Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2737▼ 484 respecto a la semana anterior
Críticas / altas1302▼ 187 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)227▼ 275 respecto a la semana anterior
–

65 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaCrítica (9.8)4.3%—Ricoh D2200 FirmwareRicoh D5500 FirmwareRicoh D5510 FirmwareRicoh D5520 Firmware+49/1/201917/6/2026
RICOH Interactive Whiteboard D2200 V1.6 to V2.2, D5500 V1.6 to V2.2, D5510 V1.6 to V2.2, and the display versions with RICOH Interactive Whiteboard Controller Type1 V1.6 to V2.2 attached (D5520, D6500, D6510, D7500, D8400) allows remote attackers to execute arbitrary commands via unspecified vectors.
ModificadaCrítica (9.8)21%—Ricoh Myprint14/12/201817/6/2026
Hardcoded credentials in the Ricoh myPrint application 2.9.2.4 for Windows and 2.2.7 for Android give access to any externally disclosed myPrint WSDL API, as demonstrated by discovering API secrets of related Google cloud printers, encrypted passwords of mail servers, and names of printed files.
ModificadaMedia (6.1)1.0%—Ricoh MP C6003 Firmware26/9/201817/6/2026
On the RICOH MP C6003 printer, HTML Injection and Stored XSS vulnerabilities have been discovered in the area of adding addresses via the entryNameIn parameter to /web/entry/en/address/adrsSetUserWizard.cgi.
ModificadaMedia (6.1)1.0%—Ricoh MP C2003sp Firmware26/9/201817/6/2026
On the RICOH MP C2003 printer, HTML Injection and Stored XSS vulnerabilities have been discovered in the area of adding addresses via the entryNameIn parameter to /web/entry/en/address/adrsSetUserWizard.cgi.
ModificadaMedia (6.1)1.0%—Ricoh MP 305+ Firmware26/9/201817/6/2026
On the RICOH Aficio MP 305+ printer, HTML Injection and Stored XSS vulnerabilities have been discovered in the area of adding addresses via the entryNameIn parameter to /web/entry/en/address/adrsSetUserWizard.cgi.
ModificadaMedia (6.1)2.3%💥 ExploitRicoh MP C307 Firmware26/9/201817/6/2026
On the RICOH MP C307 printer, HTML Injection and Stored XSS vulnerabilities have been discovered in the area of adding addresses via the entryNameIn parameter to /web/entry/en/address/adrsSetUserWizard.cgi.
ModificadaMedia (6.1)1.0%—Ricoh Aficio MP 301spf Firmware26/9/201817/6/2026
On the RICOH Aficio MP 301 printer, HTML Injection and Stored XSS vulnerabilities have been discovered in the area of adding addresses via the entryNameIn parameter to /web/entry/en/address/adrsSetUserWizard.cgi.
ModificadaMedia (6.1)1.0%—Ricoh MP C6503 Firmware26/9/201817/6/2026
On the RICOH MP C6503 Plus printer, HTML Injection and Stored XSS vulnerabilities have been discovered in the area of adding addresses via the entryNameIn parameter to /web/entry/en/address/adrsSetUserWizard.cgi.
ModificadaMedia (6.1)2.3%💥 ExploitRicoh MP C1803 JPN Firmware26/9/201817/6/2026
On the RICOH MP C1803 JPN printer, HTML Injection and Stored XSS vulnerabilities have been discovered in the area of adding addresses via the entryNameIn parameter to /web/entry/en/address/adrsSetUserWizard.cgi.
ModificadaMedia (6.1)1.0%—Ricoh MP C406zspf Firmware26/9/201817/6/2026
On the RICOH MP C406Z printer, HTML Injection and Stored XSS vulnerabilities have been discovered in the area of adding addresses via the entryNameIn parameter to /web/entry/en/address/adrsSetUserWizard.cgi.
ModificadaMedia (6.1)1.0%—Ricoh MP 2001sp Firmware21/9/201817/6/2026
On the RICOH MP 2001 printer, HTML Injection and Stored XSS vulnerabilities have been discovered in the area of adding addresses via the entryNameIn parameter to /web/entry/en/address/adrsSetUserWizard.cgi.
ModificadaMedia (6.1)1.0%—Ricoh SP 4510sf Firmware21/9/201817/6/2026
On the RICOH SP 4510SF printer, HTML Injection and Stored XSS vulnerabilities have been discovered in the area of adding addresses via the entryNameIn parameter to /web/entry/en/address/adrsSetUserWizard.cgi.
ModificadaAlta (8.8)2.5%💥 ExploitRicoh MP C4504ex Firmware28/8/201817/6/2026
RICOH MP C4504ex devices allow HTML Injection via the /web/entry/en/address/adrsSetUserWizard.cgi entryNameIn parameter.
ModificadaAlta (7.5)7.7%💥 ExploitRicoh Dl-1 Sr1031/8/201517/6/2026
Buffer overflow in Ricoh DL FTP Server 1.1.0.6 and earlier allows remote attackers to execute arbitrary code via a long USER command.
ModificadaMedia (6.8)31%💥 ExploitRicoh Dl-10Ricoh Sr10 FTP Server19/9/201216/6/2026
Stack-based buffer overflow in SR10 FTP server (SR10.exe) 1.1.0.6 in Ricoh DC Software DL-10 4.5.0.1, when the Log file name option is enabled, allows remote attackers to execute arbitrary code via a long USER FTP command.