Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2726▼ 504 respecto a la semana anterior
Críticas / altas1294▼ 196 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)229▼ 273 respecto a la semana anterior
645 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Media (6.9) | 0.68% | — | Harry0703 Moneyprinterturbo | 20/7/2025 | 17/6/2026 | A vulnerability was found in harry0703 MoneyPrinterTurbo up to 1.2.6 and classified as critical. Affected by this issue is the function verify_token of the file app/controllers/base.py of the component API Endpoint. The manipulation leads to missing authentication. The attack may be launched remotely. | |
| Analizada | Media (5.3) | 0.46% | — | Harry0703 Moneyprinterturbo | 20/7/2025 | 17/6/2026 | A vulnerability has been found in harry0703 MoneyPrinterTurbo up to 1.2.6 and classified as critical. Affected by this vulnerability is the function download_video/delete_video of the file app/controllers/v1/video.py. The manipulation leads to path traversal. The attack can be launched remotely. | |
| Analizada | Media (5.3) | 0.40% | — | Harry0703 Moneyprinterturbo | 20/7/2025 | 17/6/2026 | A vulnerability, which was classified as critical, was found in harry0703 MoneyPrinterTurbo up to 1.2.6. Affected is the function upload_bgm_file of the file app/controllers/v1/video.py of the component File Extension Handler. The manipulation of the argument File leads to unrestricted upload. It is possible to launch… | |
| Aplazada | Alta (8.5) | 0.29% | — | Printcart WEB TO Print Product Designer FOR WoocommerceAI | 4/7/2025 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in printcart Printcart Web to Print Product Designer for WooCommerce printcart-integration allows SQL Injection.This issue affects Printcart Web to Print Product Designer for WooCommerce: from n/a through <= 2.4.0. | |
| Analizada | Media (4.8) | 0.31% | — | HP Universal Print Driver | 2/7/2025 | 17/6/2026 | HP Universal Print Driver is potentially vulnerable to denial of service due to buffer overflow in versions of UPD 7.4 or older (e.g., v7.3.x, v7.2.x, v7.1.x, etc.). | |
| Aplazada | Alta (8.1) | 0.72% | — | Bzotheme PrintxtoreAI | 27/6/2025 | 17/6/2026 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in BZOTheme PrintXtore bw-printxtore allows PHP Local File Inclusion.This issue affects PrintXtore: from n/a through < 1.7.8. | |
| Analizada | Media (6.5) | 0.26% | — | Octoprint | 10/6/2025 | 17/6/2026 | OctoPrint versions up until and including 1.11.1 contain a vulnerability that allows any unauthenticated attacker to send a manipulated broken multipart/form-data request to OctoPrint and through that make the web server component become unresponsive. The issue can be triggered by a broken multipart/form-data request… | |
| Analizada | Media (4.6) | 0.29% | — | Octoprint | 10/6/2025 | 17/6/2026 | OctoPrint provides a web interface for controlling consumer 3D printers. OctoPrint versions up until and including 1.11.1 contain a vulnerability that allows an attacker with the FILE_UPLOAD permission to exfiltrate files from the host that OctoPrint has read access to, by moving them into the upload folder where they… | |
| Aplazada | Media (4.3) | 0.15% | — | Bunnys Print CSSAI | 10/6/2025 | 17/6/2026 | The Bunny’s Print CSS plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 0.95. This is due to missing or incorrect nonce validation on the pcss_options_subpanel() function. This makes it possible for unauthenticated attackers to update settings via a forged request… | |
| Aplazada | Media (6.9) | 0.40% | — | M3M Printer Server WEBAI | 26/5/2025 | 17/6/2026 | User enumeration vulnerability in M3M Printer Server Web. This issue occurs during user authentication, where a difference in error messages could allow an attacker to determine whether a username is valid or not, allowing a brute force attack on valid usernames. | |
| Aplazada | Crítica (10) | 0.42% | — | Printcart WEB TO Print Product Designer FOR WoocommerceAI | 23/5/2025 | 17/6/2026 | Unrestricted Upload of File with Dangerous Type vulnerability in printcart Printcart Web to Print Product Designer for WooCommerce printcart-integration allows Upload a Web Shell to a Web Server.This issue affects Printcart Web to Print Product Designer for WooCommerce: from n/a through <= 2.3.9. | |
