Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2743▼ 518 respecto a la semana anterior
Críticas / altas1293▼ 226 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)244▼ 258 respecto a la semana anterior
–

645 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (7.1)1.4%—Openprinting CupsFedoraproject FedoraDebian LinuxApple Macos22/6/202317/6/2026
OpenPrinting CUPS is a standards-based, open source printing system for Linux and other Unix-like operating systems. Starting in version 2.0.0 and prior to version 2.4.6, CUPS logs data of free memory to the logging service AFTER the connection has been closed, when it should have logged the data right before. This is…
ModificadaAlta (7.8)0.14%—Ricoh Printer Driver Packager NX19/6/202317/6/2026
The driver installation package created by Printer Driver Packager NX v1.0.02 to v1.1.25 fails to detect its modification and may spawn an unexpected process with the administrative privilege. If a non-administrative user modifies the driver installation package and runs it on the target PC, an arbitrary program may…
AnalizadaCrítica (9.8)1.5%—Openprinting Cpdb-libs14/6/202317/6/2026
cpdb-libs provides frontend and backend libraries for the Common Printing Dialog Backends (CPDB) project. In versions 1.0 through 2.0b4, cpdb-libs is vulnerable to buffer overflows via improper use of `scanf(3)`. cpdb-libs uses the `fscanf()` and `scanf()` functions to parse command lines and configuration files,…
ModificadaAlta (8.8)1.3%—Xforwoocommerce ADD Product TabsXforwoocommerce Autopilot SEOXforwoocommerce Bulk ADD TO CartXforwoocommerce Comment AND Review Spam Control+127/6/202317/6/2026
Sixteen XforWooCommerce Add-On Plugins for WordPress are vulnerable to authorization bypass due to a missing capability check on the wp_ajax_svx_ajax_factory function in various versions listed below. This makes it possible for authenticated attackers, with subscriber-level permissions and above, to read, edit, or…
ModificadaMedia (5.5)1.5%—Openprinting CupsDebian Linux1/6/202317/6/2026
OpenPrinting CUPS is an open source printing system. In versions 2.4.2 and prior, a heap buffer overflow vulnerability would allow a remote attacker to launch a denial of service (DoS) attack. A buffer overflow vulnerability in the function `format_log_line` could allow remote attackers to cause a DoS on the affected…
ModificadaBaja (3.3)0.21%—Brother Iprint&scan18/5/202317/6/2026
Brother iPrint&Scan V6.11.2 and earlier contains an improper access control vulnerability. This vulnerability may be exploited by the other app installed on the victim user's Android device, which may lead to displaying the settings and/or log information of the affected app as a print preview.
ModificadaAlta (8.8)0.84%—Myq-solution Central ServerMyq-solution Print Server26/4/202317/6/2026
Incorrect access control in the runReport function of MyQ Solution Print Server before 8.2 Patch 32 and Central Server before 8.2 Patch 22 allows users who do not have appropriate access rights to generate internal reports using a direct URL.
ModificadaMedia (5.5)0.34%—Kyocera Mobile PrintTriumph-adler Mobile PrintOlivetti Mobile Print13/4/202317/6/2026
KYOCERA Mobile Print' v3.2.0.230119 and earlier, 'UTAX/TA MobilePrint' v3.2.0.230119 and earlier, and 'Olivetti Mobile Print' v3.2.0.230119 and earlier are vulnerable to improper intent handling. When a malicious app is installed on the victim user's Android device, the app may send an intent and direct the affected…
ModificadaAlta (7.8)0.18%—Dell Multifunction Printer E525w Driver AND Software Suite21/2/202317/6/2026
Dell Multifunction Printer E525w Driver and Software Suite, versions prior to 1.047.2022, A05, contain a local privilege escalation vulnerability that could be exploited by malicious users to compromise the affected system
ModificadaAlta (7.8)0.66%—Microsoft Print 3D14/2/202319/8/2026
Print 3D Remote Code Execution Vulnerability
ModificadaMedia (6.1)0.45%—Averydennison Monarch Printer M9855 Firmware10/2/202317/6/2026
Avery Dennison Monarch Printer M9855 is vulnerable to Cross Site Scripting (XSS).
