Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2678▼ 660 respecto a la semana anterior
Críticas / altas1266▼ 293 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)250▼ 252 respecto a la semana anterior
–

645 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaCrítica (9.1)1.3%—Mapfish Print2/10/202017/6/2026
In mapfish-print before version 3.24, a user can do to an XML External Entity (XXE) attack with the provided SDL style.
ModificadaMedia (6.1)0.80%—Mapfish Print2/10/202017/6/2026
In mapfish-print before version 3.24, a user can use the JSONP support to do a Cross-site scripting.
ModificadaCrítica (9.8)2.5%—Mijia Inkjet Printer Firmware24/6/202017/6/2026
An issue was discovered on Xiaomi Mi Jia ink-jet printer < 3.4.6_0138. Injecting parameters to ippserver through the web management background, resulting in command execution vulnerabilities.
ModificadaCrítica (9.8)14%💥 ExploitFreereprintables Articlefr13/2/202017/6/2026
A Privilege Escalation Vulnerability exists in Free Reprintables ArticleFR 11.06.2014 due to insufficient access restrictions in the data.php script, which could let a remote malicious user obtain access or modify or delete database information.
ModificadaAlta (7.4)0.52%—Fujixerox Easy Netprint27/1/202017/6/2026
The kantan netprint App for Android 2.0.3 and earlier does not verify X.509 certificates from servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.
ModificadaAlta (7.4)0.52%—Fujixerox Easy Netprint27/1/202017/6/2026
The kantan netprint App for iOS 2.0.2 and earlier does not verify X.509 certificates from servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.
ModificadaAlta (7.4)0.52%—Fujixerox Netprint27/1/202017/6/2026
The netprint App for iOS 3.2.3 and earlier does not verify X.509 certificates from servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.
ModificadaAlta (7.8)4.4%💥 ExploitRicoh Generic Pcl5 DriverRicoh PC FAX Generic DriverRicoh Pcl6 (pcl XL) DriverRicoh Pcl6 Driver FOR Universal Print+424/1/202017/6/2026
An issue was discovered in Ricoh (including Savin and Lanier) Windows printer drivers prior to 2020 that allows attackers local privilege escalation. Affected drivers and versions are: PCL6 Driver for Universal Print - Version 4.0 or later PS Driver for Universal Print - Version 4.0 or later PC FAX Generic Driver -…
ModificadaMedia (5.5)0.58%—Freereprintables Articlefr15/1/202017/6/2026
Directory traversal vulnerability in application/templates/amelia/loadjs.php in Free Reprintables ArticleFR 3.0.7 and earlier allows local users to read arbitrary files via the s parameter.
ModificadaBaja (3.3)0.39%—HP Samsung Mobile Print9/1/202017/6/2026
An issue was found in Samsung Mobile Print (Android) versions prior to 4.08.007. A potential security vulnerability caused by incomplete obfuscation of application configuration information.
ModificadaAlta (8.1)4.5%💥 ExploitXmlblueprint30/12/201917/6/2026
XMLBlueprint through 16.191112 is affected by XML External Entity Injection. The impact is: Arbitrary File Read when an XML File is validated. The component is: XML Validate function. The attack vector is: Specially crafted XML payload.
ModificadaCrítica (9.8)2.6%—Abcprintf Upload-image-with-ajax23/12/201917/6/2026
Due to a logic error in the code, upload-image-with-ajax v1.0 allows arbitrary files to be uploaded to the web root allowing code execution.
ModificadaCrítica (9.8)10%💥 ExploitTitool Printmonitor6/12/201917/6/2026
The username parameter of the TITool PrintMonitor solution during the login request is vulnerable to and/or time-based blind SQLi.
ModificadaCrítica (9.8)41%—Hm-print Project Hm-printEq-3 Homematic Ccu2 FirmwareEq-3 Homematic Ccu3 Firmware14/11/201917/6/2026
eQ-3 Homematic CCU2 2.47.20 and CCU3 3.47.18 with the HM-Print AddOn through 1.2a installed allow Remote Code Execution by unauthenticated attackers with access to the web interface via the exec.cgi and exec1.cgi scripts, which execute TCL script content from an HTTP POST request.
ModificadaMedia (5.8)1.5%—Cisco Secure Firewall Management CenterCisco VDB Fingerprint Database2/10/201917/6/2026
A vulnerability in the file and malware inspection feature of Cisco Firepower Management Center (FMC) Software could allow an unauthenticated, remote attacker to bypass the file and malware inspection policies on an affected system. The vulnerability exists because the affected software insufficiently validates…
ModificadaMedia (5.5)5.4%💥 ExploitCanon Print5/9/201917/6/2026
The ContentProvider in the Canon PRINT jp.co.canon.bsd.ad.pixmaprint 2.5.5 application for Android does not properly restrict canon.ij.printer.capability.data data access. This allows an attacker's malicious application to obtain sensitive information including factory passwords for the administrator web interface and…
ModificadaMedia (6.1)0.91%—Bestwebsoft PDF & Print21/8/201917/6/2026
The pdf-print plugin before 2.0.3 for WordPress has multiple XSS issues.
ModificadaMedia (6.1)1.8%💥 ExploitBestwebsoft PDF & Print20/8/201917/6/2026
The pdf-print plugin before 1.9.4 for WordPress has multiple XSS issues.
ModificadaAlta (8.8)1.4%—Printeron Central Print Services29/7/201917/6/2026
An issue was discovered in PrinterOn Central Print Services (CPS) through 4.1.4. A user without valid credentials can bypass the authentication process, obtaining a valid session cookie with guest/pseudo-guest level privileges. This cookie can then be further used to perform other attacks.
ModificadaMedia (5.3)1.7%—Printeron Central Print Services29/7/201917/6/2026
An issue was discovered in PrinterOn Central Print Services (CPS) through 4.1.4. An unauthenticated attacker can view details about the printers associated with CPS via a crafted HTTP GET request.
ModificadaAlta (8.8)1.7%—Printeron Central Print Services20/7/201917/6/2026
An issue was discovered in PrinterOn Central Print Services (CPS) through 4.1.4. The core components that create and launch a print job do not perform complete verification of the session cookie that is supplied to them. As a result, an attacker with guest/pseudo-guest level permissions can bypass the session checks…
ModificadaCrítica (9.8)3.5%—Printerlogic Print Management8/5/201917/6/2026
The PrinterLogic Print Management software, versions up to and including 18.3.1.96, does not sanitize special characters allowing for remote unauthorized changes to configuration files. An unauthenticated attacker may be able to remotely execute arbitrary code with SYSTEM privileges.
ModificadaCrítica (9.8)1.1%—Printerlogic Print Management8/5/201917/6/2026
The PrinterLogic Print Management software, versions up to and including 18.3.1.96, updates and executes the code without sufficiently verifying the origin and integrity of the code. An attacker can execute malicious code by compromising the host server, performing DNS spoofing, or modifying the code in transit.
ModificadaAlta (7.4)0.75%—Printerlogic Print Management8/5/201917/6/2026
The PrinterLogic Print Management software, versions up to and including 18.3.1.96, does not validate, or incorrectly validates, the PrinterLogic management portal's SSL certificate. When a certificate is invalid or malicious, it might allow an attacker to spoof a trusted entity by using a man-in-the-middle (MITM)…
ModificadaCrítica (9.8)2.8%—Print MY Blog Project Print MY Blog27/4/201917/6/2026
Server Side Request Forgery (SSRF) exists in the Print My Blog plugin before 1.6.7 for WordPress via the site parameter.
Orbitaley — Vulnerabilidades