Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2980▼ 83 respecto a la semana anterior
Críticas / altas1452▲ 101 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)353▼ 157 respecto a la semana anterior
36 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (6.7) | 0.24% | — | Toshiba PrintersAI | 14/6/2024 | 17/6/2026 | The Toshiba printers do not implement privileges separation. As for the affected products/models/versions, see the reference URL. | |
| Aplazada | Crítica (9.8) | 1.0% | — | Toshiba PrintersAI | 14/6/2024 | 17/6/2026 | The Toshiba printers provide several ways to upload files using the admin web interface. An attacker can remotely compromise any Toshiba printer. An attacker can overwrite any insecure files. This vulnerability can be executed in combination with other vulnerabilities and difficult to execute alone. So, the CVSS score… | |
| Aplazada | Crítica (9.8) | 1.2% | — | Toshiba PrintersAI | 14/6/2024 | 17/6/2026 | The Toshiba printers provide several ways to upload files using the web interface without authentication. An attacker can overwrite any insecure files. And the Toshiba printers are vulnerable to a Local Privilege Escalation vulnerability. An attacker can remotely compromise any Toshiba printer. The programs can be… | |
| Aplazada | Media (5.9) | 0.92% | — | Toshiba PrintersAI | 14/6/2024 | 17/6/2026 | Toshiba printers use XML communication for the API endpoint provided by the printer. For the endpoint, XML parsing library is used and it is vulnerable to a time-based blind XML External Entity (XXE) vulnerability. An attacker can DoS the printers. An attacker can exploit the XXE to retrieve information. As for the… | |
| Aplazada | Alta (7.5) | 0.45% | — | Lenovo PrintersAI | 16/5/2024 | 17/6/2026 | A buffer overflow vulnerability was identified in some Lenovo printers that could allow an unauthenticated user to trigger a device restart by sending a specially crafted web request. | |
| Aplazada | Alta (7.5) | 0.55% | — | Lenovo PrintersAI | 5/4/2024 | 17/6/2026 | A denial of service vulnerability was reported in some Lenovo Printers that could allow an attacker to cause the device to crash by sending crafted LPD packets. | |
| Aplazada | Alta (7.5) | 0.49% | — | Lenovo PrintersAI | 5/4/2024 | 17/6/2026 | A vulnerability was reported in some Lenovo Printers that could allow an unauthenticated attacker to obtain the administrator password. | |
| Aplazada | Media (5.3) | 0.55% | — | Lenovo PrintersAI | 5/4/2024 | 17/6/2026 | A vulnerability was reported in some Lenovo Printers that could allow an unauthenticated attacker to reboot the printer without authentication. | |
| Aplazada | Media (4.9) | 0.52% | — | Lenovo PrintersAI | 5/4/2024 | 17/6/2026 | A denial of service vulnerability was reported in the HTTPS service of some Lenovo Printers that could result in a system reboot. | |
| Modificada | Alta (7.6) | 3.0% | — | HP 8100c Digital SenderHP 9100c Digital SenderHP 9200c Digital SenderHP 9250c Digital Sender+150 | 18/3/2009 | 16/6/2026 | The HP Embedded Web Server (EWS) on HP LaserJet Printers, Edgeline Printers, and Digital Senders has no management password by default, which makes it easier for remote attackers to obtain access. | |
| Modificada | Media (5.1) | 1.1% | — | HP 8100c Digital SenderHP 9100c Digital SenderHP 9200c Digital SenderHP 9250c Digital Sender+150 | 18/3/2009 | 16/6/2026 | Multiple cross-site request forgery (CSRF) vulnerabilities in the HP Embedded Web Server (EWS) on HP LaserJet Printers, Edgeline Printers, and Digital Senders allow remote attackers to hijack the intranet connectivity of arbitrary users for requests that (1) print documents via unknown vectors, (2) modify the network… |