Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2659▼ 692 respecto a la semana anterior
Críticas / altas1261▼ 300 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)250▼ 252 respecto a la semana anterior
–

645 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (7.7)1.5%—Printeron23/4/201917/6/2026
An XML external entity (XXE) vulnerability in PrinterOn version 4.1.4 and lower allows remote authenticated users to read arbitrary files or conduct server-side request forgery (SSRF) attacks via a crafted DTD in an XML request.
ModificadaMedia (6.5)0.53%—Printeron18/4/201917/6/2026
PrinterOn Enterprise 4.1.4 contains multiple Cross Site Request Forgery (CSRF) vulnerabilities in the Administration page. For example, an administrator, by following a link, can be tricked into making unwanted changes to a printer (Disable, Approve, etc).
ModificadaMedia (5.4)0.63%—Printeron21/3/201917/6/2026
PrinterOn Enterprise 4.1.4 suffers from multiple authenticated stored XSS vulnerabilities via the (1) "Machine Host Name" or "Server Serial Number" field in the clustering configuration, (2) "name" field in the Edit Group configuration, (3) "Rule Name" field in the Access Control configuration, (4) "Service Name" in…
ModificadaAlta (8.1)1.0%—Opensuse Yast2-printer15/3/201917/6/2026
In yast2-printer up to and including version 4.0.2 the SMB printer settings don't escape characters in passwords properly. If a password with backticks or simliar characters is supplied this allows for executing code as root. This requires tricking root to enter such a password in yast.
ModificadaMedia (6.5)1.1%—Printeron17/12/201817/6/2026
PrinterOn Enterprise 4.1.4 allows Arbitrary File Deletion.
ModificadaCrítica (9.8)21%—Ricoh Myprint14/12/201817/6/2026
Hardcoded credentials in the Ricoh myPrint application 2.9.2.4 for Windows and 2.2.7 for Android give access to any externally disclosed myPrint WSDL API, as demonstrated by discovering API secrets of related Google cloud printers, encrypted passwords of mail servers, and names of printed files.
ModificadaCrítica (9.1)2.1%—Octoprint7/9/201817/6/2026
OctoPrint through 1.3.9 allows remote attackers to obtain sensitive information or cause a denial of service via HTTP requests on port 8081. NOTE: the vendor disputes the significance of this report because their documentation states that with "blind port forwarding ... Putting OctoPrint onto the public internet is a…
ModificadaAlta (7.5)1.2%—Epson Iprint30/8/201817/6/2026
The ContentProvider in the EPSON iPrint application 6.6.3 for Android does not properly restrict data access. This allows an attacker's application to read scanned documents.
ModificadaAlta (7.5)1.1%—Epson Iprint30/8/201817/6/2026
The EPSON iPrint application 6.6.3 for Android contains hard-coded API and Secret keys for the Dropbox, Box, Evernote and OneDrive services.
ModificadaAlta (8.8)1.1%—Dell 2335dn Engine FirmwareDell 2335dn Network FirmwareDell 2335dn Printer Firmware23/8/201817/6/2026
On Dell 2335dn printers with Printer Firmware Version 2.70.05.02, Engine Firmware Version 1.10.65, and Network Firmware Version V4.02.15(2335dn MFP) 11-22-2010, the admin interface allows an authenticated attacker to retrieve the configured SMTP or LDAP password by viewing the HTML source code of the Email Settings…
ModificadaMedia (6.1)2.5%💥 ExploitCanon EFI Printme11/6/201817/6/2026
Cross-site scripting (XSS) vulnerability in the Canon PrintMe EFI webinterface allows remote attackers to inject arbitrary web script or HTML via the PATH_INFO to the /wt3/mydocs.php URI.
ModificadaAlta (7)0.26%—Printeron17/5/201817/6/2026
PrinterOn Enterprise 4.1.3 stores the Active Directory bind credentials using base64 encoding, which allows local users to obtain credentials for a domain user by reading the cps_config.xml file.
ModificadaMedia (5.4)0.55%—Printeron17/5/201817/6/2026
PrinterOn Enterprise 4.1.3 suffers from multiple authenticated stored XSS vulnerabilities via the (1) department field in the printer configuration, (2) description field in the print server configuration, and (3) username field for authentication to print as guest.
