Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2856▼ 331 respecto a la semana anterior
Críticas / altas1383▼ 38 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)292▼ 217 respecto a la semana anterior
645 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Baja (3) | 0.15% | — | PhpweasyprintAI | 19/6/2026 | 23/6/2026 | PhpWeasyPrint is a PHP library allowing PDF generation from a URL or an HTML page. Prior to version 2.6.0, `AbstractGenerator::$temporaryFiles` is a public array, and `removeTemporaryFiles()` — invoked from `__destruct()` and from a registered shutdown function — calls `unlink()` on every entry without verifying that… | |
| Aplazada | Alta (8.5) | 0.17% | — | Brother SapsprintAI | 19/6/2026 | 23/6/2026 | Brother SAPSprint 7.60 contains an unquoted service path vulnerability in the SAPSprint service binary that allows local attackers to escalate privileges. Attackers can place a malicious executable in the Program Files directory path to be executed with LocalSystem privileges when the service starts automatically. | |
| Aplazada | Alta (8.1) | 0.43% | — | PrintoAI | 17/6/2026 | 6/10/2026 | Unauthenticated Local File Inclusion in Printo <= 1.11 versions. | |
| Aplazada | Alta (8.5) | 0.18% | — | Ricoh Printer DriversAIKonicaminolta Printer DriversAI | 15/6/2026 | 24/7/2026 | Multiple printer drivers provided by Ricoh Company, Ltd. and KONICA MINOLTA JAPAN, INC. contain a privilege escalation vulnerability. If this vulnerability is exploited, an attacker who can log in to a computer running an affected printer driver could elevate privileges by using a specially crafted driver. | |
| Aplazada | Alta (8.1) | 0.56% | — | PHPAICodesupplyco BlueprintAI | 2/6/2026 | 22/7/2026 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Code Supply Co. Blueprint allows PHP Local File Inclusion. This issue affects Blueprint: from n/a before 1.1.5. | |
| Aplazada | Media (6.5) | 0.17% | — | Printeers Print & ShipAI | 2/6/2026 | 22/7/2026 | Missing Authorization vulnerability in Printeers Printeers Print & Ship allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Printeers Print & Ship: from n/a through 1.17.0. | |
| Pendiente de análisis | Media (5.1) | 0.16% | — | Canon Pixus Ix6800 Series Cups Printer DriverAICanon Pixma Mg2500 Series Cups Printer DriverAI | 29/5/2026 | 21/7/2026 | Improper handling of symbolic links in the installer of CUPS Printer Driver for macOS(*) may allow a local attacker with login privileges to exploit a specially crafted symbolic link during installation to modify permissions of directories for which they would not normally have authorization. *:Canon PIXUS iX6800… | |
| Aplazada | Crítica (9.3) | 0.55% | — | Mapfish-printAI | 28/5/2026 | 17/6/2026 | mapfish-print is a component of MapFish for printing templated cartographic maps. From 3.23.0 to before 3.28.28, 3.30.30, 3.31.22, 3.33.14, and 4.0.3, the attacker can execute arbitrary code in Dynamic table without being authenticated. This vulnerability is fixed in 3.28.28, 3.30.30, 3.31.22, 3.33.14, and 4.0.3. | |
| Aplazada | Media (6.4) | 0.26% | — | GBI TO PrintAI | 27/5/2026 | 17/6/2026 | The GBI To Print plugin for WordPress is vulnerable to Stored Cross-Site Scripting in version 1.0 via the 'div' attribute of the 'gbitoprint' shortcode. This is due to insufficient output escaping in the gbi_toprint_shortcode() function, which concatenates the raw shortcode attribute value directly into an HTML… | |
| Modificada | Alta (8.5) | 4.6% | — | HP Linux Imaging AND Printing | 20/5/2026 | 4/8/2026 | A potential security vulnerability has been identified in the HP Linux Imaging and Printing Software. This potential vulnerability may allow escalation of privileges and/or arbitrary code execution via operating system command injection. | |
| Modificada | Crítica (9.3) | 1.1% | — | HP Linux Imaging AND Printing | 20/5/2026 | 4/8/2026 | A potential security vulnerability has been identified in the HP Linux Imaging and Printing Software. This potential vulnerability may allow escalation of privileges and/or arbitrary code execution via an integer overflow in the hpcups processing path when handling crafted print data. | |
| Aplazada | Media (6.5) | 0.40% | — | Eight DAY Week Print WorkflowAI | 12/5/2026 | 17/6/2026 | The Eight Day Week Print Workflow plugin for WordPress is vulnerable to time-based blind SQL Injection via the 'title' parameter in the `pp-get-articles` AJAX action in all versions up to, and including, 1.2.6. This is due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on… | |
