Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2862▼ 326 respecto a la semana anterior
Críticas / altas1389▼ 28 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)293▼ 216 respecto a la semana anterior
–

144 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (4.8)0.59%—Xerox Xmpie Ustore10/2/20229/7/2026
A persistent cross-site scripting (XSS) vulnerability exists on two input fields within the administrative panel when editing users in the XMPie UStore application on version 12.3.7244.0.
ModificadaAlta (7.5)1.6%—Xerox Xmpie Ustore7/2/20229/7/2026
XMPie uStore 12.3.7244.0 allows for administrators to generate reports based on raw SQL queries. Since the application ships with default administrative credentials, an attacker may authenticate into the application and exfiltrate sensitive information from the database.
ModificadaAlta (7.5)1.9%—Xerox Versalink Firmware26/1/202217/6/2026
Xerox VersaLink devices on specific versions of firmware before 2022-01-26 allow remote attackers to brick the device via a crafted TIFF file in an unauthenticated HTTP POST request. There is a permanent denial of service because image parsing causes a reboot, but image parsing is restarted as soon as the boot process…
ModificadaCrítica (9.8)3.1%—Xerosecurity Sn1per19/8/202117/6/2026
In XeroSecurity Sn1per 9.0 (free version), insecure directory permissions (0777) are set during installation, allowing an unprivileged user to modify the main application and the application configuration file. This results in arbitrary code execution with root privileges.
ModificadaAlta (8.8)2.7%💥 PoCXerosecurity Sn1per19/8/202117/6/2026
In XeroSecurity Sn1per 9.0 (free version), insecure permissions (0777) are set upon application execution, allowing an unprivileged user to modify the application, modules, and configuration files. This leads to arbitrary code execution with root privileges.
ModificadaCrítica (9.8)0.99%—Xerox Altalink B8045 FirmwareXerox Altalink B8055 FirmwareXerox Altalink B8065 FirmwareXerox Altalink B8075 Firmware+613/4/202117/6/2026
Xerox AltaLink B8045/B8055/B8065/B8075/B8090, AltaLink C8030/C8035/C8045/C8055/C8070 with software releases before 103.xxx.030.32000 includes two accounts with weak hard-coded passwords which can be exploited and allow unauthorized access which cannot be disabled.
ModificadaCrítica (9.8)2.2%—Xerox Phaser 6510 FirmwareXerox Workcentre 6515 FirmwareXerox Versalink B400 FirmwareXerox Versalink B405 Firmware+2029/3/202117/6/2026
Xerox Phaser 6510 before 64.65.51 and 64.59.11 (Bridge), WorkCentre 6515 before 65.65.51 and 65.59.11 (Bridge), VersaLink B400 before 37.65.51 and 37.59.01 (Bridge), B405 before 38.65.51 and 38.59.01 (Bridge), B600/B610 before 32.65.51 and 32.59.01 (Bridge), B605/B615 before 33.65.51 and 33.59.01 (Bridge), B7025/30/35…
ModificadaCrítica (9.8)2.6%—Xerox Phaser 6510 FirmwareXerox Workcentre 6515 FirmwareXerox Versalink B400 FirmwareXerox Versalink B405 Firmware+2029/3/202117/6/2026
Xerox Phaser 6510 before 64.65.51 and 64.59.11 (Bridge), WorkCentre 6515 before 65.65.51 and 65.59.11 (Bridge), VersaLink B400 before 37.65.51 and 37.59.01 (Bridge), B405 before 38.65.51 and 38.59.01 (Bridge), B600/B610 before 32.65.51 and 32.59.01 (Bridge), B605/B615 before 33.65.51 and 33.59.01 (Bridge), B7025/30/35…
ModificadaCrítica (9.8)1.9%—Xerox Phaser 6510 FirmwareXerox Workcentre 6515 FirmwareXerox Versalink B400 FirmwareXerox Versalink B405 Firmware+1929/3/202117/6/2026
Xerox Phaser 6510 before 64.61.23 and 64.59.11 (Bridge), WorkCentre 6515 before 65.61.23 and 65.59.11 (Bridge), VersaLink B400 before 37.61.23 and 37.59.01 (Bridge), B405 before 38.61.23 and 38.59.01 (Bridge), B600/B610 before 32.61.23 and 32.59.01 (Bridge), B605/B615 before 33.61.23 and 33.59.01 (Bridge), B7025/30/35…
ModificadaAlta (7.5)0.79%—Xerox Altalink B8045 FirmwareXerox Altalink B8055 FirmwareXerox Altalink B8065 FirmwareXerox Altalink B8075 Firmware+629/3/202117/6/2026
Xerox AltaLink B80xx before 103.008.020.23120, C8030/C8035 before 103.001.020.23120, C8045/C8055 before 103.002.020.23120 and C8070 before 103.003.020.23120 provide the ability to set configuration attributes without administrative rights.
