Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2970▼ 106 respecto a la semana anterior
Críticas / altas1447▲ 86 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
645 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Pendiente de análisis | Alta (7) | 0.32% | — | OctoprintAI | 21/8/2026 | 30/9/2026 | OctoPrint provides a web interface for controlling consumer 3D printers. Prior to 1.11.8 and 2.0.0rc3, OctoPrint's custom Tornado upload handler and Flask with Werkzeug parse request parameters differently, allowing an attacker with FILE_UPLOAD permission to inject reserved internal upload fields through query… | |
| Aplazada | Media (4.6) | 0.20% | — | OctoprintAI | 21/8/2026 | 18/9/2026 | OctoPrint provides a web interface for controlling consumer 3D printers. Prior to 1.11.8 and 2.0.0rc3, Suppressed Command notification popups use PNotify rendering for printer-controlled payload.command and payload.message values in src/octoprint/static/js/app/viewmodels/terminal.js without HTML escaping. An attacker… | |
| Aplazada | Media (6.3) | 0.18% | — | Seiko Epson PrintersAISeiko Epson ScannersAI | 20/8/2026 | 28/8/2026 | Multiple SEIKO EPSON printers and scanners contain revoked root certificates. A man-in-the-middle attack may allow an attacker to obtain communication data transmitted by the product. As for the details of the affected products and versions, refer to the vendor's information. | |
| Aplazada | Media (5.3) | 0.45% | — | Blueprint StudioAIHome-assistant Home AssistantAI | 18/8/2026 | 8/9/2026 | Blueprint Studio is a VS Code-like file editor for Home Assistant configuration files. Prior to 2.5.2, Blueprint Studio backend API handlers in custom_components/blueprint_studio/backend/api.py returned raw exception strings to authenticated Home Assistant users. Some exception messages could contain internal… | |
| Aplazada | Media (5.1) | 0.76% | — | Blueprint StudioAIHome-assistant Home AssistantAI | 18/8/2026 | 8/9/2026 | Blueprint Studio is a VS Code-like file editor for Home Assistant configuration files. Prior to 2.5.2, the legacy stateless terminal command execution path in custom_components/blueprint_studio/backend/terminal_manager.py accepted a cwd working-directory parameter and checked only whether the directory existed,… | |
| Aplazada | Media (5.6) | 0.21% | — | Blueprint StudioAI | 18/8/2026 | 8/9/2026 | Blueprint Studio is a VS Code-like file editor for Home Assistant configuration files. Prior to 2.5.2, Blueprint Studio terminal SSH key authentication in custom_components/blueprint_studio/backend/terminal_manager.py wrote SSH private-key material to a file under the Home Assistant configuration directory before… | |
| Aplazada | Alta (8.6) | 0.50% | — | Blueprint StudioAIHome-assistant Home AssistantAI | 18/8/2026 | 8/9/2026 | Blueprint Studio is a VS Code-like file editor for Home Assistant configuration files. Prior to 2.5.2, Blueprint Studio generated a shell-based Git credential helper in custom_components/blueprint_studio/backend/git_manager.py by interpolating the configured Git username and token directly into executable helper… | |
| Aplazada | Media (6.9) | 0.46% | — | GITAIHome-assistant Blueprint StudioAI | 18/8/2026 | 8/9/2026 | Blueprint Studio is a VS Code-like file editor for Home Assistant configuration files. Prior to 2.5.2, Blueprint Studio configured Git's credential.helper store when saving Git credentials, causing Git credential-store to persist usernames and access tokens in plaintext in the .git-credentials file for the user… | |
| Aplazada | Alta (8.7) | 0.45% | — | Blueprint StudioAIHome-assistant Home AssistantAI | 18/8/2026 | 8/9/2026 | Blueprint Studio is a VS Code-like file editor for Home Assistant configuration files. Prior to 2.5.2, Blueprint Studio exposed administrator-intended backend API actions to any authenticated Home Assistant user because the backend did not consistently enforce the panel's admin-only authorization boundary. Affected… | |
| Aplazada | Media (6.5) | 0.37% | — | Tinycss2AIKozea WeasyprintAI | 18/8/2026 | 18/9/2026 | WeasyPrint helps web developers to create PDF documents. Prior to 69.0, WeasyPrint embeds unescaped HTML presentational-hint attribute values into CSS in weasyprint/css/__init__.py when presentational_hints=True. The background attribute is inserted into a background-image:url() declaration and parsed by… | |
| Aplazada | Alta (8.4) | 0.26% | — | Amazing-print Amazing PrintAI | 13/8/2026 | 8/9/2026 | amazing-print/amazing_print at commit dc890dfafdf07088ea901df53c19c2710e5c5234 contains a Ruby code injection condition in AwesomeMethodArray#grep. A specially named method containing Ruby interpolation syntax can be interpolated into a dynamically constructed eval string when grep is called with a block, resulting in… | |
| Pendiente de análisis | Media (5.3) | 0.47% | — | SapsprintAI | 11/8/2026 | 26/8/2026 | SAP SAPSPrint Service has memory corruption vulnerabilities in the handling of certain commands. An unauthenticated attacker could send specially crafted requests that trigger a buffer overflow in the affected component. This causes a temporary service interruption and automatic restart, resulting in low impact on… | |
