Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2722▼ 518 respecto a la semana anterior
Críticas / altas1296▼ 206 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)226▼ 276 respecto a la semana anterior
195 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Crítica (9.9) | 1.1% | — | Vasion Printerlogic Client | 25/7/2023 | 17/6/2026 | An issue was discovered in Vasion PrinterLogic Client for Windows before 25.0.0.818. During installation, binaries gets executed out of a subfolder in C:\Windows\Temp. A standard user can create the folder and path file ahead of time and obtain elevated code execution. | |
| Modificada | Alta (7.8) | 0.14% | — | Ricoh Printer Driver Packager NX | 19/6/2023 | 17/6/2026 | The driver installation package created by Printer Driver Packager NX v1.0.02 to v1.1.25 fails to detect its modification and may spawn an unexpected process with the administrative privilege. If a non-administrative user modifies the driver installation package and runs it on the target PC, an arbitrary program may… | |
| Modificada | Alta (7.8) | 0.18% | — | Dell Multifunction Printer E525w Driver AND Software Suite | 21/2/2023 | 17/6/2026 | Dell Multifunction Printer E525w Driver and Software Suite, versions prior to 1.047.2022, A05, contain a local privilege escalation vulnerability that could be exploited by malicious users to compromise the affected system | |
| Modificada | Media (6.1) | 0.45% | — | Averydennison Monarch Printer M9855 Firmware | 10/2/2023 | 17/6/2026 | Avery Dennison Monarch Printer M9855 is vulnerable to Cross Site Scripting (XSS). | |
| Modificada | Crítica (9.8) | 2.1% | — | Printer Project Printer | 31/12/2022 | 17/6/2026 | A vulnerability was found in Exciting Printer and classified as critical. This issue affects some unknown processing of the file lib/printer/jobs/prepare_page.rb of the component Argument Handler. The manipulation of the argument URL leads to command injection. The patch is named… | |
| Modificada | Crítica (9.8) | 1.5% | — | HP Color Laserjet Cm4540 MFP Cc419a FirmwareHP Color Laserjet Cm4540 MFP Cc420a FirmwareHP Color Laserjet Cm4540 MFP Cc421a FirmwareHP Color Laserjet Cm5525 MFP Ce707a Firmware+2696 | 12/12/2022 | 17/6/2026 | Certain HP Print products and Digital Sending products may be vulnerable to potential remote code execution and buffer overflow with use of Link-Local Multicast Name Resolution or LLMNR. | |
| Analizada | Alta (8.8) | 1.8% | — | Printerlogic Windows Client | 25/8/2022 | 17/6/2026 | PrinterLogic Windows Client through 25.0.0.676 allows attackers to execute directory traversal. Authenticated users with prior knowledge of the driver filename could exploit this to escalate privileges or distribute malicious content. This issue has been resolved in PrinterLogic Windows Client 25.0.0688 and all… | |
| Modificada | Alta (7.5) | 1.4% | — | Printerlogic WEB Stack | 2/2/2022 | 9/7/2026 | PrinterLogic Web Stack versions 19.1.1.13 SP9 and below are vulnerable to an Insecure Direct Object Reference (IDOR) vulnerability that allows an unauthenticated attacker to disclose the plaintext console username and password for a printer. | |
| Modificada | Alta (7.5) | 2.0% | — | Printerlogic WEB Stack | 2/2/2022 | 9/7/2026 | PrinterLogic Web Stack versions 19.1.1.13 SP9 and below are vulnerable to an Insecure Direct Object Reference (IDOR) vulnerability that allows an unauthenticated attacker to disclose the username and email address of all users. | |
| Modificada | Crítica (9.1) | 2.0% | — | Printerlogic WEB Stack | 2/2/2022 | 9/7/2026 | PrinterLogic Web Stack versions 19.1.1.13 SP9 and below are vulnerable to an Insecure Direct Object Reference (IDOR) vulnerability that allows an unauthenticated attacker to reassign drivers for any printer. | |
| Modificada | Media (6.1) | 1.2% | — | Printerlogic WEB Stack | 2/2/2022 | 9/7/2026 | PrinterLogic Web Stack versions 19.1.1.13 SP9 and below are vulnerable to multiple reflected cross site scripting vulnerabilities. Attacker controlled input is reflected back in the page without sanitization. | |
| Modificada | Crítica (9.8) | 2.3% | — | Printerlogic WEB Stack | 2/2/2022 | 9/7/2026 | PrinterLogic Web Stack versions 19.1.1.13 SP9 and below use user-controlled input to craft a URL, resulting in a Server Side Request Forgery (SSRF) vulnerability. | |
