Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2715▼ 529 respecto a la semana anterior
Críticas / altas1290▼ 220 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)225▼ 276 respecto a la semana anterior
–

195 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (7.4)0.75%—Printerlogic Print Management8/5/201917/6/2026
The PrinterLogic Print Management software, versions up to and including 18.3.1.96, does not validate, or incorrectly validates, the PrinterLogic management portal's SSL certificate. When a certificate is invalid or malicious, it might allow an attacker to spoof a trusted entity by using a man-in-the-middle (MITM)…
ModificadaAlta (7.7)1.5%—Printeron23/4/201917/6/2026
An XML external entity (XXE) vulnerability in PrinterOn version 4.1.4 and lower allows remote authenticated users to read arbitrary files or conduct server-side request forgery (SSRF) attacks via a crafted DTD in an XML request.
ModificadaMedia (6.5)0.53%—Printeron18/4/201917/6/2026
PrinterOn Enterprise 4.1.4 contains multiple Cross Site Request Forgery (CSRF) vulnerabilities in the Administration page. For example, an administrator, by following a link, can be tricked into making unwanted changes to a printer (Disable, Approve, etc).
ModificadaMedia (5.4)0.63%—Printeron21/3/201917/6/2026
PrinterOn Enterprise 4.1.4 suffers from multiple authenticated stored XSS vulnerabilities via the (1) "Machine Host Name" or "Server Serial Number" field in the clustering configuration, (2) "name" field in the Edit Group configuration, (3) "Rule Name" field in the Access Control configuration, (4) "Service Name" in…
ModificadaAlta (8.1)1.0%—Opensuse Yast2-printer15/3/201917/6/2026
In yast2-printer up to and including version 4.0.2 the SMB printer settings don't escape characters in passwords properly. If a password with backticks or simliar characters is supplied this allows for executing code as root. This requires tricking root to enter such a password in yast.
ModificadaMedia (6.5)1.1%—Printeron17/12/201817/6/2026
PrinterOn Enterprise 4.1.4 allows Arbitrary File Deletion.
ModificadaAlta (8.8)1.1%—Dell 2335dn Engine FirmwareDell 2335dn Network FirmwareDell 2335dn Printer Firmware23/8/201817/6/2026
On Dell 2335dn printers with Printer Firmware Version 2.70.05.02, Engine Firmware Version 1.10.65, and Network Firmware Version V4.02.15(2335dn MFP) 11-22-2010, the admin interface allows an authenticated attacker to retrieve the configured SMTP or LDAP password by viewing the HTML source code of the Email Settings…
ModificadaAlta (7)0.26%—Printeron17/5/201817/6/2026
PrinterOn Enterprise 4.1.3 stores the Active Directory bind credentials using base64 encoding, which allows local users to obtain credentials for a domain user by reading the cps_config.xml file.
ModificadaMedia (5.4)0.55%—Printeron17/5/201817/6/2026
PrinterOn Enterprise 4.1.3 suffers from multiple authenticated stored XSS vulnerabilities via the (1) department field in the printer configuration, (2) description field in the print server configuration, and (3) username field for authentication to print as guest.
ModificadaCrítica (9.8)3.8%—Node-printer Project Node-printer23/10/201717/6/2026
The printDirect function in lib/printer.js in the node-printer module 0.0.1 and earlier for Node.js allows remote attackers to execute arbitrary commands via unspecified characters in the lpr command.
ModificadaMedia (4.6)0.35%—Lexmark Printer Firmware22/4/201617/6/2026
Lexmark printers with firmware ATL before ATL.021.063, CB before CB.021.063, PP before PP.021.063, and YK before YK.021.063 mishandle Erase Printer Memory and Erase Hard Disk actions, which allows physically proximate attackers to obtain sensitive information via direct read operations on non-volatile memory.
ModificadaCrítica (9.8)3.3%—Lexmark Printer Firmware27/1/201617/6/2026
Race condition in the initialization process on Lexmark printers with firmware ATL before ATL.02.049, CB before CB.02.049, PP before PP.02.049, and YK before YK.02.049 allows remote attackers to bypass authentication by leveraging incorrect detection of the security-jumper status.
ModificadaMedia (6.8)0.65%—Canon Pixma Mg7500 Series Inkjet Printer11/9/201517/6/2026
Cross-site request forgery (CSRF) vulnerability in the Remote UI on Canon PIXMA MG7500 printers allows remote attackers to hijack the authentication of administrators.
ModificadaAlta (9)5.3%—HP Laserjet Cm3530 Multifunction Printer Firmware4/11/201417/6/2026
Unspecified vulnerability on the HP LaserJet CM3530 Multifunction Printer CC519A and CC520A with firmware before 53.236.2 allows remote attackers to obtain sensitive information, modify data, or cause a denial of service via unknown vectors.
