Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2739▼ 510 respecto a la semana anterior
Críticas / altas1303▼ 212 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)225▼ 276 respecto a la semana anterior
–

645 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaAlta (7.4)0.74%—Kozea WeasyprintFedoraproject Fedora9/3/202417/6/2026
WeasyPrint helps web developers to create PDF documents. Since version 61.0, there's a vulnerability which allows attaching content of arbitrary files and URLs to a generated PDF document, even if `url_fetcher` is configured to prevent access to files and URLs. This vulnerability has been patched in version 61.2.
ModificadaCrítica (9.8)6.6%💥 ExploitWp3dprinting 3dprint Lite5/2/202417/6/2026
The 3DPrint Lite WordPress plugin before 1.9.1.5 does not have any authorisation and does not check the uploaded file in its p3dlite_handle_upload AJAX action , allowing unauthenticated users to upload arbitrary file to the web server. However, there is a .htaccess, preventing the file to be accessed on Web servers…
ModificadaMedia (4.9)0.52%—Octoprint31/1/202417/6/2026
OctoPrint is a web interface for 3D printer.s OctoPrint versions up until and including 1.9.3 contain a vulnerability that allows malicious admins to change the password of other admin accounts, including their own, without having to repeat their password. An attacker who managed to hijack an admin account might use…
ModificadaMedia (5.2)0.13%—Synaptics Fingerprint Driver27/1/202417/6/2026
Use of encryption key derived from static information in Synaptics Fingerprint Driver allows an attacker to set up a TLS session with the fingerprint sensor and send restricted commands to the fingerprint sensor. This may allow an attacker, who has physical access to the sensor, to enroll a fingerprint into the…
ModificadaCrítica (9.8)1.1%—Myq-solution Print Server23/1/202417/6/2026
MyQ Print Server before 8.2 patch 43 allows remote authenticated administrators to execute arbitrary code via PHP scripts that are reached through the administrative interface.
ModificadaMedia (6.1)0.52%—Tychesoftwares Print Invoice & Delivery Notes FOR Woocommerce16/1/202417/6/2026
The Print Invoice & Delivery Notes for WooCommerce WordPress plugin before 4.7.2 is vulnerable to reflected XSS by echoing a GET value in an admin note within the WooCommerce orders page. This means that this vulnerability can be exploited for users with the edit_others_shop_orders capability. WooCommerce must be…
ModificadaAlta (8.1)0.40%—3dprint Project 3dprint16/1/202417/6/2026
The 3dprint WordPress plugin before 3.5.6.9 does not protect against CSRF attacks in the modified version of Tiny File Manager included with the plugin, allowing an attacker to craft a malicious request that will delete any number of files or directories on the target server by tricking a logged in admin into…
ModificadaAlta (7.8)1.2%—Microsoft Printer Metadata Troubleshooter Tool9/1/202417/6/2026
Microsoft Printer Metadata Troubleshooter Tool Remote Code Execution Vulnerability
ModificadaMedia (5.5)0.19%—Brother Iprint&scan26/12/202317/6/2026
Improper link resolution before file access ('Link Following') issue exists in iPrint&Scan Desktop for Windows versions 11.0.0 and earlier. A symlink attack by a malicious user may cause a Denial-of-service (DoS) condition on the PC.
ModificadaMedia (6.4)0.41%—Goodix Fingerprint Sensor Firmware9/12/202317/6/2026
The Goodix Fingerprint Device, as shipped in Dell Inspiron 15 computers, does not follow the Secure Device Connection Protocol (SDCP) when enrolling via Linux, and accepts an unauthenticated configuration packet to select the Windows template database, which allows bypass of Windows Hello authentication by enrolling…
ModificadaAlta (7.8)0.17%—HP Print AND Scan Doctor25/10/202317/6/2026
HP Print and Scan Doctor for Windows may potentially be vulnerable to escalation of privilege. HP is releasing software updates to mitigate the potential vulnerability.
ModificadaMedia (4.8)0.39%—Print, Pdf, Email BY Printfriendly25/10/202317/6/2026
Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Print, PDF, Email by PrintFriendly plugin <= 5.5.1 versions.