ModificadaCrítica (9.8)0.97%—Xerox Altalink B8045 FirmwareXerox Altalink B8055 FirmwareXerox Altalink B8065 FirmwareXerox Altalink B8075 Firmware+629/3/202117/6/2026
Xerox AltaLink B80xx before 103.008.020.23120, C8030/C8035 before 103.001.020.23120, C8045/C8055 before 103.002.020.23120 and C8070 before 103.003.020.23120 has several SQL injection vulnerabilities.
ModificadaCrítica (9.1)0.97%—Xerox Altalink B8045 FirmwareXerox Altalink B8055 FirmwareXerox Altalink B8065 FirmwareXerox Altalink B8075 Firmware+629/3/202117/6/2026
Xerox AltaLink B8045/B8090 before 103.008.030.32000, C8030/C8035 before 103.001.030.32000, C8045/C8055 before 103.002.030.32000 and C8070 before 103.003.030.32000 allow unauthorized users, by leveraging the Scan To Mailbox feature, to delete arbitrary files from the disk.
ModificadaAlta (7.5)1.5%—Fujixerox Docucentre-vii C7773 FirmwareFujixerox Docucentre-vii C6673 FirmwareFujixerox Docucentre-vii C5573 FirmwareFujixerox Docucentre-vii C4473 Firmware+7125/3/202117/6/2026
Fuji Xerox multifunction devices and printers (DocuCentre-VII C7773/C6673/C5573/C4473/C3373/C3372/C2273, DocuCentre-VII C7788/C6688/C5588, ApeosPort-VII C7773/C6673/C5573/C4473/C3373/C3372 C2273, ApeosPort-VII C7788/C6688/C5588, ApeosPort C7070/C6570/C5570/C4570/C3570/C3070/C7070G/C6570G/C5570G/C4570G/C3570G/C3070G,…
ModificadaAlta (7.5)0.70%—Xerox Altalink B8045 FirmwareXerox Altalink B8055 FirmwareXerox Altalink B8065 FirmwareXerox Altalink B8075 Firmware+64/3/202117/6/2026
On Xerox AltaLink B8045/B8055/B8065/B8075/B8090 and C8030/C8035/C8045/C8055/C8070 multifunction printers with software releases before 101.00x.099.28200, portions of the drive containing executable code were not encrypted thus leaving it open to potential cryptographic information disclosure.
ModificadaAlta (8.1)1.1%—Xerox Altalink B8045 FirmwareXerox Altalink B8055 FirmwareXerox Altalink B8065 FirmwareXerox Altalink B8075 Firmware+64/3/202117/6/2026
Xerox AltaLink B8045/B8055/B8065/B8075/B8090 and C8030/C8035/C8045/C8055/C8070 multifunction printers with software releases before 101.00x.099.28200 allow an attacker to execute an unwanted binary during a exploited clone install. This requires creating a clone file and signing that file with a compromised private…
ModificadaMedia (4.9)0.66%—Xerox Altalink B8045 FirmwareXerox Altalink B8055 FirmwareXerox Altalink B8065 FirmwareXerox Altalink B8075 Firmware+64/3/202117/6/2026
Xerox AltaLink B8045/B8055/B8065/B8075/B8090 and C8030/C8035/C8045/C8055/C8070 multifunction printers with software releases before 101.00x.099.28200 allow a user with administrative privileges to turn off data encryption on the device, thus leaving it open to potential cryptographic information disclosure.
