Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2680▼ 660 respecto a la semana anterior
Críticas / altas1277▼ 279 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)228▼ 274 respecto a la semana anterior
645 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Crítica (9.8) | 2.5% | — | Lantronix Xprintserver Firmware | 14/5/2016 | 17/6/2026 | Lantronix xPrintServer devices with firmware before 5.0.1-65 have hardcoded credentials, which allows remote attackers to obtain root access via unspecified vectors. | |
| Modificada | Media (4.6) | 0.35% | — | Lexmark Printer Firmware | 22/4/2016 | 17/6/2026 | Lexmark printers with firmware ATL before ATL.021.063, CB before CB.021.063, PP before PP.021.063, and YK before YK.021.063 mishandle Erase Printer Memory and Erase Hard Disk actions, which allows physically proximate attackers to obtain sensitive information via direct read operations on non-volatile memory. | |
| Modificada | Alta (7.8) | 0.32% | — | Lenovo Fingerprint ManagerLenovo Touch Fingerprint | 11/4/2016 | 17/6/2026 | Lenovo Fingerprint Manager before 8.01.57 and Touch Fingerprint before 1.00.08 use weak ACLs for unspecified (1) services and (2) files, which allows local users to gain privileges by invalidating local checks. | |
| Modificada | Crítica (9.8) | 3.3% | — | Lexmark Printer Firmware | 27/1/2016 | 17/6/2026 | Race condition in the initialization process on Lexmark printers with firmware ATL before ATL.02.049, CB before CB.02.049, PP before PP.02.049, and YK before YK.02.049 allows remote attackers to bypass authentication by leveraging incorrect detection of the security-jumper status. | |
| Modificada | Media (6.8) | 0.65% | — | Canon Pixma Mg7500 Series Inkjet Printer | 11/9/2015 | 17/6/2026 | Cross-site request forgery (CSRF) vulnerability in the Remote UI on Canon PIXMA MG7500 printers allows remote attackers to hijack the authentication of administrators. | |
| Modificada | Media (6.8) | 1.9% | 💥 Exploit | Freereprintables Articlefr | 16/7/2015 | 17/6/2026 | Multiple cross-site request forgery (CSRF) vulnerabilities in Free Reprintables ArticleFR 3.0.6 allow remote attackers to hijack the authentication of administrators for requests that add an administrator account via a request to dashboard/users/create/. | |
| Modificada | Media (4.3) | 4.0% | 💥 Exploit | Freereprintables Articlefr | 16/7/2015 | 17/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in Free Reprintables ArticleFR 3.0.6 allow remote attackers to inject arbitrary web script or HTML via the (1) name parameter to dashboard/settings/categories/, (2) title or (3) rel parameter to dashboard/settings/links/, or (4) url parameter to… | |
| Modificada | Alta (7.5) | 1.3% | 💥 Exploit | Freereprintables Articlefr | 27/1/2015 | 17/6/2026 | SQL injection vulnerability in the getProfile function in system/profile.functions.php in Free Reprintables ArticleFR 3.0.5 allows remote attackers to execute arbitrary SQL commands via the username parameter to register/. | |
| Modificada | Media (4.3) | 1.9% | — | Freereprintables Articlefr | 27/1/2015 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in Free Reprintables ArticleFR 3.0.5 allows remote attackers to inject arbitrary web script or HTML via the q parameter to search/v/. | |
| Modificada | Media (6.8) | 1.1% | — | Lantronix Xprintserver | 20/11/2014 | 17/6/2026 | Cross-site request forgery (CSRF) vulnerability in Lantronix xPrintServer allows remote attackers to hijack the authentication of administrators for requests that modify configuration, as demonstrated by executing arbitrary commands using the c parameter in the rpc action. | |
| Modificada | Alta (10) | 5.1% | — | Lantronix Xprintserver | 20/11/2014 | 17/6/2026 | Lantronix xPrintServer does not properly restrict access to ips/, which allows remote attackers to execute arbitrary commands via the c parameter in an rpc action. | |