| Aplazada | Alta (8.8) | 0.41% | — | Cti-transmuteAIKozea WeasyprintAI | 3/8/2026 | 26/8/2026 | CTI-Transmute is affected by a server-side request forgery vulnerability in the evaluation report PDF-generation functionality. User-controlled CTI content, including conversion names, descriptions, and comments, is converted from Markdown to HTML and rendered as a PDF using WeasyPrint. Before the patch, the renderer… | |
| Aplazada | Alta (8.6) | 0.44% | — | Printcart WEB TO Print Product DesignerAI | 27/7/2026 | 29/9/2026 | The Printcart Web to Print Product Designer for WooCommerce WordPress plugin before 2.5.3 does not restrict a user-supplied URL before fetching it server-side and does not enforce a valid authorization check, allowing unauthenticated attackers to read arbitrary local files (including configuration files containing… | |
| Pendiente de análisis | Alta (7.5) | 0.63% | — | Openprinting LibcupsfiltersAI | 23/7/2026 | 19/8/2026 | A flaw was found in libcupsfilters. The cfIEEE1284NormalizeMakeModel() function enters an infinite loop when processing a printer-advertised IEEE-1284 device ID with an empty model field, causing sustained CPU consumption. A network-adjacent attacker could exploit this by broadcasting a specially crafted printer… | |
| Aplazada | Media (6.9) | 0.38% | — | Ricoh PrintersAIRicoh Multifunction PrintersAI | 23/7/2026 | 23/7/2026 | Printers and Multifunction Printers (MFPs) provided by Ricoh Company, Ltd. do not implement restrictions on SSH port forwarding, allowing to connect to arbitrary destinations. When SSH is enabled on an affected product, SSH port forwarding may be leveraged to connect to other node on the LAN. | |
| Aplazada | Media (4.4) | 0.34% | — | Print PDF Email BY PrintfriendlyAI | 11/7/2026 | 13/7/2026 | The Print, PDF, Email by PrintFriendly plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'content_position_css' parameter in all versions up to, and including, 5.5.10 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with… | |
| Aplazada | Crítica (9.1) | 1.2% | — | Printcart WEB TO Print Product DesignerAI | 3/7/2026 | 7/7/2026 | The Printcart Web to Print Product Designer for WooCommerce plugin for WordPress is vulnerable to Arbitrary File Deletion in versions up to, and including, 2.5.2 This is due to insufficient path validation in the store_design_data() function, which constructs a filesystem path from the user-supplied 'nbd_item_key'… | |
| Aplazada | Alta (7.5) | 0.61% | — | Webandprint ARAI | 3/7/2026 | 6/7/2026 | The AR for WordPress plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 8.40 via the 'file' parameter parameter. This makes it possible for unauthenticated attackers to read the contents of arbitrary files on the server, which can contain sensitive information. Exploitation… | |
| Aplazada | Alta (7.5) | 0.42% | — | Wpfactory Print Invoice AND Delivery Notes FOR WoocommerceAI | 26/6/2026 | 26/6/2026 | Unauthenticated Sensitive Data Exposure in Print Invoice & Delivery Notes for WooCommerce <= 7.1.1 versions. | |
| Aplazada | Media (5.3) | 0.39% | — | Printcart WEB TO Print Product DesignerAI | 26/6/2026 | 6/10/2026 | The Printcart Web to Print Product Designer for WooCommerce WordPress plugin through 2.4.8 is vulnerable to path traversal which makes it possible for the attacker to retrieve the directory listing for arbitrary directories on the server. | |
| Aplazada | Alta (7.3) | 0.18% | — | Papercut Print Deploy ClientAI | 22/6/2026 | 23/6/2026 | An insecure process execution vulnerability exists in the pc-printer-updater.exe component of the PaperCut Print Deploy Client for Windows. The application, which typically operates with high-level system privileges, attempts to perform an internal validation check by invoking a secondary system utility using an… | |
| Aplazada | Media (6.5) | 0.42% | — | Pontedilana Php-weasyprintAI | 19/6/2026 | 23/6/2026 | PhpWeasyPrint is a PHP library allowing PDF generation from a URL or an HTML page. Prior to version 2.6.0, `pontedilana/php-weasyprint` fetches the content of option values server-side via `file_get_contents()` when the value looks like a URL, without restricting the URL scheme. The `attachment` option of `Pdf` is the… | |
| Aplazada | Alta (8.1) | 0.95% | — | Pontedilana Php-weasyprintAIKnplabs SnappyAI | 19/6/2026 | 22/6/2026 | PhpWeasyPrint is a PHP library allowing PDF generation from a URL or an HTML page. Prior to version 2.6.0, `pontedilana/php-weasyprint` guarded the output filename against the `phar://` stream wrapper with a case-sensitive blacklist. PHP stream wrappers are case-insensitive, so `PHAR://`, `Phar://`, etc. bypass the… | |
| Aplazada | Alta (8.2) | 0.22% | — | Pontedilana Php-weasyprintAIKnplabs SnappyAISymfony ProcessAI | 19/6/2026 | 22/6/2026 | PhpWeasyPrint is a PHP library allowing PDF generation from a URL or an HTML page. Prior to version 2.5.1, `pontedilana/php-weasyprint` builds the shell command for WeasyPrint by passing the binary path through `escapeshellarg()` first and then checking the *quoted* result with `is_executable()`. On POSIX… |