Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2856▼ 331 respecto a la semana anterior
Críticas / altas1383▼ 38 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)292▼ 217 respecto a la semana anterior
–

645 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaBaja (3)0.15%—PhpweasyprintAI19/6/202623/6/2026
PhpWeasyPrint is a PHP library allowing PDF generation from a URL or an HTML page. Prior to version 2.6.0, `AbstractGenerator::$temporaryFiles` is a public array, and `removeTemporaryFiles()` — invoked from `__destruct()` and from a registered shutdown function — calls `unlink()` on every entry without verifying that…
AplazadaAlta (8.5)0.17%—Brother SapsprintAI19/6/202623/6/2026
Brother SAPSprint 7.60 contains an unquoted service path vulnerability in the SAPSprint service binary that allows local attackers to escalate privileges. Attackers can place a malicious executable in the Program Files directory path to be executed with LocalSystem privileges when the service starts automatically.
AplazadaAlta (8.1)0.43%—PrintoAI17/6/20266/10/2026
Unauthenticated Local File Inclusion in Printo <= 1.11 versions.
AplazadaAlta (8.5)0.18%—Ricoh Printer DriversAIKonicaminolta Printer DriversAI15/6/202624/7/2026
Multiple printer drivers provided by Ricoh Company, Ltd. and KONICA MINOLTA JAPAN, INC. contain a privilege escalation vulnerability. If this vulnerability is exploited, an attacker who can log in to a computer running an affected printer driver could elevate privileges by using a specially crafted driver.
AplazadaAlta (8.1)0.56%—PHPAICodesupplyco BlueprintAI2/6/202622/7/2026
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Code Supply Co. Blueprint allows PHP Local File Inclusion. This issue affects Blueprint: from n/a before 1.1.5.
AplazadaMedia (6.5)0.17%—Printeers Print & ShipAI2/6/202622/7/2026
Missing Authorization vulnerability in Printeers Printeers Print & Ship allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Printeers Print & Ship: from n/a through 1.17.0.
Pendiente de análisisMedia (5.1)0.16%—Canon Pixus Ix6800 Series Cups Printer DriverAICanon Pixma Mg2500 Series Cups Printer DriverAI29/5/202621/7/2026
Improper handling of symbolic links in the installer of CUPS Printer Driver for macOS(*) may allow a local attacker with login privileges to exploit a specially crafted symbolic link during installation to modify permissions of directories for which they would not normally have authorization. *:Canon PIXUS iX6800…
AplazadaCrítica (9.3)0.55%—Mapfish-printAI28/5/202617/6/2026
mapfish-print is a component of MapFish for printing templated cartographic maps. From 3.23.0 to before 3.28.28, 3.30.30, 3.31.22, 3.33.14, and 4.0.3, the attacker can execute arbitrary code in Dynamic table without being authenticated. This vulnerability is fixed in 3.28.28, 3.30.30, 3.31.22, 3.33.14, and 4.0.3.
AplazadaMedia (6.4)0.26%—GBI TO PrintAI27/5/202617/6/2026
The GBI To Print plugin for WordPress is vulnerable to Stored Cross-Site Scripting in version 1.0 via the 'div' attribute of the 'gbitoprint' shortcode. This is due to insufficient output escaping in the gbi_toprint_shortcode() function, which concatenates the raw shortcode attribute value directly into an HTML…
ModificadaAlta (8.5)4.6%—HP Linux Imaging AND Printing20/5/20264/8/2026
A potential security vulnerability has been identified in the HP Linux Imaging and Printing Software. This potential vulnerability may allow escalation of privileges and/or arbitrary code execution via operating system command injection.
ModificadaCrítica (9.3)1.1%—HP Linux Imaging AND Printing20/5/20264/8/2026
A potential security vulnerability has been identified in the HP Linux Imaging and Printing Software. This potential vulnerability may allow escalation of privileges and/or arbitrary code execution via an integer overflow in the hpcups processing path when handling crafted print data.
AplazadaMedia (6.5)0.40%—Eight DAY Week Print WorkflowAI12/5/202617/6/2026
The Eight Day Week Print Workflow plugin for WordPress is vulnerable to time-based blind SQL Injection via the 'title' parameter in the `pp-get-articles` AJAX action in all versions up to, and including, 1.2.6. This is due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on…
AplazadaAlta (7.5)0.64%—Docuform Managed Print Service ClientAI11/5/202617/6/2026
docuFORM Managed Print Service Client 11.11c is vulnerable to a directory traversal allowing attackers to read arbitrary files via crafted url.