ModificadaMedia (6.5)0.57%—Octoprint9/10/202317/6/2026
OctoPrint is a web interface for 3D printers. OctoPrint versions up until and including 1.9.2 contain a vulnerability that allows malicious admins to configure a specially crafted GCODE script that will allow code execution during rendering of that script. An attacker might use this to extract data managed by…
ModificadaAlta (7)0.68%💥 PoCOpenprinting CupsOpenprinting LibppdFedoraproject FedoraDebian Linux21/9/202317/6/2026
Due to failure in validating the length provided by an attacker-crafted PPD PostScript document, CUPS and libppd are susceptible to a heap-based buffer overflow and possibly code execution. This issue has been fixed in CUPS version 2.4.7, released in September of 2023.
ModificadaMedia (6.5)0.27%—Papercut Mobility Print Server20/9/202317/6/2026
The `PaperCutNG Mobility Print` version 1.0.3512 application allows an unauthenticated attacker to perform a CSRF attack on an instance administrator to configure the clients host (in the "configure printer discovery" section). This is possible because the application has no protections against CSRF attacks, like…
ModificadaCrítica (9.8)2.0%—Wibu Codemeter RuntimeTrumpf OseonTrumpf ProgrammingtubeTrumpf Teczonebend+2013/9/202317/6/2026
A heap buffer overflow vulnerability in Wibu CodeMeter Runtime network service up to version 7.60b allows an unauthenticated, remote attacker to achieve RCE and gain full access of the host system.
ModificadaCrítica (9.8)0.62%—Osoft Dyeing - Printing - Finishing Production Management5/9/202317/6/2026
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Osoft Paint Production Management allows SQL Injection. This issue affects Paint Production Management: before 2.1.
ModificadaMedia (6.1)0.38%—Bhavikpatel Woocommerce-order-address-print30/8/202317/6/2026
Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Bhavik Patel Woocommerce Order address Print plugin <= 3.2 versions.
ModificadaCrítica (9.9)0.95%—Vasion Printerlogic Client25/7/202317/6/2026
An issue was discovered in Vasion PrinterLogic Client for Windows before 25.0.0.836. During client installation and repair, a PrinterLogic binary is called by the installer to configure the device. This window is not hidden, and is running with elevated privileges. A standard user can break out of this window,…
ModificadaCrítica (9.9)1.1%—Vasion Printerlogic Client25/7/202317/6/2026
An issue was discovered in Vasion PrinterLogic Client for Windows before 25.0.0.818. During installation, binaries gets executed out of a subfolder in C:\Windows\Temp. A standard user can create the folder and path file ahead of time and obtain elevated code execution.
ModificadaMedia (6.1)0.58%—Paulprinting Project Paulprinting20/7/202317/6/2026
A vulnerability, which was classified as problematic, was found in PaulPrinting CMS 2018. Affected is an unknown function of the file /account/delivery of the component Search. The manipulation of the argument s leads to cross site scripting. It is possible to launch the attack remotely. The exploit has been disclosed…
ModificadaMedia (5.4)0.60%—Paulprinting Project Paulprinting20/7/202317/6/2026
A vulnerability was found in PaulPrinting CMS 2018. It has been rated as problematic. Affected by this issue is some unknown functionality. The manipulation of the argument firstname/lastname/address/city/state leads to cross site scripting. The attack may be launched remotely. The exploit has been disclosed to the…
ModificadaMedia (5.3)0.35%—3dprint Project 3dprint17/7/202317/6/2026
The 3DPrint WordPress plugin before 3.5.6.9 does not protect against CSRF attacks in the modified version of Tiny File Manager included with the plugin, allowing an attacker to craft a malicious request that will create an archive of any files or directories on the target server by tricking a logged in admin into…
ModificadaAlta (7.5)0.94%—Fujifilm Docuprint M265 Z FirmwareFujifilm Docuprint M268 Z FirmwareFujifilm Docuprint M225 Z FirmwareFujifilm Docuprint M225 DW Firmware+21211/7/202317/6/2026
Null pointer dereference vulnerability exists in multiple vendors MFPs and printers which implement Debut web server 1.2 or 1.3. Processing a specially crafted request may lead an affected product to a denial-of-service (DoS) condition. As for the affected products/models/versions, see the detailed information…
ModificadaAlta (8.8)2.7%💥 PoCMaxprintisp Maxlink 1200g Firmware30/6/20239/7/2026
Maxprint Maxlink 1200G v3.4.11E has an OS command injection vulnerability in the "Diagnostic tool" functionality of the device.