ModificadaAlta (7.5)6.9%—HP Sprinter10/10/201417/6/2026
Unspecified vulnerability in HP Sprinter 12.01 allows remote attackers to execute arbitrary code via unknown vectors, aka ZDI-CAN-2344.
ModificadaAlta (7.5)6.9%—HP Sprinter10/10/201417/6/2026
Unspecified vulnerability in HP Sprinter 12.01 allows remote attackers to execute arbitrary code via unknown vectors, aka ZDI-CAN-2342.
ModificadaAlta (7.5)6.9%—HP Sprinter10/10/201417/6/2026
Unspecified vulnerability in HP Sprinter 12.01 allows remote attackers to execute arbitrary code via unknown vectors, aka ZDI-CAN-2336.
ModificadaAlta (7.5)6.9%—HP Sprinter10/10/201417/6/2026
Unspecified vulnerability in HP Sprinter 12.01 allows remote attackers to execute arbitrary code via unknown vectors, aka ZDI-CAN-2343.
ModificadaMedia (5)5.9%—HP Color Laserjet Cm1312nfi Multifunction PrinterHP Color Laserjet Cm2320n Multifunction PrinterHP Color Laserjet Cp1515HP Color Laserjet Cp1518+2117/12/201317/6/2026
Unspecified vulnerability on HP LaserJet M1522n and M2727; LaserJet Pro 100, 300, 400, CM1415fnw, CP1*, M121*, M1536dnf, and P1*; Color LaserJet CM* and CP*; and TopShot LaserJet Pro M275 printers allows remote attackers to cause a denial of service via unknown vectors.
ModificadaAlta (7.8)4.1%—HP Laserjet PRO Cp1025nw FirmwareHP Laserjet PRO M1214nfh MFP FirmwareHP Laserjet PRO P1606dn FirmwareHP Laserjet PRO M1216nfh Multifunction Printer Firmware+55/8/201316/6/2026
Unspecified vulnerability on the HP LaserJet Pro P1102w, P1606dn, M1212nf MFP, M1213nf MFP, M1214nfh MFP, M1216nfh MFP, M1217nfw MFP, M1218nfs MFP, and CP1025nw with firmware before 2013-07-26 20130703 allows remote attackers to modify data via unknown vectors.
ModificadaMedia (5)16%—Canon Mg3100 PrinterCanon Mg5300 PrinterCanon Mg6100 PrinterCanon Mp340 Printer+521/6/201316/6/2026
The Canon MG3100, MG5300, MG6100, MP495, MX340, MX870, MX890, MX920, and MX922 printers allow remote attackers to cause a denial of service (device hang) via a crafted LAN_TXT24 parameter to English/pages_MacUS/cgi_lan.cgi followed by a direct request to English/pages_MacUS/lan_set_content.html. NOTE: the vendor has…
ModificadaBaja (2.1)2.8%—Canon Mg3100 PrinterCanon Mg5300 PrinterCanon Mg6100 PrinterCanon Mp340 Printer+521/6/201316/6/2026
English/pages_MacUS/wls_set_content.html on the Canon MG3100, MG5300, MG6100, MP495, MX340, MX870, MX890, MX920, and MX922 printers shows the Wi-Fi PSK passphrase in cleartext, which allows physically proximate attackers to obtain sensitive information by reading the screen of an unattended workstation.
ModificadaAlta (7.5)2.0%—Canon Mg3100 PrinterCanon Mg5300 PrinterCanon Mg6100 PrinterCanon Mp340 Printer+521/6/201316/6/2026
The default configuration of the administrative interface on the Canon MG3100, MG5300, MG6100, MP495, MX340, MX870, MX890, MX920, and MX922 printers does not require authentication, which allows remote attackers to modify the configuration by visiting the Advanced page. NOTE: the vendor has apparently responded by…
ModificadaAlta (8.8)2.5%—HP Hotspot Laserjet PRO M1218nfs MFPHP Laserjet PRO M1212nf MFPHP Laserjet PRO M1213nf MFPHP Laserjet PRO M1214nfh MFP+169/3/201316/6/2026
Unspecified vulnerability on the HP LaserJet Pro M1212nf, M1213nf, M1214nfh, M1216nfh, M1217nfw, and M1219nf, and HotSpot LaserJet Pro M1218nfs, with firmware before 20130211; LaserJet Pro CP1025nw with firmware before 20130212; and LaserJet Pro P1102w and P1606dn with firmware before 20130213 allows remote attackers…
ModificadaAlta (7.5)8.0%—Samsung Printer Firmware28/11/201216/6/2026
The Samsung printer firmware before 20121031 has a hardcoded read-write SNMP community, which makes it easier for remote attackers to obtain administrative access via an SNMP request.