Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2677▼ 656 respecto a la semana anterior
Críticas / altas1264▼ 294 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)244▼ 258 respecto a la semana anterior
–

645 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (8.1)5.6%—Printerlogic WEB Stack31/1/20229/7/2026
PrinterLogic Web Stack versions 19.1.1.13 SP9 and below use a hardcoded APP_KEY value, leading to pre-auth remote code execution.
ModificadaAlta (8.1)6.2%—Printerlogic Virtual AppliancePrinterlogic WEB Stack31/1/20229/7/2026
PrinterLogic Web Stack versions 19.1.1.13 SP9 and below deserializes attacker controlled leading to pre-auth remote code execution.
ModificadaCrítica (9.8)3.9%—Printable Staff ID Card Creator System Project Printable Staff ID Card Creator System12/1/202217/6/2026
In Sourcecodetester Printable Staff ID Card Creator System 1.0 after compromising the database via SQLi, an attacker can log in and leverage an arbitrary file upload vulnerability to obtain remote code execution.
ModificadaCrítica (9.8)0.94%—Wowsoft Printchaser28/12/202117/6/2026
Printchaser v2.2021.804.1 and earlier versions contain a vulnerability, which could allow remote attacker to download and execute remote file by setting the argument, variable in the activeX module. This can be leveraged for code execution.
ModificadaMedia (5.5)0.33%—Cordova Plugin Fingerprint All-in-one Project Cordova Plugin Fingerprint All-in-one23/12/202117/6/2026
cordova-plugin-fingerprint-aio is a plugin provides a single and simple interface for accessing fingerprint APIs on both Android 6+ and iOS. In versions prior to 5.0.1 The exported activity `de.niklasmerz.cordova.biometric.BiometricActivity` can cause the app to crash. This vulnerability occurred because the activity…
ModificadaAlta (8.8)2.3%—HP Color Laserjet Cm4540 MFP FirmwareHP Color Laserjet Enterprise Flow MFP M880z FirmwareHP Color Laserjet Managed Flow MFP M880zm FirmwareHP Color Laserjet Enterprise M455 Firmware+2119/11/202117/6/2026
During installation with certain driver software or application packages an arbitrary code execution could occur.
ModificadaMedia (4.8)0.68%—Print-o-matic Project Print-o-matic8/11/202117/6/2026
The Print-O-Matic WordPress plugin before 2.0.3 does not escape some of its settings before outputting them in attribute, which could allow high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed.
ModificadaAlta (7.8)0.29%—HP Print AND Scan Doctor3/11/202117/6/2026
HP Print and Scan Doctor may potentially be vulnerable to local elevation of privilege.
ModificadaAlta (8.1)0.54%—Print MY Blog Project Print MY Blog20/9/202117/6/2026
The Print My Blog WordPress Plugin before 3.4.2 does not enforce nonce (CSRF) checks, which allows attackers to make logged in administrators deactivate the Print My Blog plugin and delete all saved data for that plugin by tricking them to open a malicious link
ModificadaMedia (6.1)0.66%—Canon OCE Print Exec Workgroup23/8/202117/6/2026
Canon Oce Print Exec Workgroup 1.3.2 allows XSS via the lang parameter.
ModificadaMedia (5.3)0.81%—Canon OCE Print Exec Workgroup23/8/202117/6/2026
Canon Oce Print Exec Workgroup 1.3.2 allows Host header injection.
ModificadaAlta (7.8)1.4%💥 ExploitLexmark G2 DriverLexmark G3 DriverLexmark G4 DriverLexmark Universal Print Driver19/7/202117/6/2026
The Lexmark Universal Print Driver version 2.15.1.0 and below, G2 driver 2.7.1.0 and below, G3 driver 3.2.0.0 and below, and G4 driver 4.2.1.0 and below are affected by a privilege escalation vulnerability. A standard low priviliged user can use the driver to execute a DLL of their choosing during the add printer…
ModificadaAlta (7.8)0.25%—Lexmark Printer Software G2Lexmark Printer Software G3Lexmark Printer Software G414/7/202117/6/2026
The Lexmark Printer Software G2, G3 and G4 Installation Packages have a local escalation of privilege vulnerability due to a registry entry that has an unquoted service path.
