Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2838▼ 146 respecto a la semana anterior
Críticas / altas1377▲ 68 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)255▼ 268 respecto a la semana anterior
11 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Pendiente de análisis | Alta (7.5) | 0.46% | — | HP DeskjetAI | 6/7/2026 | 31/8/2026 | Certain HP DeskJet All-in-One printers may be potentially vulnerable to information disclosure that allows an unauthenticated attacker to access sensitive information through exposed APIs. | |
| Pendiente de análisis | Alta (8.7) | 0.29% | — | HP DeskjetAI | 15/4/2026 | 17/6/2026 | Certain HP DeskJet All in One devices may be vulnerable to remote code execution caused by a buffer overflow when specially crafted Web Services for Devices (WSD) scan requests are improperly validated and handled by the MFP. WSD Scan is a Microsoft Windows–based network scanning protocol that allows a PC to discover… | |
| Modificada | Crítica (9) | 1.0% | — | HP Deskjet 2540 A9u23b Firmware | 6/2/2023 | 17/6/2026 | **UNSUPPORTED WHEN ASSIGNED** Cross Site Scripting (XSS) in HP Deskjet 2540 series printer Firmware Version CEP1FN1418BR and Product Model Number A9U23B allows authenticated attacker to inject their own script into the page via HTTP configuration page. NOTE: This vulnerability only affects products that are no longer… | |
| Modificada | Crítica (9.8) | 1.5% | — | HP Color Laserjet Cm4540 MFP Cc419a FirmwareHP Color Laserjet Cm4540 MFP Cc420a FirmwareHP Color Laserjet Cm4540 MFP Cc421a FirmwareHP Color Laserjet Cm5525 MFP Ce707a Firmware+2696 | 12/12/2022 | 17/6/2026 | Certain HP Print products and Digital Sending products may be vulnerable to potential remote code execution and buffer overflow with use of Link-Local Multicast Name Resolution or LLMNR. | |
| Modificada | Alta (8.8) | 2.3% | — | HP Color Laserjet Cm4540 MFP FirmwareHP Color Laserjet Enterprise Flow MFP M880z FirmwareHP Color Laserjet Managed Flow MFP M880zm FirmwareHP Color Laserjet Enterprise M455 Firmware+211 | 9/11/2021 | 17/6/2026 | During installation with certain driver software or application packages an arbitrary code execution could occur. | |
| Modificada | Alta (7.5) | 15% | — | UI Unifi ControllerW1.fi HostapdAsus Rt-n11Broadcom Adsl+213 | 8/6/2020 | 17/6/2026 | The Open Connectivity Foundation UPnP specification before 2020-04-17 does not forbid the acceptance of a subscription request with a delivery URL on a different network segment than the fully qualified event-subscription URL, aka the CallStranger issue. | |
| Modificada | Media (6.5) | 1.5% | — | HP Envy 5000 M2u85a FirmwareHP Envy 5000 M2u85b FirmwareHP Envy 5000 M2u91a FirmwareHP Envy 5000 M2u94b Firmware+4 | 16/3/2020 | 17/6/2026 | A potential security vulnerability has been identified for certain HP Printers and All-in-Ones that would allow bypassing account lockout. | |
| Modificada | Alta (8.1) | 0.56% | — | HP Deskjet 3630 F5s43a FirmwareHP Deskjet 3630 F5s57a FirmwareHP Deskjet 3630 K4t93a FirmwareHP Deskjet 3630 K4t99c Firmware+4 | 9/1/2020 | 17/6/2026 | HP DeskJet 3630 All-in-One Printers models F5S43A - F5S57A, K4T93A - K4T99C, K4U00B - K4U03B, and V3F21A - V3F22A (firmware version SWP1FN1912BR or higher) have a Cross-Site Request Forgery (CSRF) vulnerability that could lead to a denial of service (DOS) or device misconfiguration. | |
| Modificada | Media (4.8) | 0.65% | — | HP Deskjet 2600 4uj28b FirmwareHP Deskjet 2600 V1n01a FirmwareHP Deskjet 2600 V1n08a FirmwareHP Deskjet 2600 Y5h60a Firmware+48 | 9/1/2020 | 17/6/2026 | A potential security vulnerability has been identified with certain HP InkJet printers. The vulnerability could be exploited to allow cross-site scripting (XSS). Affected products and versions include: HP DeskJet 2600 All-in-One Printer series model numbers 4UJ28B, V1N01A - V1N08A, Y5H60A - Y5H80A; HP DeskJet Ink… | |
| Modificada | Alta (8.1) | 0.56% | — | HP Deskjet 3630 F5s43a FirmwareHP Deskjet 3630 F5s57a FirmwareHP Deskjet 3630 K4t93a FirmwareHP Deskjet 3630 K4t99c Firmware+4 | 9/1/2020 | 17/6/2026 | Certain HP DeskJet 3630 All-in-One Printers models F5S43A - F5S57A, K4T93A - K4T99C, K4U00B - K4U03B, and V3F21A - V3F22A (firmware version SWP1FN1912BR or higher) have a Cross-Site Request Forgery (CSRF) vulnerability that could lead to a denial of service (DOS) or device misconfiguration. | |
| Modificada | Media (4.3) | 1.6% | — | HP Deskjet 6840 | 17/4/2009 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in refresh_rate.htm in the web interface on the HP Deskjet 6840 printer with firmware XF1M131A allows remote attackers to inject arbitrary web script or HTML via the POST request body. |