| Aplazada | Crítica (9.3) | 0.34% | — | Printcart WEB TO Print Product Designer FOR WoocommerceAI | 23/5/2025 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in printcart Printcart Web to Print Product Designer for WooCommerce printcart-integration allows SQL Injection.This issue affects Printcart Web to Print Product Designer for WooCommerce: from n/a through <= 2.4.0. | |
| Analizada | Alta (8) | 0.26% | — | Dynamixsoftware Printershare | 23/5/2025 | 17/6/2026 | A double-free condition occurs during the cleanup of temporary image files, which can be exploited to achieve memory corruption and potentially arbitrary code execution. | |
| Analizada | Crítica (9.8) | 0.69% | — | Dynamixsoftware Printershare | 23/5/2025 | 17/6/2026 | An Out of Bounds Write occurs when the native library attempts PDF rendering, which can be exploited to achieve memory corruption and potentially arbitrary code execution. | |
| Analizada | Crítica (9.1) | 0.30% | — | Dynamixsoftware Printershare | 23/5/2025 | 17/6/2026 | PrinterShare Android application allows the capture of Gmail authentication tokens that can be reused to access a user's Gmail account without proper authorization. | |
| Aplazada | Alta (8.4) | 0.21% | — | Seiko Epson Printer DriversAI | 28/4/2025 | 17/6/2026 | Multiple SEIKO EPSON printer drivers for Windows OS are configured with an improper access permission settings when installed or used in a language other than English. If a user is directed to place a crafted DLL file in a location of an attacker's choosing, the attacker may execute arbitrary code with SYSTEM… | |
| Aplazada | Media (6.5) | 0.53% | — | Entrust Corp Printer ManagerAI | 25/4/2025 | 17/6/2026 | An issue in the Printer Manager Systm of Entrust Corp Printer Manager D3.18.4-3 and below allows attackers to execute a directory traversal via a crafted POST request. | |
| Aplazada | Alta (7.1) | 0.15% | — | John Weissberg Print Science DesignerAI | 24/4/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in John Weissberg Print Science Designer print-science-designer allows Stored XSS.This issue affects Print Science Designer: from n/a through <= 1.3.155. | |
| Aplazada | Media (4.3) | 0.28% | — | Woocommerce Automatic Order PrintingAI | 24/4/2025 | 17/6/2026 | The Woocommerce Automatic Order Printing | ( Formerly WooCommerce Google Cloud Print) plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 4.1 via the xc_woo_printer_preview AJAX action due to missing validation on a user controlled key. This makes it possible… | |
| Analizada | Media (4.3) | 0.25% | — | Octoprint | 22/4/2025 | 17/6/2026 | OctoPrint provides a web interface for controlling consumer 3D printers. In versions up to and including 1.10.3, OctoPrint has a vulnerability that allows an attacker to bypass the login redirect and directly access the rendered HTML of certain frontend pages. The primary risk lies in potential future modifications to… | |
| Aplazada | Alta (7.5) | 0.73% | — | John Weissberg Print Science DesignerAI | 11/4/2025 | 17/6/2026 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in John Weissberg Print Science Designer print-science-designer allows Path Traversal.This issue affects Print Science Designer: from n/a through <= 1.3.155. | |
| Aplazada | Alta (7.1) | 0.19% | — | SEO Nutrition AND Print FOR Recipes BY EdamamAI | 9/4/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Edamam SEO, Nutrition and Print for Recipes by Edamam seo-nutrition-and-print-for-recipes-by-edamam allows Stored XSS.This issue affects SEO, Nutrition and Print for Recipes by Edamam: from n/a through <= 3.3. | |
| Analizada | Media (4.9) | 0.40% | — | Wp3dprinting 3dprint Lite | 8/4/2025 | 17/6/2026 | The 3DPrint Lite plugin for WordPress is vulnerable to SQL Injection via the 'printer_text' parameter in all versions up to, and including, 2.1.3.6 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated… | |
| Analizada | Media (4.9) | 0.40% | — | Wp3dprinting 3dprint Lite | 8/4/2025 | 17/6/2026 | The 3DPrint Lite plugin for WordPress is vulnerable to SQL Injection via the 'material_text' parameter in all versions up to, and including, 2.1.3.6 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated… | |
| Analizada | Media (4.9) | 0.40% | — | Wp3dprinting 3dprint Lite | 8/4/2025 | 17/6/2026 | The 3DPrint Lite plugin for WordPress is vulnerable to SQL Injection via the 'coating_text' parameter in all versions up to, and including, 2.1.3.6 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated… |