Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2696▼ 543 respecto a la semana anterior
Críticas / altas1264▼ 228 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)262▼ 241 respecto a la semana anterior
–

144 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (7.5)1.0%—Xerox Phaser 3320 Firmware13/3/202017/6/2026
Some Xerox printers (such as the Phaser 3320 V53.006.16.000) did not implement account lockout. Local account credentials may be extracted from the device via brute force guessing attacks.
ModificadaCrítica (9.8)2.8%—Xerox Phaser 3320 Firmware13/3/202017/6/2026
Some Xerox printers (such as the Phaser 3320 V53.006.16.000) were affected by a buffer overflow vulnerability in the request parser of the IPP service. This would allow an unauthenticated attacker to cause a Denial of Service (DoS) and potentially execute arbitrary code on the device.
ModificadaAlta (8.8)1.1%—Xerox Workcentre 3655 FirmwareXerox Workcentre 3655i FirmwareXerox Workcentre 5845 FirmwareXerox Workcentre 5855 Firmware+1421/2/202017/6/2026
Certain Xerox WorkCentre printers before 073.xxx.000.02300 do not require the user to reenter or validate LDAP bind credentials when changing the LDAP connector IP address. A malicious actor who gains access to affected devices (e.g., by using default credentials) can change the LDAP connection IP address to a system…
ModificadaCrítica (9.8)1.2%—Xerox Colorqube 9201 FirmwareXerox Colorqube 9202 FirmwareXerox Colorqube 9203 FirmwareXerox Workcentre 6400 Firmware+813/2/202017/6/2026
Xerox ColorCube and WorkCenter devices in 2013 had hardcoded FTP and shell user accounts.
ModificadaMedia (5.9)0.50%—Fujixerox Apeosware Management Suite31/1/202017/6/2026
The AWMS Mobile App for Android 2.0.0 to 2.0.5 and for iOS 2.0.0 to 2.0.8 does not verify X.509 certificates from servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.
ModificadaAlta (7.4)0.52%—Fujixerox Easy Netprint27/1/202017/6/2026
The kantan netprint App for Android 2.0.3 and earlier does not verify X.509 certificates from servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.
ModificadaAlta (7.4)0.52%—Fujixerox Easy Netprint27/1/202017/6/2026
The kantan netprint App for iOS 2.0.2 and earlier does not verify X.509 certificates from servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.
ModificadaAlta (7.4)0.52%—Fujixerox Netprint27/1/202017/6/2026
The netprint App for iOS 3.2.3 and earlier does not verify X.509 certificates from servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.
ModificadaAlta (8.8)0.72%—Xerox Altalink C8035 Firmware18/12/201917/6/2026
Xerox AltaLink C8035 printers allow CSRF. A request to add users is made in the Device User Database form field to the xerox.set URI. (The frmUserName value must have a unique name.)
ModificadaCrítica (9.8)1.5%—Xerox Atlalink Firmware4/10/201917/6/2026
Xerox AtlaLink B8045/B8055/B8065/B8075/B8090 C8030/C8035/C8045/C8055/C8070 printers with software before 101.00x.089.22600 allow an attacker to gain privileges.
ModificadaMedia (6.1)1.1%—Fujixerox Docushare14/9/201917/6/2026
A Reflected Cross-Site Scripting (XSS) vulnerability in the webEx module in webExMeetingLogin.jsp and deleteWebExMeetingCheck.jsp in Fuji Xerox DocuShare through 7.0.0.C1.609 allows remote attackers to inject arbitrary web script or HTML via the handle parameter (webExMeetingLogin.jsp) and meetingKey parameter…
ModificadaMedia (6.1)1.1%—Fujixerox Apeosware Management SuiteFujixerox Apeosware Management Suite 212/9/201917/6/2026
Open redirect vulnerability in ApeosWare Management Suite Ver.1.4.0.18 and earlier, and ApeosWare Management Suite 2 Ver.2.1.2.4 and earlier allow remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via unspecified vectors.
ModificadaMedia (6.1)0.69%—Xerox Colorqube 8580 Firmware13/5/201917/6/2026
Cross-site scripting (XSS) in the web interface of the Xerox ColorQube 8580 allows remote persistent injection of custom HTML / JavaScript code.
ModificadaCrítica (9.8)8.5%—Xerox Colorqube 8700 FirmwareXerox Colorqube 8900 FirmwareXerox Colorqube 9301 FirmwareXerox Colorqube 9302 Firmware+112/4/201917/6/2026
Within multiple XEROX products a vulnerability allows remote command execution on the Linux system, as the "nobody" user through a crafted "HTTP" request (OS Command Injection vulnerability in the HTTP interface). Depending upon configuration authentication may not be necessary.
ModificadaCrítica (9.8)3.1%—Xerox Workcentre 3655i FirmwareXerox Workcentre 3655 FirmwareXerox Workcentre 5890i FirmwareXerox Workcentre 5865i Firmware+2510/2/201917/6/2026
An issue was discovered on Xerox WorkCentre 3655, 3655i, 58XX, 58XXi, 59XX, 59XXi, 6655, 6655i, 72XX, 72XXi, 78XX, 78XXi, 7970, 7970i, EC7836, and EC7856 devices before R18-05 073.xxx.0487.15000. There is unauthenticated Remote Command Execution.
