Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2729▼ 513 respecto a la semana anterior
Críticas / altas1298▼ 212 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)225▼ 276 respecto a la semana anterior
645 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (5.5) | 0.16% | — | Monoprice Select Mini 3D Printer V2 Firmware | 12/6/2024 | 17/6/2026 | Improper input validation of printing files in Monoprice Select Mini V2 V37.115.32 allows attackers to instruct the device's movable parts to destinations that exceed the devices' maximum coordinates via the printing of a malicious .gcode file. | |
| Analizada | Media (6.7) | 2.4% | — | Openprinting CupsDebian Linux | 11/6/2024 | 17/6/2026 | OpenPrinting CUPS is an open source printing system for Linux and other Unix-like operating systems. In versions 2.4.8 and earlier, when starting the cupsd server with a Listen configuration item pointing to a symbolic link, the cupsd process can be caused to perform an arbitrary chmod of the provided argument,… | |
| Aplazada | Alta (7.5) | 0.42% | — | CPF Concepts LLC BizprintAI | 9/6/2024 | 17/6/2026 | Missing Authorization vulnerability in BizSwoop a CPF Concepts, LLC Brand BizPrint.This issue affects BizPrint: from n/a through 4.3.39. | |
| Aplazada | Alta (7.3) | 0.27% | — | FprintdAI | 8/6/2024 | 17/6/2026 | fprintd through 1.94.3 lacks a security attention mechanism, and thus unexpected actions might be authorized by "auth sufficient pam_fprintd.so" for Sudo. NOTE: the supplier disputes this because they believe issue resolution would involve modifying the PAM configuration to restrict pam_fprintd.so to front-ends that… | |
| Aplazada | Media (6.4) | 0.27% | — | Print-o-maticAI | 22/5/2024 | 17/6/2026 | The Print-O-Matic plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'print-me' shortcode in all versions up to, and including, 2.1.10 due to insufficient input sanitization and output escaping on user supplied attributes such as 'tag'. This makes it possible for authenticated… | |
| Aplazada | Crítica (9.8) | 0.78% | — | Blackprint EngineAI | 20/5/2024 | 17/6/2026 | A Prototype Pollution issue in Blackprint @blackprint/engine v.0.9.0 allows an attacker to execute arbitrary code via the _utils.setDeepProperty function of engine.min.js. | |
| Aplazada | Alta (7.5) | 0.45% | — | Lenovo PrintersAI | 16/5/2024 | 17/6/2026 | A buffer overflow vulnerability was identified in some Lenovo printers that could allow an unauthenticated user to trigger a device restart by sending a specially crafted web request. | |
| Analizada | Crítica (9.4) | 0.90% | — | Octoprint | 14/5/2024 | 17/6/2026 | OctoPrint provides a web interface for controlling consumer 3D printers. OctoPrint versions up until and including 1.10.0 contain a vulnerability that allows an unauthenticated attacker to completely bypass the authentication if the `autologinLocal` option is enabled within `config.yaml`, even if they come from… | |
| Aplazada | Media (4.3) | 0.34% | — | Tychesoftwares Print Invoice AND Delivery Notes FOR WoocommerceAITychesoftwares Arconix ShortcodesAITychesoftwares Arconix FAQAI | 8/5/2024 | 17/6/2026 | Missing Authorization vulnerability in Tyche Softwares Print Invoice & Delivery Notes for WooCommerce, Tyche Softwares Arconix Shortcodes, Tyche Softwares Arconix FAQ.This issue affects Print Invoice & Delivery Notes for WooCommerce: from n/a through 4.8.1; Arconix Shortcodes: from n/a through 2.1.10; Arconix FAQ:… | |
| Aplazada | Media (5.3) | 0.45% | — | Michael Nelson Print MY BlogAI | 6/5/2024 | 17/6/2026 | Missing Authorization vulnerability in Michael Nelson Print My Blog print-my-blog.This issue affects Print My Blog: from n/a through <= 3.26.2. | |
| Aplazada | Media (6.5) | 0.31% | — | Twinpictures Print-o-maticAI | 3/5/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Twinpictures Print-O-Matic allows Stored XSS.This issue affects Print-O-Matic: from n/a through 2.1.10. | |