| Modificada | Alta (9) | 5.3% | — | HP Laserjet Cm3530 Multifunction Printer Firmware | 4/11/2014 | 17/6/2026 | Unspecified vulnerability on the HP LaserJet CM3530 Multifunction Printer CC519A and CC520A with firmware before 53.236.2 allows remote attackers to obtain sensitive information, modify data, or cause a denial of service via unknown vectors. | |
| Modificada | Media (5.4) | 0.27% | — | Gannett Argus Leader Print Edition | 19/10/2014 | 17/6/2026 | The Argus Leader Print Edition (aka com.argusleader.android.prod) application 6.7 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate. | |
| Modificada | Media (5.4) | 0.27% | — | Gannett Lansing State Journal Print | 19/10/2014 | 17/6/2026 | The Lansing State Journal Print (aka com.lansingjournal.android.prod) application 6.7 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate. | |
| Modificada | Alta (7.5) | 6.9% | — | HP Sprinter | 10/10/2014 | 17/6/2026 | Unspecified vulnerability in HP Sprinter 12.01 allows remote attackers to execute arbitrary code via unknown vectors, aka ZDI-CAN-2344. | |
| Modificada | Alta (7.5) | 6.9% | — | HP Sprinter | 10/10/2014 | 17/6/2026 | Unspecified vulnerability in HP Sprinter 12.01 allows remote attackers to execute arbitrary code via unknown vectors, aka ZDI-CAN-2342. | |
| Modificada | Alta (7.5) | 6.9% | — | HP Sprinter | 10/10/2014 | 17/6/2026 | Unspecified vulnerability in HP Sprinter 12.01 allows remote attackers to execute arbitrary code via unknown vectors, aka ZDI-CAN-2336. | |
| Modificada | Alta (7.5) | 6.9% | — | HP Sprinter | 10/10/2014 | 17/6/2026 | Unspecified vulnerability in HP Sprinter 12.01 allows remote attackers to execute arbitrary code via unknown vectors, aka ZDI-CAN-2343. | |
| Modificada | Baja (3.5) | 1.0% | — | Drupal Print | 9/10/2014 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in the Print (aka Printer, e-mail and PDF versions) module 6.x-1.x before 6.x-1.19, 7.x-1.x before 7.x-1.3, and 7.x-2.x before 7.x-2.0 for Drupal allows remote authenticated users with certain permissions to inject arbitrary web script or HTML via vectors related to nodes. | |
| Modificada | Media (5.4) | 0.27% | — | Gannett Daily Advertiser Print | 30/9/2014 | 17/6/2026 | The Daily Advertiser Print (aka com.lafayettedailyadv.android.prod) application 6.7 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate. | |
| Modificada | Media (5.4) | 0.30% | — | Kicksend Photo Prints | 9/9/2014 | 17/6/2026 | The Kicksend Photo Prints (aka com.kicksend.android.print) application 1.0.7 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate. | |
| Modificada | Media (5.4) | 0.27% | — | Torrnad0 Sprint Jump | 9/9/2014 | 17/6/2026 | The Sprint jump (aka air.com.ilaz.appilas) application 1 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate. | |
| Modificada | Alta (7.5) | 2.3% | 💥 Exploit | Freereprintables Articlefr | 22/8/2014 | 17/6/2026 | Multiple SQL injection vulnerabilities in Free Reprintables ArticleFR 3.0.4 and earlier allow remote attackers to execute arbitrary SQL commands via the id parameter in a (1) get or (2) set action to rate.php. | |
| Modificada | Alta (7.5) | 1.5% | — | SAP Print AND Output Management | 10/4/2014 | 17/6/2026 | SAP Print and Output Management has hardcoded credentials, which makes it easier for remote attackers to obtain access via unspecified vectors. | |
| Modificada | Media (6.8) | 1.1% | — | Wp-plugins Wp-print | 10/4/2014 | 16/6/2026 | Cross-site request forgery (CSRF) vulnerability in the Options in the WP-Print plugin before 2.52 for WordPress allows remote attackers to hijack the authentication of administrators for requests that manipulate plugin settings via unspecified vectors. |