| Modificada | Media (5.3) | 2.0% | — | Printerlogic WEB Stack | 2/2/2022 | 9/7/2026 | PrinterLogic Web Stack versions 19.1.1.13 SP9 and below are vulnerable to SQL Injection, which may allow an attacker to access additional audit records. | |
| Modificada | Alta (8.1) | 5.5% | — | Printerlogic WEB Stack | 1/2/2022 | 9/7/2026 | PrinterLogic Web Stack versions 19.1.1.13 SP9 and below do not sanitize user input resulting in pre-auth remote code execution. | |
| Modificada | Alta (8.1) | 5.6% | — | Printerlogic WEB Stack | 31/1/2022 | 9/7/2026 | PrinterLogic Web Stack versions 19.1.1.13 SP9 and below use a hardcoded APP_KEY value, leading to pre-auth remote code execution. | |
| Modificada | Alta (8.1) | 6.2% | — | Printerlogic Virtual AppliancePrinterlogic WEB Stack | 31/1/2022 | 9/7/2026 | PrinterLogic Web Stack versions 19.1.1.13 SP9 and below deserializes attacker controlled leading to pre-auth remote code execution. | |
| Modificada | Alta (8.8) | 2.3% | — | HP Color Laserjet Cm4540 MFP FirmwareHP Color Laserjet Enterprise Flow MFP M880z FirmwareHP Color Laserjet Managed Flow MFP M880zm FirmwareHP Color Laserjet Enterprise M455 Firmware+211 | 9/11/2021 | 17/6/2026 | During installation with certain driver software or application packages an arbitrary code execution could occur. | |
| Modificada | Alta (7.8) | 0.25% | — | Lexmark Printer Software G2Lexmark Printer Software G3Lexmark Printer Software G4 | 14/7/2021 | 17/6/2026 | The Lexmark Printer Software G2, G3 and G4 Installation Packages have a local escalation of privilege vulnerability due to a registry entry that has an unquoted service path. | |
| Modificada | Alta (7.8) | 0.34% | — | Epson Album PrintEpson Color Calibration UtilityEpson ColorbaseEpson Colorio Easy Print+29 | 24/11/2020 | 17/6/2026 | Untrusted search path vulnerability in the installers of multiple SEIKO EPSON products allows an attacker to gain privileges via a Trojan horse DLL in an unspecified directory. | |
| Modificada | Crítica (9.8) | 2.5% | — | Mijia Inkjet Printer Firmware | 24/6/2020 | 17/6/2026 | An issue was discovered on Xiaomi Mi Jia ink-jet printer < 3.4.6_0138. Injecting parameters to ippserver through the web management background, resulting in command execution vulnerabilities. | |
| Modificada | Alta (8.8) | 1.4% | — | Printeron Central Print Services | 29/7/2019 | 17/6/2026 | An issue was discovered in PrinterOn Central Print Services (CPS) through 4.1.4. A user without valid credentials can bypass the authentication process, obtaining a valid session cookie with guest/pseudo-guest level privileges. This cookie can then be further used to perform other attacks. | |
| Modificada | Media (5.3) | 1.7% | — | Printeron Central Print Services | 29/7/2019 | 17/6/2026 | An issue was discovered in PrinterOn Central Print Services (CPS) through 4.1.4. An unauthenticated attacker can view details about the printers associated with CPS via a crafted HTTP GET request. | |
| Modificada | Alta (8.8) | 1.7% | — | Printeron Central Print Services | 20/7/2019 | 17/6/2026 | An issue was discovered in PrinterOn Central Print Services (CPS) through 4.1.4. The core components that create and launch a print job do not perform complete verification of the session cookie that is supplied to them. As a result, an attacker with guest/pseudo-guest level permissions can bypass the session checks… | |
| Modificada | Crítica (9.8) | 3.5% | — | Printerlogic Print Management | 8/5/2019 | 17/6/2026 | The PrinterLogic Print Management software, versions up to and including 18.3.1.96, does not sanitize special characters allowing for remote unauthorized changes to configuration files. An unauthenticated attacker may be able to remotely execute arbitrary code with SYSTEM privileges. | |
| Modificada | Crítica (9.8) | 1.1% | — | Printerlogic Print Management | 8/5/2019 | 17/6/2026 | The PrinterLogic Print Management software, versions up to and including 18.3.1.96, updates and executes the code without sufficiently verifying the origin and integrity of the code. An attacker can execute malicious code by compromising the host server, performing DNS spoofing, or modifying the code in transit. |