Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2730▼ 551 respecto a la semana anterior
Críticas / altas1294▼ 234 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)244▼ 258 respecto a la semana anterior
–

645 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaAlta (8.8)1.8%—Printerlogic Windows Client25/8/202217/6/2026
PrinterLogic Windows Client through 25.0.0.676 allows attackers to execute directory traversal. Authenticated users with prior knowledge of the driver filename could exploit this to escalate privileges or distribute malicious content. This issue has been resolved in PrinterLogic Windows Client 25.0.0688 and all…
ModificadaAlta (7.8)0.35%—Octoprint22/8/202217/6/2026
Unverified Password Change in GitHub repository octoprint/octoprint prior to 1.8.3.
ModificadaAlta (8.8)0.86%—Prinitix Cloud Print Management19/8/20229/7/2026
Printix Cloud Print Management v1.3.1149.0 for Windows was discovered to contain insecure permissions.
ModificadaAlta (7.5)0.85%—Octoprint15/8/202217/6/2026
An attacker can freely brute force username and password and can takeover any account. An attacker could easily guess user passwords and gain access to user and administrative accounts.
ModificadaMedia (4.8)0.59%—Print, Pdf, Email BY Printfriendly20/6/202217/6/2026
The Print, PDF, Email by PrintFriendly WordPress plugin before 5.2.3 does not sanitise and escape the Custom Button Text settings, which could allow high privilege users such as admin to perform cross-Site Scripting attacks even when the unfiltered_html capability is disallowed
ModificadaAlta (7.1)0.26%—Synaptics Fingerprint Driver16/6/202217/6/2026
Improper Input Validation vulnerability in synaTEE.signed.dll of Synaptics Fingerprint Driver allows a local authorized attacker to overwrite a heap tag, with potential loss of confidentiality. This issue affects: Synaptics Synaptics Fingerprint Driver 5.1.xxx.26 versions prior to xxx=340 on x86/64; 5.2.xxxx.26…
ModificadaMedia (4.6)0.48%—Verbatim Executive Fingerprint Secure SSD FirmwareVerbatim Fingerprint Secure Portable Hard Drive Firmware8/6/202217/6/2026
An issue was discovered in certain Verbatim drives through 2022-03-31. Due to an insecure design, they can be unlocked by an attacker who can then gain unauthorized access to the stored data. The attacker can simply use an undocumented IOCTL command that retrieves the correct password. This affects Executive…
ModificadaMedia (4.6)0.32%—Verbatim Executive Fingerprint Secure SSD FirmwareVerbatim Fingerprint Secure Portable Hard Drive Firmware8/6/202217/6/2026
An issue was discovered in certain Verbatim drives through 2022-03-31. Due to missing integrity checks, an attacker can manipulate the content of the emulated CD-ROM drive (containing the Windows and macOS client software). The content of this emulated CD-ROM drive is stored as an ISO-9660 image in the hidden sectors…
ModificadaMedia (6.8)0.59%—Verbatim Keypad Secure USB 3.2 GEN 1 FirmwareVerbatim Store 'N' GO Secure Portable HDD FirmwareVerbatim Executive Fingerprint Secure SSD FirmwareVerbatim Fingerprint Secure Portable Hard Drive Firmware8/6/202217/6/2026
An issue was discovered in certain Verbatim drives through 2022-03-31. Due to insufficient firmware validation, an attacker can store malicious firmware code for the USB-to-SATA bridge controller on the USB drive (e.g., by leveraging physical access during the supply chain). This code is then executed. This affects…
ModificadaAlta (7.5)1.8%—Verbatim Keypad Secure USB 3.2 GEN 1 FirmwareVerbatim Store 'N' GO Secure Portable HDD FirmwareVerbatim Executive Fingerprint Secure SSD FirmwareVerbatim Fingerprint Secure Portable Hard Drive Firmware8/6/202217/6/2026
An issue was discovered in certain Verbatim drives through 2022-03-31. Due to the use of an insecure encryption AES mode (Electronic Codebook, aka ECB), an attacker may be able to extract information even from encrypted data, for example by observing repeating byte patterns. The firmware of the USB-to-SATA bridge…
ModificadaMedia (6.7)0.60%—Apple CupsApple MAC OS XApple MacosDebian Linux+226/5/202217/6/2026
A logic issue was addressed with improved state management. This issue is fixed in Security Update 2022-003 Catalina, macOS Monterey 12.3, macOS Big Sur 11.6.5. An application may be able to gain elevated privileges.