ModificadaCrítica (9.8)1.1%—Xerox Workcentre 3655i FirmwareXerox Workcentre 3655 FirmwareXerox Workcentre 5890i FirmwareXerox Workcentre 5865i Firmware+2510/2/201917/6/2026
An issue was discovered on Xerox WorkCentre 3655, 3655i, 58XX, 58XXi, 59XX, 59XXi, 6655, 6655i, 72XX, 72XXi, 78XX, 78XXi, 7970, 7970i, EC7836, and EC7856 devices before R18-05 073.xxx.0487.15000. There is Blind SQL Injection.
ModificadaAlta (7.5)1.4%—Xerox Workcentre 3655i FirmwareXerox Workcentre 3655 FirmwareXerox Workcentre 5890i FirmwareXerox Workcentre 5865i Firmware+2510/2/201917/6/2026
An issue was discovered on Xerox WorkCentre 3655, 3655i, 58XX, 58XXi, 59XX, 59XXi, 6655, 6655i, 72XX, 72XXi, 78XX, 78XXi, 7970, 7970i, EC7836, and EC7856 devices before R18-05 073.xxx.0487.15000. There is a Local File Inclusion vulnerability.
ModificadaCrítica (9.8)1.2%—Xerox Workcentre 3655i FirmwareXerox Workcentre 3655 FirmwareXerox Workcentre 5890i FirmwareXerox Workcentre 5865i Firmware+2510/2/201917/6/2026
An issue was discovered on Xerox WorkCentre 3655, 3655i, 58XX, 58XXi, 59XX, 59XXi, 6655, 6655i, 72XX, 72XXi, 78XX, 78XXi, 7970, 7970i, EC7836, and EC7856 devices before R18-05 073.xxx.0487.15000. An attacker can execute PHP code by leveraging a writable file.
ModificadaAlta (8.8)2.2%—Xerox Workcentre 3655i FirmwareXerox Workcentre 3655 FirmwareXerox Workcentre 5890i FirmwareXerox Workcentre 5865i Firmware+2510/2/201917/6/2026
An issue was discovered on Xerox WorkCentre 3655, 3655i, 58XX, 58XXi, 59XX, 59XXi, 6655, 6655i, 72XX, 72XXi, 78XX, 78XXi, 7970, 7970i, EC7836, and EC7856 devices before R18-05 073.xxx.0487.15000. There is authenticated remote command execution.
ModificadaCrítica (9.8)2.0%—Xerox Altalink C8030 FirmwareXerox Altalink C8035 FirmwareXerox Altalink C8045 FirmwareXerox Altalink C8055 Firmware+63/1/201917/6/2026
The web application on Xerox AltaLink B80xx before 100.008.028.05200, C8030/C8035 before 100.001.028.05200, C8045/C8055 before 100.002.028.05200, and C8070 before 100.003.028.05200 allows unauthenticated command injection.
ModificadaCrítica (9.8)2.1%—Fujixerox Docucentre-v 3065 FirmwareFujixerox Apeosport-v C4475 FirmwareFujixerox Apeosport-vi C3371 FirmwareFujixerox Apeosport-v C3375 Firmware+57/9/201817/6/2026
Fuji Xerox DocuCentre-V 3065, ApeosPort-VI C3371, ApeosPort-V C4475, ApeosPort-V C3375, DocuCentre-VI C2271, ApeosPort-V C5576, DocuCentre-IV C2263, DocuCentre-V C2263, and ApeosPort-V 5070 devices allow remote attackers to read or write to files via crafted PJL commands.
ModificadaAlta (7.8)1.1%—Fujixerox Contentsbridge Utility1/9/201717/6/2026
Untrusted search path vulnerability in Installer for ContentsBridge Utility for Windows 7.4.0 and earlier allows an attacker to gain privileges via a Trojan horse DLL in an unspecified directory.
ModificadaAlta (7.8)1.1%—Fujixerox Docuworks1/9/201717/6/2026
Untrusted search path vulnerability in Self-extracting document generated by DocuWorks 8.0.7 and earlier allows an attacker to gain privileges via a Trojan horse DLL in an unspecified directory.
ModificadaAlta (7.8)1.1%—Fujixerox DocuworksFujixerox Docuworks Viewer Light1/9/201717/6/2026
Untrusted search path vulnerability in Installers for DocuWorks 8.0.7 and earlier and DocuWorks Viewer Light published in Jul 2017 and earlier allows an attacker to gain privileges via a Trojan horse DLL in an unspecified directory.
ModificadaMedia (6.5)2.7%💥 ExploitXerox Docushare2/5/201417/6/2026
SQL injection vulnerability in Xerox DocuShare before 6.53 Patch 6 Hotfix 2, 6.6.1 Update 1 before Hotfix 24, and 6.6.1 Update 2 before Hotfix 3 allows remote authenticated users to execute arbitrary SQL commands via the PATH_INFO to /docushare/dsweb/ResultBackgroundJobMultiple/. NOTE: some of these details are…