AplazadaMedia (6.1)0.24%—Docuform Managed Print Service ClientAI11/5/202617/6/2026
docuFORM Managed Print Service Client 11.11c is vulnerable to a reflected cross site scripting attack via the login page of the application.
AplazadaMedia (6.3)0.27%—Docuform Managed Print Service ClientAI11/5/202617/6/2026
docuFORM Managed Print Service Client 11.11c is vulnerable to arbitrary file upload via pmupdate.php.
AplazadaMedia (5.4)0.22%—Docuform Managed Print Service ClientAI11/5/202617/6/2026
docuFORM Managed Print Service Client 11.11c is vulnerable to a session fixation attack via the login page of the application.
AplazadaAlta (7.3)0.29%—Gmbh Mecury Managed Print ServicesAI11/5/202617/6/2026
A reflected cross-site scripted (XSS) vulnerability in the dfm-menu_orderopt.php component of GmbH Mecury Managed Print Services (docuForm) v11.11c allows attackers to execute arbitrary Javascript in the context of a user's browser via injecting a crafted payload into an unfiltered variable value.
AplazadaAlta (7.3)0.29%—Gmbh Mercury Managed Print ServicesAIGmbh DocuformAI11/5/202617/6/2026
A reflected cross-site scripted (XSS) vulnerability in the dfm-menu_markeralerts.php component of GmbH Mecury Managed Print Services (docuForm) v11.11c allows attackers to execute arbitrary Javascript in the context of a user's browser via injecting a crafted payload into an unfiltered variable value.
AplazadaAlta (7.3)0.29%—Gmbh Mecury Managed Print ServicesAI11/5/202617/6/2026
A reflected cross-site scripted (XSS) vulnerability in the acc-menu_pricess.php component of GmbH Mecury Managed Print Services (docuForm) v11.11c allows attackers to execute arbitrary Javascript in the context of a user's browser via injecting a crafted payload into an unfiltered variable value.
AplazadaAlta (7.3)0.29%—Gmbh Mercury Managed Print ServicesAI11/5/202617/6/2026
A reflected cross-site scripted (XSS) vulnerability in the dfm-menu_alerts.php component of GmbH Mecury Managed Print Services (docuForm) v11.11c allows attackers to execute arbitrary Javascript in the context of a user's browser via injecting a crafted payload into an unfiltered variable value.
AplazadaMedia (6.1)0.24%—Gmbh Mecury Managed Print ServicesAI11/5/202617/6/2026
A reflected cross-site scripted (XSS) vulnerability in the acc-menu_billings.php component of GmbH Mecury Managed Print Services (docuForm) v11.11c allows attackers to execute arbitrary Javascript in the context of a user's browser via injecting a crafted payload into an unfiltered variable value.
AplazadaMedia (6.1)0.24%—Gmbh Mecury Managed Print ServicesAI11/5/202617/6/2026
A reflected cross-site scripted (XSS) vulnerability in the dfm-menu_departments.php component of GmbH Mecury Managed Print Services (docuForm) v11.11c allows attackers to execute arbitrary Javascript in the context of a user's browser via injecting a crafted payload into an unfiltered variable value.
AplazadaMedia (6.1)0.24%—Gmbh Mecury Managed Print ServicesAI11/5/202617/6/2026
A reflected cross-site scripted (XSS) vulnerability in the dfm-menu_maintenance.php component of GmbH Mecury Managed Print Services (docuForm) v11.11c allows attackers to execute arbitrary Javascript in the context of a user's browser via injecting a crafted payload into an unfiltered variable value.
AplazadaMedia (6.1)0.24%—Gmbh Mecury Managed Print ServicesAIDocuformAI11/5/202617/6/2026
A reflected cross-site scripted (XSS) vulnerability in the acc-menu_papers.php component of GmbH Mecury Managed Print Services (docuForm) v11.11c allows attackers to execute arbitrary Javascript in the context of a user's browser via injecting a crafted payload into an unfiltered variable value.
AplazadaMedia (6.1)0.24%—Gmbh Mecury Managed Print ServicesAIGmbh DocuformAI11/5/202617/6/2026
A reflected cross-site scripted (XSS) vulnerability in the dfm-menu_coveragealerts.php component of GmbH Mecury Managed Print Services (docuForm) v11.11c allows attackers to execute arbitrary Javascript in the context of a user's browser via injecting a crafted payload into an unfiltered variable value.
Orbitaley — Vulnerabilidades