Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3026▼ 51 respecto a la semana anterior
Críticas / altas1412▲ 58 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)385▼ 125 respecto a la semana anterior
89 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Crítica (9.8) | 0.71% | — | Lexmark Cxtpc FirmwareLexmark Cstpc FirmwareLexmark Mxtct FirmwareLexmark Mxtpm Firmware+22 | 10/4/2023 | 17/6/2026 | Certain Lexmark devices through 2023-02-19 mishandle Input Validation (issue 3 of 4). | |
| Modificada | Crítica (9.8) | 12% | — | Lexmark Cxtpc FirmwareLexmark Cstpc FirmwareLexmark Mxtct FirmwareLexmark Mxtpm Firmware+22 | 10/4/2023 | 17/6/2026 | Certain Lexmark devices through 2023-02-19 mishandle Input Validation (issue 2 of 4). | |
| Modificada | Alta (8.1) | 38% | — | Lexmark Cxtpc FirmwareLexmark Cstpc FirmwareLexmark Mxtct FirmwareLexmark Mxtpm Firmware+22 | 10/4/2023 | 17/6/2026 | Certain Lexmark devices through 2023-02-19 mishandle Input Validation (issue 1 of 4). | |
| Modificada | Crítica (9.8) | 0.71% | — | Lexmark Cxtpc FirmwareLexmark Cstpc FirmwareLexmark Mxtct FirmwareLexmark Mxtpm Firmware+22 | 10/4/2023 | 17/6/2026 | Certain Lexmark devices through 2023-02-19 have Improper Validation of an Array Index. | |
| Modificada | Crítica (9.8) | 0.71% | — | Lexmark Cxtpc FirmwareLexmark Cstpc FirmwareLexmark Mxtct FirmwareLexmark Mxtpm Firmware+22 | 10/4/2023 | 17/6/2026 | Certain Lexmark devices through 2023-02-19 have an Integer Overflow. | |
| Modificada | Crítica (9.8) | 0.71% | — | Lexmark Cxtpc FirmwareLexmark Cstpc FirmwareLexmark Mxtct FirmwareLexmark Mxtpm Firmware+22 | 10/4/2023 | 17/6/2026 | Certain Lexmark devices through 2023-02-19 have an Out-of-bounds Write. | |
| Modificada | Crítica (9.8) | 0.71% | — | Lexmark Cxtpc FirmwareLexmark Cstpc FirmwareLexmark Mxtct FirmwareLexmark Mxtpm Firmware+22 | 10/4/2023 | 17/6/2026 | Certain Lexmark devices through 2023-02-19 access a Resource By Using an Incompatible Type. | |
| Modificada | Crítica (9.8) | 14% | — | Lexmark B2236 FirmwareLexmark B2338 FirmwareLexmark B2442 FirmwareLexmark B2546 Firmware+124 | 23/1/2023 | 17/6/2026 | In certain Lexmark products through 2023-01-12, SSRF can occur because of a lack of input validation. | |
| Modificada | Alta (7.5) | 28% | — | Lexmark B2236 FirmwareLexmark B2338 FirmwareLexmark B2442 FirmwareLexmark B2546 Firmware+124 | 23/1/2023 | 17/6/2026 | Lexmark products through 2023-01-10 have Improper Control of Interaction Frequency. | |
| Modificada | Alta (8.1) | 1.0% | — | Lexmark B2236 FirmwareLexmark Mb2236 FirmwareLexmark Ms331 FirmwareLexmark Ms431 Firmware+113 | 26/8/2022 | 17/6/2026 | Various Lexmark products through 2022-04-27 allow an attacker who has already compromised an affected Lexmark device to maintain persistence across reboots. | |
| Modificada | Alta (7.5) | 0.76% | — | Lexmark Firmware | 28/4/2022 | 17/6/2026 | Lexmark products through 2022-02-10 have Incorrect Access Control. | |
| Modificada | Alta (8.8) | 1.4% | — | Lexmark B2236 FirmwareLexmark Mb2236 FirmwareLexmark Ms431 FirmwareLexmark Ms331 Firmware+230 | 20/1/2022 | 17/6/2026 | PJL directory traversal vulnerability in Lexmark devices through 2021-12-07 that can be leveraged to overwrite internal configuration files. | |
| Modificada | Crítica (9.8) | 2.2% | — | Lexmark Mc3224i Firmware | 20/1/2022 | 17/6/2026 | The initial admin account setup wizard on Lexmark devices allow unauthenticated access to the “out of service erase” feature. | |
| Modificada | Crítica (9.8) | 7.0% | — | Lexmark B2236 FirmwareLexmark Mb2236 FirmwareLexmark Ms431 FirmwareLexmark Ms331 Firmware+114 | 20/1/2022 | 17/6/2026 | Embedded web server command injection vulnerability in Lexmark devices through 2021-12-07. | |
