Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2659▼ 692 respecto a la semana anterior
Críticas / altas1261▼ 300 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)250▼ 252 respecto a la semana anterior
645 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.7) | 1.5% | — | Printeron | 23/4/2019 | 17/6/2026 | An XML external entity (XXE) vulnerability in PrinterOn version 4.1.4 and lower allows remote authenticated users to read arbitrary files or conduct server-side request forgery (SSRF) attacks via a crafted DTD in an XML request. | |
| Modificada | Media (6.5) | 0.53% | — | Printeron | 18/4/2019 | 17/6/2026 | PrinterOn Enterprise 4.1.4 contains multiple Cross Site Request Forgery (CSRF) vulnerabilities in the Administration page. For example, an administrator, by following a link, can be tricked into making unwanted changes to a printer (Disable, Approve, etc). | |
| Modificada | Media (5.4) | 0.63% | — | Printeron | 21/3/2019 | 17/6/2026 | PrinterOn Enterprise 4.1.4 suffers from multiple authenticated stored XSS vulnerabilities via the (1) "Machine Host Name" or "Server Serial Number" field in the clustering configuration, (2) "name" field in the Edit Group configuration, (3) "Rule Name" field in the Access Control configuration, (4) "Service Name" in… | |
| Modificada | Alta (8.1) | 1.0% | — | Opensuse Yast2-printer | 15/3/2019 | 17/6/2026 | In yast2-printer up to and including version 4.0.2 the SMB printer settings don't escape characters in passwords properly. If a password with backticks or simliar characters is supplied this allows for executing code as root. This requires tricking root to enter such a password in yast. | |
| Modificada | Media (6.5) | 1.1% | — | Printeron | 17/12/2018 | 17/6/2026 | PrinterOn Enterprise 4.1.4 allows Arbitrary File Deletion. | |
| Modificada | Crítica (9.8) | 21% | — | Ricoh Myprint | 14/12/2018 | 17/6/2026 | Hardcoded credentials in the Ricoh myPrint application 2.9.2.4 for Windows and 2.2.7 for Android give access to any externally disclosed myPrint WSDL API, as demonstrated by discovering API secrets of related Google cloud printers, encrypted passwords of mail servers, and names of printed files. | |
| Modificada | Crítica (9.1) | 2.1% | — | Octoprint | 7/9/2018 | 17/6/2026 | OctoPrint through 1.3.9 allows remote attackers to obtain sensitive information or cause a denial of service via HTTP requests on port 8081. NOTE: the vendor disputes the significance of this report because their documentation states that with "blind port forwarding ... Putting OctoPrint onto the public internet is a… | |
| Modificada | Alta (7.5) | 1.2% | — | Epson Iprint | 30/8/2018 | 17/6/2026 | The ContentProvider in the EPSON iPrint application 6.6.3 for Android does not properly restrict data access. This allows an attacker's application to read scanned documents. | |
| Modificada | Alta (7.5) | 1.1% | — | Epson Iprint | 30/8/2018 | 17/6/2026 | The EPSON iPrint application 6.6.3 for Android contains hard-coded API and Secret keys for the Dropbox, Box, Evernote and OneDrive services. | |
| Modificada | Alta (8.8) | 1.1% | — | Dell 2335dn Engine FirmwareDell 2335dn Network FirmwareDell 2335dn Printer Firmware | 23/8/2018 | 17/6/2026 | On Dell 2335dn printers with Printer Firmware Version 2.70.05.02, Engine Firmware Version 1.10.65, and Network Firmware Version V4.02.15(2335dn MFP) 11-22-2010, the admin interface allows an authenticated attacker to retrieve the configured SMTP or LDAP password by viewing the HTML source code of the Email Settings… | |
| Modificada | Media (6.1) | 2.5% | 💥 Exploit | Canon EFI Printme | 11/6/2018 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in the Canon PrintMe EFI webinterface allows remote attackers to inject arbitrary web script or HTML via the PATH_INFO to the /wt3/mydocs.php URI. | |
| Modificada | Alta (7) | 0.26% | — | Printeron | 17/5/2018 | 17/6/2026 | PrinterOn Enterprise 4.1.3 stores the Active Directory bind credentials using base64 encoding, which allows local users to obtain credentials for a domain user by reading the cps_config.xml file. | |
| Modificada | Media (5.4) | 0.55% | — | Printeron | 17/5/2018 | 17/6/2026 | PrinterOn Enterprise 4.1.3 suffers from multiple authenticated stored XSS vulnerabilities via the (1) department field in the printer configuration, (2) description field in the print server configuration, and (3) username field for authentication to print as guest. | |
