Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2738▼ 488 respecto a la semana anterior
Críticas / altas1301▼ 189 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)229▼ 273 respecto a la semana anterior
–

144 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (5)2.6%—Xerox Workcentre 232Xerox Workcentre 238Xerox Workcentre 245Xerox Workcentre 255+221/2/200616/6/2026
Unspecified vulnerability in ESS/ Network Controller and MicroServer Web Server in Xerox WorkCentre Pro and Xerox WorkCentre running software 13.027.24.015 and 14.027.24.015 allows remote attackers to cause a denial of service via a crafted Postscript request.
ModificadaMedia (5)1.4%—Xerox Workcentre 232Xerox Workcentre 238Xerox Workcentre 245Xerox Workcentre 255+221/2/200616/6/2026
Cross-site scripting vulnerability in ESS/ Network Controller and MicroServer Web Server in Xerox WorkCentre Pro and Xerox WorkCentre running software 13.027.24.015 and 14.027.24.015 allows remote attackers to inject arbitrary web script or HTML via unknown attack vectors.
ModificadaMedia (5)2.1%—Xerox Workcentre 232Xerox Workcentre 238Xerox Workcentre 245Xerox Workcentre 255+221/2/200616/6/2026
Unspecified vulnerability in ESS/ Network Controller and MicroServer Web Server in Xerox WorkCentre Pro and Xerox WorkCentre running software 13.027.24.015 and 14.027.24.015 allows remote attackers to "reduce effectiveness of security features" via unknown attack vectors.
ModificadaAlta (7.5)2.8%—Xerox Workcentre 232Xerox Workcentre 238Xerox Workcentre 245Xerox Workcentre 255+221/2/200616/6/2026
Multiple unspecified vulnerabilities in ESS/ Network Controller and MicroServer Web Server in Xerox WorkCentre Pro and Xerox WorkCentre running software 13.027.24.015 and 14.027.24.015 allow remote attackers to bypass authentication or gain "unauthorized network access" via unknown attack vectors.
ModificadaAlta (7.5)2.5%—Xerox Document Centre 265Xerox Document Centre 332Xerox Document Centre 340Xerox Document Centre 420+323/8/200516/6/2026
Unknown vulnerability in Xerox MicroServer Web Server in Document Centre 220 through 265, 332 and 340, 420 through 490, and 535 through 555 allows remote attackers to bypass authentication.
ModificadaMedia (6.4)2.1%—Xerox Document Centre 220Xerox Document Centre 230Xerox Document Centre 240Xerox Document Centre 255+1623/8/200516/6/2026
Unknown vulnerability in Xerox MicroServer Web Server in Document Centre 220 through 265, 332 and 340, 420 through 490, and 535 through 555 allows remote attackers to cause a denial of service or read files via unknown vectors involving crafted HTTP requests.
ModificadaMedia (4.3)1.8%—Xerox Document Centre 265Xerox Document Centre 332Xerox Document Centre 340Xerox Document Centre 420+323/8/200516/6/2026
Cross-site scripting (XSS) vulnerability in Xerox MicroServer Web Server in Document Centre 220 through 265, 332 and 340, 420 through 490, and 535 through 555 allows remote attackers to inject arbitrary web script or HTML and modify web pages via unknown vectors.
ModificadaMedia (4.3)1.8%—Xerox Workcentre 2128Xerox Workcentre 2636Xerox Workcentre 354511/7/200516/6/2026
Cross-site scripting (XSS) vulnerability in the MicroServer Web Server for Xerox WorkCentre Pro Color 2128, 2636, and 3545, version 0.001.04.044 through 0.001.04.504, allows remote attackers to inject arbitrary web script or HTML via unknown vectors.