| Modificada | Crítica (9.8) | 6.2% | — | Lexmark B2236 FirmwareLexmark Mb2236 FirmwareLexmark Ms431 FirmwareLexmark Ms331 Firmware+230 | 20/1/2022 | 17/6/2026 | Embedded web server input sanitization vulnerability in Lexmark devices through 2021-12-07, which can which can lead to remote code execution on the device. | |
| Modificada | Crítica (9.8) | 3.3% | — | Lexmark B2236 FirmwareLexmark Mb2236 FirmwareLexmark Ms431 FirmwareLexmark Ms331 Firmware+230 | 20/1/2022 | 17/6/2026 | Buffer overflow vulnerability has been identified in Lexmark devices through 2021-12-07 in postscript interpreter. | |
| Modificada | Alta (7.8) | 1.4% | — | Lexmark G2 DriverLexmark G3 DriverLexmark G4 DriverLexmark Universal Print Driver | 19/7/2021 | 17/6/2026 | The Lexmark Universal Print Driver version 2.15.1.0 and below, G2 driver 2.7.1.0 and below, G3 driver 3.2.0.0 and below, and G4 driver 4.2.1.0 and below are affected by a privilege escalation vulnerability. A standard low priviliged user can use the driver to execute a DLL of their choosing during the add printer… | |
| Modificada | Alta (7.8) | 0.25% | — | Lexmark Printer Software G2Lexmark Printer Software G3Lexmark Printer Software G4 | 14/7/2021 | 17/6/2026 | The Lexmark Printer Software G2, G3 and G4 Installation Packages have a local escalation of privilege vulnerability due to a registry entry that has an unquoted service path. | |
| Modificada | Media (5.4) | 0.65% | — | Lexmark Cs31x FirmwareLexmark Cs41x FirmwareLexmark Cs51x FirmwareLexmark Cx310 Firmware+76 | 28/4/2020 | 17/6/2026 | A cross-site scripting (XSS) vulnerability in Lexmark CS31x before LW74.VYL.P273; CS41x before LW74.VY2.P273; CS51x before LW74.VY4.P273; CX310 before LW74.GM2.P273; CX410 & XC2130 before LW74.GM4.P273; CX510 & XC2132 before LW74.GM7.P273; MS310, MS312, MS317 before LW74.PRL.P273; MS410, M1140 before LW74.PRL.P273;… | |
| Modificada | Media (5.4) | 0.66% | — | Lexmark Cs31x FirmwareLexmark Cs41x FirmwareLexmark Cs51x FirmwareLexmark Cx310 Firmware+76 | 28/4/2020 | 17/6/2026 | A cross-site scripting (XSS) vulnerability in Lexmark Pro910 series inkjet and other discontinued products. | |
| Modificada | Alta (7.5) | 1.7% | — | Lexmark 6500e FirmwareLexmark C748 FirmwareLexmark C79x FirmwareLexmark C925 Firmware+45 | 10/3/2020 | 17/6/2026 | Certain older Lexmark devices (C, M, X, and 6500e before 2018-12-18) contain a directory traversal vulnerability in the embedded web server. | |
| Modificada | Alta (8.8) | 3.0% | — | Lexmark Markvision Enterprise | 9/3/2020 | 17/6/2026 | Lexmark Markvision Enterprise before 2.3.0 misuses the Apache Commons Collections Library, leading to remote code execution because of Java deserialization. | |
| Modificada | Media (5.3) | 0.87% | — | Lexmark X860 FirmwareLexmark X862 FirmwareLexmark X864 FirmwareLexmark X734 Firmware+29 | 9/3/2020 | 16/6/2026 | Lexmark X, W, T, E, and C devices before 2012-02-09 allow attackers to obtain sensitive information by reading passwords within exported settings. | |
| Modificada | Alta (7.5) | 1.1% | — | Lexmark X950 FirmwareLexmark X952 FirmwareLexmark X954 FirmwareLexmark X940e Firmware+80 | 9/3/2020 | 16/6/2026 | Lexmark X, W, T, E, C, 6500e, and 25xxN devices before 2011-11-15 allow attackers to obtain sensitive information via a hidden email address in a Scan To Email shortcut. | |
| Modificada | Crítica (9.8) | 1.9% | — | Lexmark Markvision Enterprise | 9/3/2020 | 17/6/2026 | Lexmark Markvision Enterprise (MVE) before 2.4.1 allows remote attackers to execute arbitrary commands by uploading files. ( |