| Modificada | Media (6.8) | 0.50% | — | Meco USB Memory Stick With Fingerprint Firwmare | 22/3/2018 | 17/6/2026 | An issue was discovered on MECO USB Memory Stick with Fingerprint MECOZiolsamDE601 devices. The fingerprint authentication requirement for data access can be bypassed. An attacker with physical access can send a static packet to a serial port exposed on the PCB to unlock the key and get access to the data without… | |
| Modificada | Alta (7.5) | 1.9% | — | Sblim Project Small Footprint CIM Broker | 8/2/2018 | 17/6/2026 | SBLIM Small Footprint CIM Broker (SFCB) 1.4.9 has a null pointer (DoS) vulnerability via a crafted POST request to the /cimom URI. | |
| Modificada | Media (6.1) | 37% | — | Epson Airprint | 8/2/2018 | 17/6/2026 | Versions of Epson AirPrint released prior to January 19, 2018 contain a reflective cross-site scripting (XSS) vulnerability, which can allow untrusted users on the network to hijack a session cookie or perform other reflected XSS attacks on a currently logged-on user. | |
| Modificada | Alta (7.8) | 0.40% | — | Lenovo Fingerprint Manager PRO | 26/1/2018 | 17/6/2026 | Sensitive data stored by Lenovo Fingerprint Manager Pro, version 8.01.86 and earlier, including users' Windows logon credentials and fingerprint data, is encrypted using a weak algorithm, contains a hard-coded password, and is accessible to all users with local non-administrative access to the system in which it is… | |
| Modificada | Crítica (9.8) | 3.8% | — | Node-printer Project Node-printer | 23/10/2017 | 17/6/2026 | The printDirect function in lib/printer.js in the node-printer module 0.0.1 and earlier for Node.js allows remote attackers to execute arbitrary commands via unspecified characters in the lpr command. | |
| Modificada | Media (6.7) | 0.34% | — | Lenovo Fingerprint Manager | 3/10/2017 | 17/6/2026 | Services and files in Lenovo Fingerprint Manager before 8.01.42 have incorrect ACLs, which allows local users to invalidate local checks and gain privileges via standard filesystem operations. | |
| Modificada | Alta (7.8) | 19% | 💥 Exploit | Cyberlink Labelprint | 23/9/2017 | 17/6/2026 | Stack-based buffer overflows in CyberLink LabelPrint 2.5 allow remote attackers to execute arbitrary code via the (1) author (inside the INFORMATION tag), (2) name (inside the INFORMATION tag), (3) artist (inside the TRACK tag), or (4) default (inside the TEXT tag) parameter in an lpp project file. | |
| Modificada | Media (6.1) | 0.79% | — | BMC Footprints Service Core | 28/8/2017 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in BMC Footprints Service Core 11.5. | |
| Modificada | Alta (8.1) | 6.3% | — | HP Linux Imaging AND Printing | 2/8/2017 | 17/6/2026 | The hp-plugin utility in HP Linux Imaging and Printing (HPLIP) makes it easier for man-in-the-middle attackers to execute arbitrary code by leveraging use of a short GPG key id from a keyserver to verify print plugin downloads. | |
| Modificada | Alta (7.8) | 0.96% | — | Japan Pension Service Device Data Encryption ProgramJapan Pension Service Specification Check ProgramJapan Pension Service Todokesho Creation ProgramJapan Pension Service Todokesho Print Program | 9/6/2017 | 17/6/2026 | Untrusted search path vulnerability in Installers for Specification check program (social insurance) Ver. 9.00 and earlier, TODOKESHO print program Ver. 5.00 and earlier, Device data encryption program Ver. 1.00 and earlier, and TODOKESHO creation program Ver. 15.00 and earlier available prior to October 17, 2016… | |
| Modificada | Media (6.1) | 0.89% | — | Bestwebsoft CaptchaBestwebsoft CAR RentalBestwebsoft Contact FormBestwebsoft Contact Form Multi+47 | 22/5/2017 | 17/6/2026 | Cross-site scripting vulnerability in Captcha prior to version 4.3.0, Car Rental prior to version 1.0.5, Contact Form Multi prior to version 1.2.1, Contact Form prior to version 4.0.6, Contact Form to DB prior to version 1.5.7, Custom Admin Page prior to version 0.1.2, Custom Fields Search prior to version 1.3.2,… | |
| Modificada | Alta (8.8) | 3.1% | — | Novell Iprint | 11/3/2017 | 16/6/2026 | Remote attackers can use the iPrint web-browser ActiveX plugin in Novell iPrint Client before 5.42 for Windows XP/Vista/Win7 to execute code by overflowing the "name" parameter. |