Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2677▼ 656 respecto a la semana anterior
Críticas / altas1264▼ 294 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)244▼ 258 respecto a la semana anterior
645 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (8.1) | 5.6% | — | Printerlogic WEB Stack | 31/1/2022 | 9/7/2026 | PrinterLogic Web Stack versions 19.1.1.13 SP9 and below use a hardcoded APP_KEY value, leading to pre-auth remote code execution. | |
| Modificada | Alta (8.1) | 6.2% | — | Printerlogic Virtual AppliancePrinterlogic WEB Stack | 31/1/2022 | 9/7/2026 | PrinterLogic Web Stack versions 19.1.1.13 SP9 and below deserializes attacker controlled leading to pre-auth remote code execution. | |
| Modificada | Crítica (9.8) | 3.9% | — | Printable Staff ID Card Creator System Project Printable Staff ID Card Creator System | 12/1/2022 | 17/6/2026 | In Sourcecodetester Printable Staff ID Card Creator System 1.0 after compromising the database via SQLi, an attacker can log in and leverage an arbitrary file upload vulnerability to obtain remote code execution. | |
| Modificada | Crítica (9.8) | 0.94% | — | Wowsoft Printchaser | 28/12/2021 | 17/6/2026 | Printchaser v2.2021.804.1 and earlier versions contain a vulnerability, which could allow remote attacker to download and execute remote file by setting the argument, variable in the activeX module. This can be leveraged for code execution. | |
| Modificada | Media (5.5) | 0.33% | — | Cordova Plugin Fingerprint All-in-one Project Cordova Plugin Fingerprint All-in-one | 23/12/2021 | 17/6/2026 | cordova-plugin-fingerprint-aio is a plugin provides a single and simple interface for accessing fingerprint APIs on both Android 6+ and iOS. In versions prior to 5.0.1 The exported activity `de.niklasmerz.cordova.biometric.BiometricActivity` can cause the app to crash. This vulnerability occurred because the activity… | |
| Modificada | Alta (8.8) | 2.3% | — | HP Color Laserjet Cm4540 MFP FirmwareHP Color Laserjet Enterprise Flow MFP M880z FirmwareHP Color Laserjet Managed Flow MFP M880zm FirmwareHP Color Laserjet Enterprise M455 Firmware+211 | 9/11/2021 | 17/6/2026 | During installation with certain driver software or application packages an arbitrary code execution could occur. | |
| Modificada | Media (4.8) | 0.68% | — | Print-o-matic Project Print-o-matic | 8/11/2021 | 17/6/2026 | The Print-O-Matic WordPress plugin before 2.0.3 does not escape some of its settings before outputting them in attribute, which could allow high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed. | |
| Modificada | Alta (7.8) | 0.29% | — | HP Print AND Scan Doctor | 3/11/2021 | 17/6/2026 | HP Print and Scan Doctor may potentially be vulnerable to local elevation of privilege. | |
| Modificada | Alta (8.1) | 0.54% | — | Print MY Blog Project Print MY Blog | 20/9/2021 | 17/6/2026 | The Print My Blog WordPress Plugin before 3.4.2 does not enforce nonce (CSRF) checks, which allows attackers to make logged in administrators deactivate the Print My Blog plugin and delete all saved data for that plugin by tricking them to open a malicious link | |
| Modificada | Media (6.1) | 0.66% | — | Canon OCE Print Exec Workgroup | 23/8/2021 | 17/6/2026 | Canon Oce Print Exec Workgroup 1.3.2 allows XSS via the lang parameter. | |
| Modificada | Media (5.3) | 0.81% | — | Canon OCE Print Exec Workgroup | 23/8/2021 | 17/6/2026 | Canon Oce Print Exec Workgroup 1.3.2 allows Host header injection. | |
| Modificada | Alta (7.8) | 1.4% | 💥 Exploit | Lexmark G2 DriverLexmark G3 DriverLexmark G4 DriverLexmark Universal Print Driver | 19/7/2021 | 17/6/2026 | The Lexmark Universal Print Driver version 2.15.1.0 and below, G2 driver 2.7.1.0 and below, G3 driver 3.2.0.0 and below, and G4 driver 4.2.1.0 and below are affected by a privilege escalation vulnerability. A standard low priviliged user can use the driver to execute a DLL of their choosing during the add printer… | |
