Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2698▼ 542 respecto a la semana anterior
Críticas / altas1273▼ 220 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)254▼ 248 respecto a la semana anterior
144 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (6) | 0.30% | — | Xerox Freeflow Print ServerSunos | 17/1/2013 | 16/6/2026 | Unspecified vulnerability in Oracle Sun Solaris 10 allows local users to affect confidentiality, integrity, and availability via unknown vectors related to the Bind/Postinstall script for Bind package. | |
| Modificada | Media (4.6) | 0.35% | — | Xerox Freeflow Print ServerSunos | 17/1/2013 | 16/6/2026 | Unspecified vulnerability in Oracle Sun Solaris 10 and 11 allows local users to affect availability via unknown vectors related to Kernel/DTrace Framework. | |
| Modificada | Baja (3.3) | 0.35% | — | Xerox Freeflow Print ServerSunos | 17/1/2013 | 16/6/2026 | Unspecified vulnerability Oracle Sun Solaris 10 allows local users to affect confidentiality and integrity via unknown vectors related to Install/smpatch. | |
| Modificada | Alta (9.3) | 5.5% | — | Adobe Flash PlayerAdobe AIRXerox Freeflow Print Server | 28/3/2012 | 16/6/2026 | The NetStream class in Adobe Flash Player before 10.3.183.18 and 11.x before 11.2.202.228 on Windows, Mac OS X, and Linux; Flash Player before 10.3.183.18 and 11.x before 11.2.202.223 on Solaris; Flash Player before 11.1.111.8 on Android 2.x and 3.x; and AIR before 3.2.0.2070 allows attackers to execute arbitrary code… | |
| Modificada | Media (5) | 1.2% | — | Xerox Workcentre 6400 NET ControllerXerox Workcentre 6400 System Software | 4/2/2010 | 16/6/2026 | Unspecified vulnerability in the Network Controller in Xerox WorkCentre 6400 System Software 060.070.109.11407 through 060.070.109.29510, and Net Controller 060.079.11410 through 060.079.29310, allows remote attackers to access "directory structure" via a crafted PostScript file, aka "Unauthorized Directory Structure… | |
| Modificada | Media (5) | 2.0% | — | Xerox Workcentre 5632Xerox Workcentre 5638Xerox Workcentre 5645Xerox Workcentre 5655+3 | 4/2/2010 | 16/6/2026 | Multiple unspecified vulnerabilities in the Network Controller and Web Server in Xerox WorkCentre 5632, 5638, 5645, 5655, 5665, 5675, and 5687 allow remote attackers to (1) access mailboxes via unknown vectors that bypass Scan to Mailbox authorization or (2) read device configuration information via via unknown… | |
| Modificada | Alta (7.5) | 2.7% | 💥 Exploit | Xerox Fiery Webtools | 9/11/2009 | 16/6/2026 | SQL injection vulnerability in summary.php in Xerox Fiery Webtools allows remote attackers to execute arbitrary SQL commands via the select parameter. | |
| Modificada | Alta (10) | 3.6% | — | Xerox Workcentre | 16/5/2009 | 16/6/2026 | Xerox WorkCentre and WorkCentre Pro 232, 238, 245, 255, 265, 275; and WorkCentre 5632, 5638, 5645, 5655, 5665, 5675, 5687, 7655, 7656, and 7675 allows remote attackers to execute arbitrary commands via unknown attack vectors, aka "command injection vulnerability." | |
| Modificada | Media (4.3) | 1.2% | — | Xerox Workcentre | 6/3/2009 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in the Web Server in Xerox WorkCentre 7132, 7228, 7235, and 7245 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. | |
| Modificada | Media (4.3) | 4.1% | 💥 Exploit | Xerox Docushare | 25/11/2008 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in Xerox DocuShare 6 and earlier allow remote attackers to inject arbitrary web script or HTML via the PATH_INFO to the default URI under (1) SearchResults/ and (2) Services/ in dsdn/dsweb/, and (3) the default URI under unspecified… | |
| Modificada | Alta (7.8) | 36% | 💥 Exploit | Xerox Phaser | 10/8/2008 | 16/6/2026 | The Xerox Phaser 8400 allows remote attackers to cause a denial of service (reboot) via an empty UDP packet to port 1900. | |
| Modificada | Media (4.3) | 1.0% | — | Xerox Centreware WEB | 10/7/2008 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in Xerox CentreWare Web (CWW) before 4.6.46 allow remote authenticated users to inject arbitrary web script or HTML via unspecified vectors. | |