ModificadaMedia (6.1)1.2%—Octoprint11/5/202117/6/2026
OctoPrint before 1.6.0 allows XSS because API error messages include the values of input parameters.
ModificadaMedia (6.5)1.5%—Octoprint11/5/202117/6/2026
The Logging subsystem in OctoPrint before 1.6.0 has incorrect access control because it attempts to manage files that are not *.log files.
ModificadaAlta (7.5)1.5%—Fujixerox Docucentre-vii C7773 FirmwareFujixerox Docucentre-vii C6673 FirmwareFujixerox Docucentre-vii C5573 FirmwareFujixerox Docucentre-vii C4473 Firmware+7125/3/202117/6/2026
Fuji Xerox multifunction devices and printers (DocuCentre-VII C7773/C6673/C5573/C4473/C3373/C3372/C2273, DocuCentre-VII C7788/C6688/C5588, ApeosPort-VII C7773/C6673/C5573/C4473/C3373/C3372 C2273, ApeosPort-VII C7788/C6688/C5588, ApeosPort C7070/C6570/C5570/C4570/C3570/C3070/C7070G/C6570G/C5570G/C4570G/C3570G/C3070G,…
ModificadaAlta (7.5)2.2%—Adaltas Printf12/3/202117/6/2026
The package printf before 0.6.1 are vulnerable to Regular Expression Denial of Service (ReDoS) via the regex string /\%(?:\(([\w_.]+)\)|([1-9]\d*)\$)?([0 +\-\]*)(\*|\d+)?(\.)?(\*|\d+)?[hlL]?([\%bscdeEfFgGioOuxX])/g in lib/printf.js. The vulnerable regular expression has cubic worst-case time complexity.
ModificadaCrítica (9.8)4.2%—Eprints1/3/202117/6/2026
EPrints 3.4.2 allows remote attackers to read arbitrary files and possibly execute commands via crafted LaTeX input to a cgi/latex2png?latex= URI.
ModificadaAlta (8.8)3.1%—Eprints1/3/202117/6/2026
EPrints 3.4.2 allows remote attackers to execute arbitrary commands via crafted input to the verb parameter in a cgi/toolbox/toolbox URI.
ModificadaCrítica (9.8)4.0%—Eprints1/3/202117/6/2026
EPrints 3.4.2 allows remote attackers to read arbitrary files and possibly execute commands via crafted JSON/XML input to a cgi/ajax/phrase URI.
ModificadaMedia (6.1)3.1%💥 ExploitEprints1/3/202117/6/2026
EPrints 3.4.2 exposes a reflected XSS opportunity in the dataset parameter to the cgi/dataset_dictionary URI.
ModificadaCrítica (9.8)3.1%—Eprints1/3/202117/6/2026
EPrints 3.4.2 allows remote attackers to execute OS commands via crafted LaTeX input to a cgi/cal?year= URI.
ModificadaMedia (6.1)7.3%💥 ExploitEprints1/3/202117/6/2026
EPrints 3.4.2 exposes a reflected XSS opportunity in the via a cgi/cal URI.
ModificadaAlta (7.8)0.88%—Epsonnet SetupmanagerEpson Offirio Synergyware Printdirector24/12/202017/6/2026
Untrusted search path vulnerability in self-extracting files created by EpsonNet SetupManager versions 2.2.14 and earlier, and Offirio SynergyWare PrintDirector versions 1.6x/1.6y and earlier allows an attacker to gain privileges via a Trojan horse DLL in an unspecified directory.
ModificadaAlta (7.8)0.34%—Epson Album PrintEpson Color Calibration UtilityEpson ColorbaseEpson Colorio Easy Print+2924/11/202017/6/2026
Untrusted search path vulnerability in the installers of multiple SEIKO EPSON products allows an attacker to gain privileges via a Trojan horse DLL in an unspecified directory.
Orbitaley — Vulnerabilidades