Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas3026▼ 51 respecto a la semana anterior
Críticas / altas1412▲ 58 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)385▼ 125 respecto a la semana anterior
–

89 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaCrítica (9.8)0.71%—Lexmark Cxtpc FirmwareLexmark Cstpc FirmwareLexmark Mxtct FirmwareLexmark Mxtpm Firmware+2210/4/202317/6/2026
Certain Lexmark devices through 2023-02-19 mishandle Input Validation (issue 3 of 4).
ModificadaCrítica (9.8)12%—Lexmark Cxtpc FirmwareLexmark Cstpc FirmwareLexmark Mxtct FirmwareLexmark Mxtpm Firmware+2210/4/202317/6/2026
Certain Lexmark devices through 2023-02-19 mishandle Input Validation (issue 2 of 4).
ModificadaAlta (8.1)38%—Lexmark Cxtpc FirmwareLexmark Cstpc FirmwareLexmark Mxtct FirmwareLexmark Mxtpm Firmware+2210/4/202317/6/2026
Certain Lexmark devices through 2023-02-19 mishandle Input Validation (issue 1 of 4).
ModificadaCrítica (9.8)0.71%—Lexmark Cxtpc FirmwareLexmark Cstpc FirmwareLexmark Mxtct FirmwareLexmark Mxtpm Firmware+2210/4/202317/6/2026
Certain Lexmark devices through 2023-02-19 have Improper Validation of an Array Index.
ModificadaCrítica (9.8)0.71%—Lexmark Cxtpc FirmwareLexmark Cstpc FirmwareLexmark Mxtct FirmwareLexmark Mxtpm Firmware+2210/4/202317/6/2026
Certain Lexmark devices through 2023-02-19 have an Integer Overflow.
ModificadaCrítica (9.8)0.71%—Lexmark Cxtpc FirmwareLexmark Cstpc FirmwareLexmark Mxtct FirmwareLexmark Mxtpm Firmware+2210/4/202317/6/2026
Certain Lexmark devices through 2023-02-19 have an Out-of-bounds Write.
ModificadaCrítica (9.8)0.71%—Lexmark Cxtpc FirmwareLexmark Cstpc FirmwareLexmark Mxtct FirmwareLexmark Mxtpm Firmware+2210/4/202317/6/2026
Certain Lexmark devices through 2023-02-19 access a Resource By Using an Incompatible Type.
ModificadaCrítica (9.8)14%—Lexmark B2236 FirmwareLexmark B2338 FirmwareLexmark B2442 FirmwareLexmark B2546 Firmware+12423/1/202317/6/2026
In certain Lexmark products through 2023-01-12, SSRF can occur because of a lack of input validation.
ModificadaAlta (7.5)28%—Lexmark B2236 FirmwareLexmark B2338 FirmwareLexmark B2442 FirmwareLexmark B2546 Firmware+12423/1/202317/6/2026
Lexmark products through 2023-01-10 have Improper Control of Interaction Frequency.
ModificadaAlta (8.1)1.0%—Lexmark B2236 FirmwareLexmark Mb2236 FirmwareLexmark Ms331 FirmwareLexmark Ms431 Firmware+11326/8/202217/6/2026
Various Lexmark products through 2022-04-27 allow an attacker who has already compromised an affected Lexmark device to maintain persistence across reboots.
ModificadaAlta (7.5)0.76%—Lexmark Firmware28/4/202217/6/2026
Lexmark products through 2022-02-10 have Incorrect Access Control.
ModificadaAlta (8.8)1.4%—Lexmark B2236 FirmwareLexmark Mb2236 FirmwareLexmark Ms431 FirmwareLexmark Ms331 Firmware+23020/1/202217/6/2026
PJL directory traversal vulnerability in Lexmark devices through 2021-12-07 that can be leveraged to overwrite internal configuration files.
ModificadaCrítica (9.8)2.2%—Lexmark Mc3224i Firmware20/1/202217/6/2026
The initial admin account setup wizard on Lexmark devices allow unauthenticated access to the “out of service erase” feature.
ModificadaCrítica (9.8)7.0%—Lexmark B2236 FirmwareLexmark Mb2236 FirmwareLexmark Ms431 FirmwareLexmark Ms331 Firmware+11420/1/202217/6/2026
Embedded web server command injection vulnerability in Lexmark devices through 2021-12-07.