ModificadaMedia (5.4)0.36%—Wepanow Print Away3/2/202317/6/2026
WEPA Print Away does not verify that a user has authorization to access documents before generating print orders and associated release codes. This could allow an attacker to generate print orders and release codes for documents they don´t own and print hem without authorization. In order to exploit this…
ModificadaMedia (5.4)0.37%—Wepanow Print Away3/2/202317/6/2026
WEPA Print Away is vulnerable to a stored XSS. It does not properly sanitize uploaded filenames, allowing an attacker to deceive a user into uploading a document with a malicious filename, which will be included in subsequent HTTP responses, allowing a stored XSS to occur. This attack is persistent across victim…
ModificadaAlta (7.8)0.30%—Qlik Nprinting Designer26/1/202317/6/2026
Qlik NPrinting Designer through 21.14.3.0 creates a Temporary File in a Directory with Insecure Permissions.
ModificadaMedia (5.4)0.47%—Print-o-matic Project Print-o-matic23/1/202317/6/2026
The Print-O-Matic WordPress plugin before 2.1.8 does not validate and escape some of its shortcode attributes before outputting them back in the page, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attacks which could be used against high privilege users such as admins.
ModificadaAlta (7.5)0.89%—Wp-print-friendly Project WP Print Friendly3/1/202316/6/2026
A vulnerability classified as problematic has been found in ethitter WP-Print-Friendly up to 0.5.2. This affects an unknown part of the file wp-print-friendly.php. The manipulation leads to information disclosure. It is possible to initiate the attack remotely. Upgrading to version 0.5.3 is able to address this issue.…
ModificadaCrítica (9.8)2.1%—Printer Project Printer31/12/202217/6/2026
A vulnerability was found in Exciting Printer and classified as critical. This issue affects some unknown processing of the file lib/printer/jobs/prepare_page.rb of the component Argument Handler. The manipulation of the argument URL leads to command injection. The patch is named…
ModificadaMedia (6.1)0.36%—Imprint CMS Project Imprint CMS21/12/202217/6/2026
A vulnerability was found in Imprint CMS. It has been classified as problematic. Affected is the function SearchForm of the file ImprintCMS/Models/ViewHelpers.cs. The manipulation of the argument query leads to cross site scripting. It is possible to launch the attack remotely. The name of the patch is…
ModificadaMedia (6.1)0.91%💥 ExploitHelloprint12/12/202217/6/2026
The Helloprint WordPress plugin before 1.4.7 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting
ModificadaCrítica (9.8)1.5%—HP Color Laserjet Cm4540 MFP Cc419a FirmwareHP Color Laserjet Cm4540 MFP Cc420a FirmwareHP Color Laserjet Cm4540 MFP Cc421a FirmwareHP Color Laserjet Cm5525 MFP Ce707a Firmware+269612/12/202217/6/2026
Certain HP Print products and Digital Sending products may be vulnerable to potential remote code execution and buffer overflow with use of Link-Local Multicast Name Resolution or LLMNR.
ModificadaMedia (6)0.42%—Octoprint19/10/202217/6/2026
Failure to Sanitize Special Elements into a Different Plane (Special Element Injection) in GitHub repository octoprint/octoprint prior to 1.8.3.
ModificadaAlta (8.8)0.51%—Octoprint21/9/202217/6/2026
Improper Privilege Management in GitHub repository octoprint/octoprint prior to 1.8.3.
ModificadaMedia (4.4)0.30%—Octoprint21/9/202217/6/2026
If an attacker comes into the possession of a victim's OctoPrint session cookie through whatever means, the attacker can use this cookie to authenticate as long as the victim's account exists.
ModificadaMedia (5.4)0.68%—Octoprint21/9/202217/6/2026
Unrestricted Upload of File with Dangerous Type in GitHub repository octoprint/octoprint prior to 1.8.3.
ModificadaMedia (5.9)1.3%—Ecisolutions Printanista Managed Print Service15/9/202217/6/2026
The login form /Login in ECi Printanista Hub (formerly FMAudit Printscout) before 5.5.2 (July 2023) performs expensive RSA key-generation operations, which allows attackers to cause a denial of service (DoS) by requesting that form repeatedly.