| Modificada | Alta (7.8) | 0.25% | — | Lexmark Printer Software G2Lexmark Printer Software G3Lexmark Printer Software G4 | 14/7/2021 | 17/6/2026 | The Lexmark Printer Software G2, G3 and G4 Installation Packages have a local escalation of privilege vulnerability due to a registry entry that has an unquoted service path. | |
| Modificada | Media (6.1) | 1.2% | — | Octoprint | 11/5/2021 | 17/6/2026 | OctoPrint before 1.6.0 allows XSS because API error messages include the values of input parameters. | |
| Modificada | Media (6.5) | 1.5% | — | Octoprint | 11/5/2021 | 17/6/2026 | The Logging subsystem in OctoPrint before 1.6.0 has incorrect access control because it attempts to manage files that are not *.log files. | |
| Modificada | Alta (7.5) | 1.5% | — | Fujixerox Docucentre-vii C7773 FirmwareFujixerox Docucentre-vii C6673 FirmwareFujixerox Docucentre-vii C5573 FirmwareFujixerox Docucentre-vii C4473 Firmware+71 | 25/3/2021 | 17/6/2026 | Fuji Xerox multifunction devices and printers (DocuCentre-VII C7773/C6673/C5573/C4473/C3373/C3372/C2273, DocuCentre-VII C7788/C6688/C5588, ApeosPort-VII C7773/C6673/C5573/C4473/C3373/C3372 C2273, ApeosPort-VII C7788/C6688/C5588, ApeosPort C7070/C6570/C5570/C4570/C3570/C3070/C7070G/C6570G/C5570G/C4570G/C3570G/C3070G,… | |
| Modificada | Alta (7.5) | 2.2% | — | Adaltas Printf | 12/3/2021 | 17/6/2026 | The package printf before 0.6.1 are vulnerable to Regular Expression Denial of Service (ReDoS) via the regex string /\%(?:\(([\w_.]+)\)|([1-9]\d*)\$)?([0 +\-\]*)(\*|\d+)?(\.)?(\*|\d+)?[hlL]?([\%bscdeEfFgGioOuxX])/g in lib/printf.js. The vulnerable regular expression has cubic worst-case time complexity. | |
| Modificada | Crítica (9.8) | 4.2% | — | Eprints | 1/3/2021 | 17/6/2026 | EPrints 3.4.2 allows remote attackers to read arbitrary files and possibly execute commands via crafted LaTeX input to a cgi/latex2png?latex= URI. | |
| Modificada | Alta (8.8) | 3.1% | — | Eprints | 1/3/2021 | 17/6/2026 | EPrints 3.4.2 allows remote attackers to execute arbitrary commands via crafted input to the verb parameter in a cgi/toolbox/toolbox URI. | |
| Modificada | Crítica (9.8) | 4.0% | — | Eprints | 1/3/2021 | 17/6/2026 | EPrints 3.4.2 allows remote attackers to read arbitrary files and possibly execute commands via crafted JSON/XML input to a cgi/ajax/phrase URI. | |
| Modificada | Media (6.1) | 3.1% | 💥 Exploit | Eprints | 1/3/2021 | 17/6/2026 | EPrints 3.4.2 exposes a reflected XSS opportunity in the dataset parameter to the cgi/dataset_dictionary URI. | |
| Modificada | Crítica (9.8) | 3.1% | — | Eprints | 1/3/2021 | 17/6/2026 | EPrints 3.4.2 allows remote attackers to execute OS commands via crafted LaTeX input to a cgi/cal?year= URI. | |
| Modificada | Media (6.1) | 7.3% | 💥 Exploit | Eprints | 1/3/2021 | 17/6/2026 | EPrints 3.4.2 exposes a reflected XSS opportunity in the via a cgi/cal URI. | |
| Modificada | Alta (7.8) | 0.88% | — | Epsonnet SetupmanagerEpson Offirio Synergyware Printdirector | 24/12/2020 | 17/6/2026 | Untrusted search path vulnerability in self-extracting files created by EpsonNet SetupManager versions 2.2.14 and earlier, and Offirio SynergyWare PrintDirector versions 1.6x/1.6y and earlier allows an attacker to gain privileges via a Trojan horse DLL in an unspecified directory. | |
| Modificada | Alta (7.8) | 0.34% | — | Epson Album PrintEpson Color Calibration UtilityEpson ColorbaseEpson Colorio Easy Print+29 | 24/11/2020 | 17/6/2026 | Untrusted search path vulnerability in the installers of multiple SEIKO EPSON products allows an attacker to gain privileges via a Trojan horse DLL in an unspecified directory. |