| Aplazada | Alta (7.5) | 0.64% | — | Docuform Managed Print Service ClientAI | 11/5/2026 | 17/6/2026 | docuFORM Managed Print Service Client 11.11c is vulnerable to a directory traversal allowing attackers to read arbitrary files via crafted url. | |
| Aplazada | Media (6.1) | 0.24% | — | Docuform Managed Print Service ClientAI | 11/5/2026 | 17/6/2026 | docuFORM Managed Print Service Client 11.11c is vulnerable to a reflected cross site scripting attack via the login page of the application. | |
| Aplazada | Media (6.3) | 0.27% | — | Docuform Managed Print Service ClientAI | 11/5/2026 | 17/6/2026 | docuFORM Managed Print Service Client 11.11c is vulnerable to arbitrary file upload via pmupdate.php. | |
| Aplazada | Media (5.4) | 0.22% | — | Docuform Managed Print Service ClientAI | 11/5/2026 | 17/6/2026 | docuFORM Managed Print Service Client 11.11c is vulnerable to a session fixation attack via the login page of the application. | |
| Aplazada | Alta (7.3) | 0.29% | — | Gmbh Mecury Managed Print ServicesAI | 11/5/2026 | 17/6/2026 | A reflected cross-site scripted (XSS) vulnerability in the dfm-menu_orderopt.php component of GmbH Mecury Managed Print Services (docuForm) v11.11c allows attackers to execute arbitrary Javascript in the context of a user's browser via injecting a crafted payload into an unfiltered variable value. | |
| Aplazada | Alta (7.3) | 0.29% | — | Gmbh Mercury Managed Print ServicesAIGmbh DocuformAI | 11/5/2026 | 17/6/2026 | A reflected cross-site scripted (XSS) vulnerability in the dfm-menu_markeralerts.php component of GmbH Mecury Managed Print Services (docuForm) v11.11c allows attackers to execute arbitrary Javascript in the context of a user's browser via injecting a crafted payload into an unfiltered variable value. | |
| Aplazada | Alta (7.3) | 0.29% | — | Gmbh Mecury Managed Print ServicesAI | 11/5/2026 | 17/6/2026 | A reflected cross-site scripted (XSS) vulnerability in the acc-menu_pricess.php component of GmbH Mecury Managed Print Services (docuForm) v11.11c allows attackers to execute arbitrary Javascript in the context of a user's browser via injecting a crafted payload into an unfiltered variable value. | |
| Aplazada | Alta (7.3) | 0.29% | — | Gmbh Mercury Managed Print ServicesAI | 11/5/2026 | 17/6/2026 | A reflected cross-site scripted (XSS) vulnerability in the dfm-menu_alerts.php component of GmbH Mecury Managed Print Services (docuForm) v11.11c allows attackers to execute arbitrary Javascript in the context of a user's browser via injecting a crafted payload into an unfiltered variable value. | |
| Aplazada | Media (6.1) | 0.24% | — | Gmbh Mecury Managed Print ServicesAI | 11/5/2026 | 17/6/2026 | A reflected cross-site scripted (XSS) vulnerability in the acc-menu_billings.php component of GmbH Mecury Managed Print Services (docuForm) v11.11c allows attackers to execute arbitrary Javascript in the context of a user's browser via injecting a crafted payload into an unfiltered variable value. | |
| Aplazada | Media (6.1) | 0.24% | — | Gmbh Mecury Managed Print ServicesAI | 11/5/2026 | 17/6/2026 | A reflected cross-site scripted (XSS) vulnerability in the dfm-menu_departments.php component of GmbH Mecury Managed Print Services (docuForm) v11.11c allows attackers to execute arbitrary Javascript in the context of a user's browser via injecting a crafted payload into an unfiltered variable value. | |
| Aplazada | Media (6.1) | 0.24% | — | Gmbh Mecury Managed Print ServicesAI | 11/5/2026 | 17/6/2026 | A reflected cross-site scripted (XSS) vulnerability in the dfm-menu_maintenance.php component of GmbH Mecury Managed Print Services (docuForm) v11.11c allows attackers to execute arbitrary Javascript in the context of a user's browser via injecting a crafted payload into an unfiltered variable value. | |
| Aplazada | Media (6.1) | 0.24% | — | Gmbh Mecury Managed Print ServicesAIDocuformAI | 11/5/2026 | 17/6/2026 | A reflected cross-site scripted (XSS) vulnerability in the acc-menu_papers.php component of GmbH Mecury Managed Print Services (docuForm) v11.11c allows attackers to execute arbitrary Javascript in the context of a user's browser via injecting a crafted payload into an unfiltered variable value. | |
| Aplazada | Media (6.1) | 0.24% | — | Gmbh Mecury Managed Print ServicesAIGmbh DocuformAI | 11/5/2026 | 17/6/2026 | A reflected cross-site scripted (XSS) vulnerability in the dfm-menu_coveragealerts.php component of GmbH Mecury Managed Print Services (docuForm) v11.11c allows attackers to execute arbitrary Javascript in the context of a user's browser via injecting a crafted payload into an unfiltered variable value. |