ModificadaMedia (6.4)1.2%—Octoprint18/5/202217/6/2026
Cross-site Scripting (XSS) - Generic in GitHub repository octoprint/octoprint prior to 1.8.0.
ModificadaAlta (7.5)1.4%—Octoprint18/5/202217/6/2026
Cross-site Scripting (XSS) - DOM in GitHub repository octoprint/octoprint prior to 1.8.0.
ModificadaAlta (7.5)7.9%💥 ExploitWebtoprint WEB TO Print Shop\25/4/202217/6/2026
The Web To Print Shop : uDraw WordPress plugin before 3.3.3 does not validate the url parameter in its udraw_convert_url_to_base64 AJAX action (available to both unauthenticated and authenticated users) before using it in the file_get_contents function and returning its content base64 encoded in the response. As a…
ModificadaCrítica (9.1)0.97%—Rambus Safezone Basic Crypto ModuleFujifilm Apeos C7070 FirmwareFujifilm Apeos C6570 FirmwareFujifilm Apeos C5570 Firmware+8814/3/202217/6/2026
The Rambus SafeZone Basic Crypto Module before 10.4.0, as used in certain Fujifilm (formerly Fuji Xerox) devices before 2022-03-01, Canon imagePROGRAF and imageRUNNER devices through 2022-03-14, and potentially many other devices, generates RSA keys that can be broken with Fermat's factorization method. This allows…
ModificadaAlta (8.1)11%💥 ExploitKofax Printix10/3/20229/7/2026
Printix Secure Cloud Print Management through 1.3.1106.0 creates a temporary temp.ini file in a directory with insecure permissions, leading to privilege escalation because of a race condition.
ModificadaMedia (4.9)0.69%—Fujifilm Apeosport-iv 7080 FirmwareFujifilm Apeosport-iv 6080 FirmwareFujifilm Apeosport-iv 5080 FirmwareFujifilm Apeosport-iv 3065 Firmware+1563/3/202217/6/2026
A risky-algorithm issue was discovered on Fujifilm DocuCentre-VI C4471 1.8 devices. An attacker that obtained access to the administrative web interface of a printer (e.g., by using the default credentials) can download the address book file, which contains the list of users (domain users, FTP users, etc.) stored on…
ModificadaCrítica (9.8)18%💥 ExploitKofax Printix3/3/20229/7/2026
Printix Secure Cloud Print Management through 1.3.1106.0 incorrectly uses Privileged APIs to modify values in HKEY_LOCAL_MACHINE via UITasks.PersistentRegistryData.
ModificadaAlta (7.5)1.4%—Printerlogic WEB Stack2/2/20229/7/2026
PrinterLogic Web Stack versions 19.1.1.13 SP9 and below are vulnerable to an Insecure Direct Object Reference (IDOR) vulnerability that allows an unauthenticated attacker to disclose the plaintext console username and password for a printer.
ModificadaAlta (7.5)2.0%—Printerlogic WEB Stack2/2/20229/7/2026
PrinterLogic Web Stack versions 19.1.1.13 SP9 and below are vulnerable to an Insecure Direct Object Reference (IDOR) vulnerability that allows an unauthenticated attacker to disclose the username and email address of all users.
ModificadaCrítica (9.1)2.0%—Printerlogic WEB Stack2/2/20229/7/2026
PrinterLogic Web Stack versions 19.1.1.13 SP9 and below are vulnerable to an Insecure Direct Object Reference (IDOR) vulnerability that allows an unauthenticated attacker to reassign drivers for any printer.
ModificadaMedia (6.1)1.2%—Printerlogic WEB Stack2/2/20229/7/2026
PrinterLogic Web Stack versions 19.1.1.13 SP9 and below are vulnerable to multiple reflected cross site scripting vulnerabilities. Attacker controlled input is reflected back in the page without sanitization.
ModificadaCrítica (9.8)2.3%—Printerlogic WEB Stack2/2/20229/7/2026
PrinterLogic Web Stack versions 19.1.1.13 SP9 and below use user-controlled input to craft a URL, resulting in a Server Side Request Forgery (SSRF) vulnerability.
ModificadaMedia (5.3)2.0%—Printerlogic WEB Stack2/2/20229/7/2026
PrinterLogic Web Stack versions 19.1.1.13 SP9 and below are vulnerable to SQL Injection, which may allow an attacker to access additional audit records.
ModificadaAlta (8.1)5.5%—Printerlogic WEB Stack1/2/20229/7/2026
PrinterLogic Web Stack versions 19.1.1.13 SP9 and below do not sanitize user input resulting in pre-auth remote code execution.