| Modificada | Media (5.4) | 0.41% | — | Ukrsolution Print Labels With Barcodes | 2/5/2024 | 17/6/2026 | The Print Labels with Barcodes. Create price tags, product labels, order labels for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the template and javascript label fields in all versions up to, and including, 3.4.6 due to insufficient input sanitization and output escaping. This… | |
| Modificada | Alta (8.8) | 0.51% | — | Ukrsolution Print Labels With Barcodes | 2/5/2024 | 17/6/2026 | The Print Labels with Barcodes. Create price tags, product labels, order labels for WooCommerce plugin for WordPress is vulnerable to unauthorized access of data, modification of data, and loss of data due to an improper capability check on 42 separate AJAX functions in all versions up to, and including, 3.4.6. This… | |
| Aplazada | Alta (7.5) | 0.77% | — | Proquality PqprintshippinglabelsAI | 30/4/2024 | 17/6/2026 | ProQuality pqprintshippinglabels before v.4.15.0 is vulnerable to Directory Traversal via the pqprintshippinglabels module. | |
| Aplazada | Alta (8.8) | 0.31% | — | Dymo Labelwriter Print ServerAI | 19/4/2024 | 17/6/2026 | DYMO LabelWriter Print Server through 2.366 contains a backdoor hard-coded password that could allow an attacker to take control. | |
| Aplazada | Alta (7.5) | 0.55% | — | Lenovo PrintersAI | 5/4/2024 | 17/6/2026 | A denial of service vulnerability was reported in some Lenovo Printers that could allow an attacker to cause the device to crash by sending crafted LPD packets. | |
| Aplazada | Alta (7.5) | 0.49% | — | Lenovo PrintersAI | 5/4/2024 | 17/6/2026 | A vulnerability was reported in some Lenovo Printers that could allow an unauthenticated attacker to obtain the administrator password. | |
| Aplazada | Media (5.3) | 0.55% | — | Lenovo PrintersAI | 5/4/2024 | 17/6/2026 | A vulnerability was reported in some Lenovo Printers that could allow an unauthenticated attacker to reboot the printer without authentication. | |
| Aplazada | Media (4.9) | 0.52% | — | Lenovo PrintersAI | 5/4/2024 | 17/6/2026 | A denial of service vulnerability was reported in the HTTPS service of some Lenovo Printers that could result in a system reboot. | |
| Aplazada | Media (4.9) | 0.53% | — | Lenovo PrinterAI | 5/4/2024 | 17/6/2026 | A buffer overflow vulnerability was reported in the HTTPS service of some Lenovo Printers that could result in denial of service. | |
| Aplazada | Media (6.3) | 0.25% | — | Lenovo DevicesAISynaptics Fingerprint ReaderAIMicrosoft Windows HelloAI | 5/4/2024 | 17/6/2026 | An authentication bypass vulnerability was reported in Lenovo devices with Synaptics fingerprint readers that could allow an attacker with physical access to replay fingerprints and bypass Windows Hello authentication. | |
| Aplazada | Media (6.5) | 0.35% | — | Bplugins Print PageAI | 29/3/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in bPlugins Print Page block allows Stored XSS.This issue affects Print Page block: from n/a through 1.0.8. | |
| Aplazada | Alta (7.1) | 0.19% | — | CPF Concepts LLC BizprintAI | 27/3/2024 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in BizSwoop a CPF Concepts, LLC Brand BizPrint allows Cross-Site Scripting (XSS).This issue affects BizPrint: from n/a through 4.5.5. | |
| Analizada | Media (4.8) | 0.44% | — | Octoprint | 18/3/2024 | 17/6/2026 | OctoPrint provides a web interface for controlling consumer 3D printers. OctoPrint versions up until and including 1.9.3 contain a vulnerability that allows malicious admins to configure or talk a victim with administrator rights into configuring a webcam snapshot URL which when tested through the "Test" button… | |
| Aplazada | Media (5.3) | 0.34% | — | Brother Industries PrinterAIBrother Industries ScannerAI | 18/3/2024 | 17/6/2026 | Improper authentication vulnerability in exists in multiple printers and scanners which implement Web Based Management provided by BROTHER INDUSTRIES, LTD. If this vulnerability is exploited, a network-adjacent user who can access the product may impersonate an administrative user. As for the details of affected… |