| Modificada | Media (6.5) | 0.90% | — | Xerox Centreware WEB | 10/7/2008 | 16/6/2026 | Multiple SQL injection vulnerabilities in Xerox CentreWare Web (CWW) before 4.6.46 allow remote authenticated users to execute arbitrary SQL commands via the unspecified vectors. | |
| Modificada | Media (6.8) | 1.3% | — | Exerocms Exero CMS | 24/6/2008 | 16/6/2026 | Multiple directory traversal vulnerabilities in Exero CMS 1.0.0 and 1.0.1 allow remote attackers to include and execute arbitrary local files via a .. (dot dot) in the theme parameter to (1) custompage.php, (2) errors/404.php, (3) members/memberslist.php, (4) members/profile.php, (5) news/fullview.php, (6)… | |
| Modificada | Media (4.3) | 1.2% | — | Xerox Workcentre | 23/6/2008 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in the embedded Web Server in Xerox WorkCentre M123, M128, and 133 and WorkCentre Pro 123, 128, and 133 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. | |
| Modificada | Alta (10) | 2.6% | — | Xerox Workcentre | 23/6/2008 | 16/6/2026 | Unspecified vulnerability in the Extensible Interface Platform in Web Services in Xerox WorkCentre 7655, 7665, and 7675 allows remote attackers to make configuration changes via unknown vectors. | |
| Modificada | Media (4.3) | 1.2% | — | Xerox 4110Xerox 4590Xerox 4595 | 17/6/2008 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in the embedded web server in Xerox 4110, 4590, and 4595 Copier/Printers allows remote attackers to inject arbitrary web script or HTML via unknown attack vectors. | |
| Modificada | Alta (7.5) | 2.4% | 💥 Exploit | Exero CMS | 20/3/2008 | 16/6/2026 | Multiple directory traversal vulnerabilities in the Default theme in Exero CMS 1.0.1 allow remote attackers to include and execute arbitrary local files via directory traversal sequences in the theme parameter to (1) index.php, (2) editpassword.php, and (3) avatar.php in usercp/; (4) custompage.php; (5)… | |
| Modificada | Media (5) | 2.9% | 💥 Exploit | Xeroxer Simple One-file Gallery | 27/2/2007 | 16/6/2026 | Directory traversal vulnerability in gallery.php in XeroXer Simple one-file gallery allows remote attackers to read arbitrary files via a .. (dot dot) in the f parameter. | |
| Modificada | Media (4.3) | 1.9% | 💥 Exploit | Xeroxer Simple One-file Gallery | 27/2/2007 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in gallery.php in XeroXer Simple one-file gallery allows remote attackers to inject arbitrary web script or HTML via the f parameter. | |
| Modificada | Alta (7.5) | 10% | 💥 Exploit | Xero Portal | 30/1/2007 | 16/6/2026 | Multiple PHP remote file inclusion vulnerabilities in Xero Portal 1.2 allow remote attackers to execute arbitrary PHP code via a URL in the phpbb_root_path parameter to (1) admin_linkdb.php, (2) admin_forum_prune.php, (3) admin_extensions.php, (4) admin_board.php, (5) admin_attachments.php, or (6) admin_users.php in… | |
| Modificada | Alta (10) | 1.4% | — | Xerox Workcentre | 11/12/2006 | 16/6/2026 | The SNMP Agent in Xerox WorkCentre and WorkCentre Pro before 12.050.03.000, 13.x before 13.050.03.000, and 14.x before 14.050.03.000 returns no error for a non-writable object, which has unknown impact and attack vectors. NOTE: due to the vagueness of the advisory, it is not clear whether this is a vulnerability, or a… | |
| Modificada | Media (5.8) | 0.61% | — | Xerox Workcentre | 11/12/2006 | 16/6/2026 | Xerox WorkCentre and WorkCentre Pro before 12.050.03.000, 13.x before 13.050.03.000, and 14.x before 14.050.03.000 do not properly restrict access to SMB file resources, which allows remote attackers to gain unspecified file or directory access via vectors related to (1) visibility of the SMB "Homes" share and (2) SMB… | |
| Modificada | Media (5.8) | 0.45% | — | Xerox Workcentre | 11/12/2006 | 16/6/2026 | Xerox WorkCentre and WorkCentre Pro before 12.050.03.000, 13.x before 13.050.03.000, and 14.x before 14.050.03.000 do not block the postgres port (5432/tcp), which has unknown impact and remote attack vectors, probably related to unauthorized connections to a PostgreSQL daemon. | |
| Modificada | Alta (10) | 1.4% | — | Xerox Workcentre | 11/12/2006 | 16/6/2026 | Xerox WorkCentre and WorkCentre Pro before 12.050.03.000, 13.x before 13.050.03.000, and 14.x before 14.050.03.000 use weak permissions for certain files, which allows unspecified file access. |