.5) | 0.30% | — | Lenovo PrintersAI | 16/8/2024 | 17/6/2026 | A denial-of-service vulnerability was reported in some Lenovo printers that could allow an unauthenticated attacker on a shared network to disrupt the printer's functionality until a manual system reboot occurs. | |
| Aplazada | Media (6.5) | 0.34% | — | Lenovo PrintersAI | 16/8/2024 | 17/6/2026 | A denial-of-service vulnerability was reported in some Lenovo printers that could allow an unauthenticated attacker on a shared network to crash printer communications until the system is rebooted. | |
| Aplazada | Alta (7.1) | 0.17% | — | Contact Form 7 Summary AND PrintAI | 13/8/2024 | 17/6/2026 | Cross-Site Request Forgery (CSRF), Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Muhammad Rehman Contact Form 7 Summary and Print allows Stored XSS.This issue affects Contact Form 7 Summary and Print: from n/a through 1.2.5. | |
| Aplazada | Baja (3.5) | 0.28% | — | Honeywell Pc42t Printer FirmwareAIHoneywell Pc42tp Printer FirmwareAIHoneywell Pc42d Printer FirmwareAI | 29/7/2024 | 17/6/2026 | Honeywell PC42t, PC42tp, and PC42d Printers, T10.19.020016 to T10.20.060398, contain a cross-site scripting vulnerability. A(n) attacker could potentially inject malicious code which may lead to information disclosure, session theft, or client-side request forgery. Honeywell recommends updating to the most recent… | |
| Aplazada | Alta (8.4) | 0.59% | 💥 PoC | Entrustdatacard XPS Card Printer DriverAI | 22/7/2024 | 17/6/2026 | Insecure permissions in Entrust Datacard XPS Card Printer Driver 8.5 and earlier without the dxp1-patch-E24-004 patch allows unauthenticated attackers to execute arbitrary code as SYSTEM via a crafted DLL payload. | |
| Modificada | Media (4.8) | 0.30% | — | Print MY Blog Project Print MY Blog | 22/7/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Michael Nelson Print My Blog print-my-blog.This issue affects Print My Blog: from n/a through <= 3.27.0. | |
| Aplazada | Alta (8.2) | 0.58% | — | Ricoh MFPAIRicoh PrinterAI | 10/7/2024 | 17/6/2026 | Out-of-bounds write vulnerability exists in Ricoh MFPs and printers. If a remote attacker sends a specially crafted request to the affected products, the products may be able to cause a denial-of-service (DoS) condition and/or user's data may be destroyed. | |
| Aplazada | Alta (8.8) | 0.74% | — | Toshiba PrinterAI | 14/6/2024 | 17/6/2026 | Path traversal vulnerability in the web server of the Toshiba printer enables attacker to overwrite orginal files or add new ones to the printer. As for the affected products/models/versions, see the reference URL. | |
| Aplazada | Alta (7.4) | 0.27% | — | Toshiba PrinterAI | 14/6/2024 | 17/6/2026 | It was observed that all the Toshiba printers contain credentials used for WebDAV access in the readable file. Then, it is possible to get a full access with WebDAV to the printer. As for the affected products/models/versions, see the reference URL. |