ModificadaAlta (7.5)0.80%—Xerox Workcentre 3655 FirmwareXerox Workcentre 3655i FirmwareXerox Workcentre 5865 FirmwareXerox Workcentre 5875 Firmware+2626/1/202117/6/2026
An issue was discovered in certain Xerox WorkCentre products. They do not properly encrypt passwords. This affects 3655, 3655i, 58XX, 58XXi 59XX, 59XXi, 6655, 6655i, 72XX, 72XXi 78XX, 78XXi, 7970, 7970i, EC7836, and EC7856 devices.
ModificadaMedia (6.1)0.65%—Xerox Workcentre Ec7836 FirmwareXerox Workcentre Ec7856 Firmware9/10/202017/6/2026
Xerox WorkCentre EC7836 before 073.050.059.25300 and EC7856 before 073.020.059.25300 devices allow XSS via Description pages.
ModificadaCrítica (9.8)2.0%—Xerox Workcentre 3655 FirmwareXerox Workcentre 3655i FirmwareXerox Workcentre 5865 FirmwareXerox Workcentre 5875 Firmware+2129/4/202017/6/2026
Xerox WorkCentre 3655, 3655i, 58XX, 58XXi, 59XX, 59XXi, 6655, 6655i, 72XX, 72XXi, 78XX, 78XXi, 7970, and 7970i devices before 073.xxx.086.15410 do not properly escape parameters in the support/remoteUI/configrui.php script, which can allow an unauthenticated attacker to execute OS commands on the device.
ModificadaCrítica (9.8)3.0%—Xerox Phaser 3320 Firmware13/3/202017/6/2026
Some Xerox printers (such as the Phaser 3320 V53.006.16.000) were affected by a buffer overflow vulnerability in the Authentication Cookie of the web application that would allow an attacker to execute arbitrary code on the device.
ModificadaCrítica (9.8)2.8%—Xerox Phaser 3320 Firmware13/3/202017/6/2026
Some Xerox printers (such as the Phaser 3320 V53.006.16.000) were affected by one or more stack-based buffer overflow vulnerabilities in the Google Cloud Print implementation that would allow an unauthenticated attacker to execute arbitrary code on the device. This was caused by an insecure handling of the register…
ModificadaMedia (6.5)0.41%—Xerox Phaser 3320 Firmware13/3/202017/6/2026
Some Xerox printers (such as the Phaser 3320 V53.006.16.000) did not implement any mechanism to avoid CSRF attacks. Successful exploitation of this vulnerability can lead to the takeover of a local account on the device.
ModificadaCrítica (9.8)2.7%—Xerox Phaser 3320 Firmware13/3/202017/6/2026
Some Xerox printers (such as the Phaser 3320 V53.006.16.000) were affected by a buffer overflow vulnerability in the Content-Type HTTP Header of the web application that would allow an attacker to execute arbitrary code on the device.
ModificadaCrítica (9.8)2.8%—Xerox Phaser 3320 Firmware13/3/202017/6/2026
Some Xerox printers (such as the Phaser 3320 V53.006.16.000) were affected by a buffer overflow vulnerability in the attributes parser of the IPP service. This would allow an unauthenticated attacker to cause a Denial of Service (DoS) and potentially execute arbitrary code on the device.
ModificadaMedia (6.1)1.0%—Xerox Phaser 3320 Firmware13/3/202017/6/2026
Multiple Stored XSS vulnerabilities were found in the Xerox Web Application, used by the Phaser 3320 V53.006.16.000 and other printers. Successful exploitation of this vulnerability can lead to session hijacking of the administrator in the web application or the execution of unwanted actions.
Orbitaley — Vulnerabilidades