ModificadaMedia (6.8)0.50%—Meco USB Memory Stick With Fingerprint Firwmare22/3/201817/6/2026
An issue was discovered on MECO USB Memory Stick with Fingerprint MECOZiolsamDE601 devices. The fingerprint authentication requirement for data access can be bypassed. An attacker with physical access can send a static packet to a serial port exposed on the PCB to unlock the key and get access to the data without…
ModificadaAlta (7.5)1.9%—Sblim Project Small Footprint CIM Broker8/2/201817/6/2026
SBLIM Small Footprint CIM Broker (SFCB) 1.4.9 has a null pointer (DoS) vulnerability via a crafted POST request to the /cimom URI.
ModificadaMedia (6.1)37%—Epson Airprint8/2/201817/6/2026
Versions of Epson AirPrint released prior to January 19, 2018 contain a reflective cross-site scripting (XSS) vulnerability, which can allow untrusted users on the network to hijack a session cookie or perform other reflected XSS attacks on a currently logged-on user.
ModificadaAlta (7.8)0.40%—Lenovo Fingerprint Manager PRO26/1/201817/6/2026
Sensitive data stored by Lenovo Fingerprint Manager Pro, version 8.01.86 and earlier, including users' Windows logon credentials and fingerprint data, is encrypted using a weak algorithm, contains a hard-coded password, and is accessible to all users with local non-administrative access to the system in which it is…
ModificadaCrítica (9.8)3.8%—Node-printer Project Node-printer23/10/201717/6/2026
The printDirect function in lib/printer.js in the node-printer module 0.0.1 and earlier for Node.js allows remote attackers to execute arbitrary commands via unspecified characters in the lpr command.
ModificadaMedia (6.7)0.34%—Lenovo Fingerprint Manager3/10/201717/6/2026
Services and files in Lenovo Fingerprint Manager before 8.01.42 have incorrect ACLs, which allows local users to invalidate local checks and gain privileges via standard filesystem operations.
ModificadaAlta (7.8)19%💥 ExploitCyberlink Labelprint23/9/201717/6/2026
Stack-based buffer overflows in CyberLink LabelPrint 2.5 allow remote attackers to execute arbitrary code via the (1) author (inside the INFORMATION tag), (2) name (inside the INFORMATION tag), (3) artist (inside the TRACK tag), or (4) default (inside the TEXT tag) parameter in an lpp project file.
ModificadaMedia (6.1)0.79%—BMC Footprints Service Core28/8/201717/6/2026
Cross-site scripting (XSS) vulnerability in BMC Footprints Service Core 11.5.
ModificadaAlta (8.1)6.3%—HP Linux Imaging AND Printing2/8/201717/6/2026
The hp-plugin utility in HP Linux Imaging and Printing (HPLIP) makes it easier for man-in-the-middle attackers to execute arbitrary code by leveraging use of a short GPG key id from a keyserver to verify print plugin downloads.
ModificadaAlta (7.8)0.96%—Japan Pension Service Device Data Encryption ProgramJapan Pension Service Specification Check ProgramJapan Pension Service Todokesho Creation ProgramJapan Pension Service Todokesho Print Program9/6/201717/6/2026
Untrusted search path vulnerability in Installers for Specification check program (social insurance) Ver. 9.00 and earlier, TODOKESHO print program Ver. 5.00 and earlier, Device data encryption program Ver. 1.00 and earlier, and TODOKESHO creation program Ver. 15.00 and earlier available prior to October 17, 2016…
ModificadaMedia (6.1)0.89%—Bestwebsoft CaptchaBestwebsoft CAR RentalBestwebsoft Contact FormBestwebsoft Contact Form Multi+4722/5/201717/6/2026
Cross-site scripting vulnerability in Captcha prior to version 4.3.0, Car Rental prior to version 1.0.5, Contact Form Multi prior to version 1.2.1, Contact Form prior to version 4.0.6, Contact Form to DB prior to version 1.5.7, Custom Admin Page prior to version 0.1.2, Custom Fields Search prior to version 1.3.2,…
ModificadaAlta (8.8)3.1%—Novell Iprint11/3/201716/6/2026
Remote attackers can use the iPrint web-browser ActiveX plugin in Novell iPrint Client before 5.42 for Windows XP/Vista/Win7 to execute code by overflowing the "name" parameter.