Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas3023▼ 71 respecto a la semana anterior
Críticas / altas1419▲ 54 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▼ 128 respecto a la semana anterior
–

89 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (5.4)0.66%—Lexmark Cs31x FirmwareLexmark Cs41x FirmwareLexmark Cs51x FirmwareLexmark Cx310 Firmware+766/3/202017/6/2026
Various Lexmark products have stored XSS in the embedded web server used in older generation Lexmark devices. Affected products are available in http://support.lexmark.com/index?page=content&id=TE935&locale=en&userlocale=EN_US.
ModificadaMedia (5.4)0.65%—Lexmark Cs31x FirmwareLexmark Cs41x FirmwareLexmark Cs51x FirmwareLexmark Cx310 Firmware+766/3/202017/6/2026
Various Lexmark products have reflected XSS in the embedded web server used in older generation Lexmark devices. Affected products are available in http://support.lexmark.com/index?page=content&id=TE935&locale=en&userlocale=EN_US.
ModificadaMedia (5.4)0.53%—Lexmark Cx31x FirmwareLexmark Cx41x FirmwareLexmark Cx310 FirmwareLexmark Ms310 Firmware+7613/2/202017/6/2026
Lexmark printer MS812 and multiple older generation Lexmark devices have a stored XSS vulnerability in the embedded web server. The vulnerability can be exploited to expose session credentials and other information via the users web browser.
ModificadaAlta (7.5)4.4%—Lexmark Markvision Enterprise27/1/202017/6/2026
Directory traversal vulnerability in the ReportDownloadServlet servlet in Lexmark MarkVision Enterprise before 2.1 allows remote attackers to read arbitrary files via unspecified vectors.
ModificadaCrítica (9.8)77%—Lexmark Markvision Enterprise27/1/202017/6/2026
Directory traversal vulnerability in the GfdFileUploadServerlet servlet in Lexmark MarkVision Enterprise before 2.1 allows remote attackers to write to arbitrary files via unspecified vectors.
ModificadaAlta (7.5)17%—Lexmark Services Monitor Firmware21/11/201917/6/2026
In Lexmark Services Monitor 2.27.4.0.39 (running on TCP port 2070), a remote attacker can use a directory traversal technique using /../../../ or ..%2F..%2F..%2F to obtain local files on the host operating system.
ModificadaCrítica (9.8)1.5%—Lexmark Cs31x FirmwareLexmark Cs41x FirmwareLexmark Cx310 FirmwareLexmark Ms310 Firmware+6728/8/201917/6/2026
Various Lexmark products have a Buffer Overflow (issue 3 of 3).
ModificadaCrítica (9.8)1.5%—Lexmark Cs31x FirmwareLexmark Cs41x FirmwareLexmark Cx310 FirmwareLexmark Ms310 Firmware+6728/8/201917/6/2026
Various Lexmark products have a Buffer Overflow (issue 2 of 3).
ModificadaAlta (7.5)1.1%—Lexmark Cs31x FirmwareLexmark Cs41x FirmwareLexmark Cx310 FirmwareLexmark Ms310 Firmware+6728/8/201917/6/2026
Various Lexmark printers contain a denial of service vulnerability in the SNMP service that can be exploited to crash the device.
ModificadaCrítica (9.8)1.5%—Lexmark Cs31x FirmwareLexmark Cs41x FirmwareLexmark Cx310 FirmwareLexmark Ms310 Firmware+6728/8/201917/6/2026
Various Lexmark products have an Integer Overflow.
ModificadaMedia (5.3)0.87%—Lexmark Cs31x FirmwareLexmark Cs41x FirmwareLexmark Cx310 FirmwareLexmark Ms310 Firmware+6728/8/201917/6/2026
The legacy finger service (TCP port 79) is enabled by default on various older Lexmark devices.
ModificadaMedia (6.5)0.41%—Lexmark Cs31x FirmwareLexmark Cs41x FirmwareLexmark Cx310 FirmwareLexmark Ms310 Firmware+2128/8/201917/6/2026
Various Lexmark products have CSRF.
ModificadaMedia (5.3)0.83%—Lexmark Cs31x FirmwareLexmark Cs41x FirmwareLexmark Cx310 FirmwareLexmark Ms310 Firmware+2128/8/201917/6/2026
Various Lexmark products have Incorrect Access Control (issue 2 of 2).