ModificadaMedia (6.4)2.4%—Xerox Workcentre 2128Xerox Workcentre 2636Xerox Workcentre 354511/7/200516/6/2026
Unknown vulnerability in the MicroServer Web Server for Xerox WorkCentre Pro Color 2128, 2636, and 3545, version 0.001.04.044 through 0.001.04.504, allow attackers to cause a denial of service or access files via crafted HTTP requests.
ModificadaAlta (7.5)2.2%—Xerox Workcentre 2128Xerox Workcentre 2636Xerox Workcentre 354511/7/200516/6/2026
Multiple unknown vulnerabilities in the MicroServer Web Server for Xerox WorkCentre Pro Color 2128, 2636, and 3545, version 0.001.04.044 through 0.001.04.504, allow attackers to bypass authentication.
ModificadaAlta (7.5)1.5%—Xerox Document Centre 220Xerox Document Centre 230Xerox Document Centre 240Xerox Document Centre 255+1613/6/200516/6/2026
Unknown vulnerability in the web server for the ESS/ Network Controller for Xerox Document Centre 240 through 555 running System Software 27.18.017 and earlier allows attackers to "gain unauthorized access."
ModificadaMedia (5)1.4%—Xerox WorkcentreXerox Workcentre 165Xerox Workcentre 175Xerox Workcentre 2128+152/5/200516/6/2026
Unknown vulnerability in Xerox MicroServer Web Server for various WorkCentre products including M35/M45/M55 2.028.11.000 through 2.97.20.032 and 4.84.16.000 through 4.97.20.032, Pro 35/45/55 3.028.11.000 through 3.97.20.032, Pro 65/75/90 1.001.00.060 through 1.001.02.084, and others, related to SNMP authentication,…
ModificadaMedia (5)1.0%—Xerox Workcentre 165Xerox Workcentre 175Xerox Workcentre 2128Xerox Workcentre 2636+147/3/200516/6/2026
Xerox MicroServer Web Server for various WorkCentre products including M35/M45/M55 2.028.11.000 through 2.97.20.032 and 4.84.16.000 through 4.97.20.032, Pro 35/45/55 3.028.11.000 through 3.97.20.032, Pro 65/75/90 1.001.00.060 through 1.001.02.084, and others, has an "unauthenticated account," which allows remote…
ModificadaMedia (6.4)1.4%—Xerox Docutech 6110Xerox Docutech 611531/12/200216/6/2026
The default configuration of Xerox DocuTech 6110 and DocuTech 6115 allows remote attackers to connect to the web server and (1) submit print jobs directly into the "print now" queue or (2) read the scanner job history.
ModificadaAlta (7.5)1.5%—Xerox Docutech 6110Xerox Docutech 611531/12/200216/6/2026
The default configuration of Xerox DocuTech 6110 and DocuTech 6115 running Solaris 8.0 has a large number of unnecessary services enabled such as RPC and sprayd, which could allow remote attackers to obtain access to the device.
ModificadaAlta (7.5)1.8%—Xerox Docutech 6110Xerox Docutech 611531/12/200216/6/2026
The default configurations for DocuTech 6110 and DocuTech 6115 have a default administrative password of (1) "service!" on Solaris 8.0 or (2) "administ" on Windows NT, which allows remote attackers to gain privileges.
ModificadaMedia (5)1.4%—Xerox Docutech 6110Xerox Docutech 611531/12/200216/6/2026
The default configuration of Xerox DocuTech 6110 and DocuTech 6115 exports certain NFS shares to the world with world writable permissions, which may allow remote attackers to modify sensitive files.
ModificadaMedia (5)1.6%—Xerox Docuprint N409/8/200116/6/2026
Xerox DocuPrint N40 Printers allow remote attackers to cause a denial of service via malformed data, such as that produced by the Code Red worm.
ModificadaMedia (5)1.3%—Xerox Docucolor 4LP13/10/199916/6/2026
HTTP server for Xerox DocuColor 4 LP allows remote attackers to cause a denial of service (hang) via a long URL that contains a large number of . characters.
Orbitaley — Vulnerabilidades