ModificadaCrítica (9.8)6.2%—Lexmark B2236 FirmwareLexmark Mb2236 FirmwareLexmark Ms431 FirmwareLexmark Ms331 Firmware+23020/1/202217/6/2026
Embedded web server input sanitization vulnerability in Lexmark devices through 2021-12-07, which can which can lead to remote code execution on the device.
ModificadaCrítica (9.8)3.3%—Lexmark B2236 FirmwareLexmark Mb2236 FirmwareLexmark Ms431 FirmwareLexmark Ms331 Firmware+23020/1/202217/6/2026
Buffer overflow vulnerability has been identified in Lexmark devices through 2021-12-07 in postscript interpreter.
ModificadaAlta (7.8)1.4%—Lexmark G2 DriverLexmark G3 DriverLexmark G4 DriverLexmark Universal Print Driver19/7/202117/6/2026
The Lexmark Universal Print Driver version 2.15.1.0 and below, G2 driver 2.7.1.0 and below, G3 driver 3.2.0.0 and below, and G4 driver 4.2.1.0 and below are affected by a privilege escalation vulnerability. A standard low priviliged user can use the driver to execute a DLL of their choosing during the add printer…
ModificadaAlta (7.8)0.25%—Lexmark Printer Software G2Lexmark Printer Software G3Lexmark Printer Software G414/7/202117/6/2026
The Lexmark Printer Software G2, G3 and G4 Installation Packages have a local escalation of privilege vulnerability due to a registry entry that has an unquoted service path.
ModificadaMedia (5.4)0.65%—Lexmark Cs31x FirmwareLexmark Cs41x FirmwareLexmark Cs51x FirmwareLexmark Cx310 Firmware+7628/4/202017/6/2026
A cross-site scripting (XSS) vulnerability in Lexmark CS31x before LW74.VYL.P273; CS41x before LW74.VY2.P273; CS51x before LW74.VY4.P273; CX310 before LW74.GM2.P273; CX410 & XC2130 before LW74.GM4.P273; CX510 & XC2132 before LW74.GM7.P273; MS310, MS312, MS317 before LW74.PRL.P273; MS410, M1140 before LW74.PRL.P273;…
ModificadaMedia (5.4)0.66%—Lexmark Cs31x FirmwareLexmark Cs41x FirmwareLexmark Cs51x FirmwareLexmark Cx310 Firmware+7628/4/202017/6/2026
A cross-site scripting (XSS) vulnerability in Lexmark Pro910 series inkjet and other discontinued products.
ModificadaAlta (7.5)1.7%—Lexmark 6500e FirmwareLexmark C748 FirmwareLexmark C79x FirmwareLexmark C925 Firmware+4510/3/202017/6/2026
Certain older Lexmark devices (C, M, X, and 6500e before 2018-12-18) contain a directory traversal vulnerability in the embedded web server.
ModificadaAlta (8.8)3.0%—Lexmark Markvision Enterprise9/3/202017/6/2026
Lexmark Markvision Enterprise before 2.3.0 misuses the Apache Commons Collections Library, leading to remote code execution because of Java deserialization.
ModificadaMedia (5.3)0.87%—Lexmark X860 FirmwareLexmark X862 FirmwareLexmark X864 FirmwareLexmark X734 Firmware+299/3/202016/6/2026
Lexmark X, W, T, E, and C devices before 2012-02-09 allow attackers to obtain sensitive information by reading passwords within exported settings.
ModificadaAlta (7.5)1.1%—Lexmark X950 FirmwareLexmark X952 FirmwareLexmark X954 FirmwareLexmark X940e Firmware+809/3/202016/6/2026
Lexmark X, W, T, E, C, 6500e, and 25xxN devices before 2011-11-15 allow attackers to obtain sensitive information via a hidden email address in a Scan To Email shortcut.
ModificadaCrítica (9.8)1.9%—Lexmark Markvision Enterprise9/3/202017/6/2026
Lexmark Markvision Enterprise (MVE) before 2.4.1 allows remote attackers to execute arbitrary commands by uploading files. (