ModificadaMedia (5.3)0.83%—Lexmark Cs31x FirmwareLexmark Cs41x FirmwareLexmark Cx310 FirmwareLexmark Ms310 Firmware+2128/8/201917/6/2026
Various Lexmark products have Incorrect Access Control (issue 1 of 2).
ModificadaCrítica (9.1)1.1%—Lexmark Cs31x FirmwareLexmark Cs41x FirmwareLexmark Cx310 FirmwareLexmark Ms310 Firmware+7028/8/201917/6/2026
Various Lexmark products have Incorrect Access Control.
ModificadaCrítica (9.8)1.2%—Lexmark Cx310 FirmwareLexmark Cx410 FirmwareLexmark Cx510 FirmwareLexmark Xc2132 Firmware+2828/6/201917/6/2026
Various Lexmark devices have a Buffer Overflow (issue 1 of 2).
ModificadaCrítica (9.8)1.2%—Lexmark Cx82x FirmwareLexmark Cx860 FirmwareLexmark Xc6152 FirmwareLexmark Xc8155 Firmware+3028/6/201917/6/2026
Various Lexmark devices have a Buffer Overflow (issue 2 of 2).
ModificadaMedia (4.9)0.87%—Lexmark Cx725h FirmwareLexmark Cx820 FirmwareLexmark Cx825 FirmwareLexmark Cx860 Firmware+412/3/201917/6/2026
On certain Lexmark devices that communicate with an LDAP or SMTP server, a malicious administrator can discover LDAP or SMTP credentials by changing that server's hostname to one that they control, and then capturing the credentials that are sent there. This occurs because stored credentials are not automatically…
ModificadaMedia (5.3)0.94%—Lexmark Xm5163 FirmwareLexmark Xm5170 FirmwareLexmark Xm7155 FirmwareLexmark Xm7163 Firmware+3611/2/201917/6/2026
Certain Lexmark CX, MX, X, XC, XM, XS, and 6500e devices before 2019-02-11 allow remote attackers to erase stored shortcuts.
ModificadaCrítica (9.8)3.4%—Lexmark Scan TO Network7/9/201717/6/2026
Lexmark Scan To Network (SNF) 3.2.9 and earlier stores network configuration credentials in plaintext and transmits them in requests, which allows remote attackers to obtain sensitive information via requests to (1) cgi-bin/direct/printer/prtappauth/apps/snfDestServlet or (2)…
ModificadaAlta (8.8)2.1%—Lexmark Perceptive Document Filters5/9/201717/6/2026
An exploitable code execution vulnerability exists in the image rendering functionality of Lexmark Perceptive Document Filters 11.3.0.2400. A specifically crafted PDF can cause a function call on a corrupted DCTStream to occur, resulting in user controlled data being written to the stack. A maliciously crafted PDF…
ModificadaAlta (8.8)2.3%—Lexmark Perceptive Document Filters5/9/201717/6/2026
An exploitable use-after-free exists in the PDF parsing functionality of Lexmark Perspective Document Filters 11.3.0.2400 and 11.4.0.2452. A crafted PDF document can lead to a use-after-free resulting in direct code execution.
ModificadaBaja (3.3)0.91%—Lexmark Perceptive Document Filters20/4/201717/6/2026
An exploitable arbitrary read exists in the XLS parsing of the Lexmark Perspective Document Filters conversion functionality. A crafted XLS document can lead to a arbitrary read resulting in memory disclosure. The vulnerability was confirmed on versions 11.3.0.2228 and 11.3.0.2400
ModificadaAlta (7.8)2.0%—Lexmark Perceptive Document Filters6/1/201717/6/2026
An exploitable heap overflow vulnerability exists in the Compound Binary File Format (CBFF) parser functionality of Lexmark Perceptive Document Filters library. A specially crafted CBFF file can cause a code execution. An attacker can send a malformed file to trigger this vulnerability.
ModificadaCrítica (9.8)3.9%—Lexmark Perceptive Document Filters6/1/201717/6/2026
An exploitable out-of-bounds write exists in the Bzip2 parsing of the Lexmark Perspective Document Filters conversion functionality. A crafted Bzip2 document can lead to a stack-based buffer overflow causing an out-of-bounds write which under the right circumstance could potentially be leveraged by an attacker to gain…