Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3059▲ 556 respecto a la semana anterior
Críticas / altas1460▲ 282 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▲ 175 respecto a la semana anterior
13 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Pendiente de análisis | Alta (8.9) | 0.43% | — | HP WEB JetadminAI | 17/8/2026 | 31/8/2026 | HP has identified a potential vulnerability in HP Web Jetadmin (WJA) that may allow an unauthenticated actor to read from or write to arbitrary files through a DLL hijacking mechanism. | |
| Modificada | Alta (7.5) | 3.5% | — | HP WEB Jetadmin | 23/1/2018 | 17/6/2026 | A potential security vulnerability has been identified with HP Web Jetadmin before 10.4 SR2. This vulnerability could potentially be exploited to create a denial of service. | |
| Modificada | Media (4.3) | 1.6% | — | HP WEB Jetadmin | 13/6/2012 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in HP Web Jetadmin 8.x allow remote attackers to inject arbitrary web script or HTML via unspecified vectors. | |
| Modificada | Media (4.3) | 0.28% | — | HP WEB Jetadmin | 1/3/2011 | 16/6/2026 | Unspecified vulnerability in HP Web Jetadmin 10.2 Service Release 3 and 4 allows local users to bypass intended access restrictions via unknown vectors. | |
| Modificada | Alta (9) | 1.8% | — | HP WEB Jetadmin | 14/1/2010 | 16/6/2026 | Multiple unspecified vulnerabilities in HP Web Jetadmin 10.2, when a remote SQL server is used, allow remote attackers to obtain access to data or cause a denial of service, possibly by leveraging authentication and encryption weaknesses on the SQL server. | |
| Modificada | Media (5) | 1.2% | — | HP WEB JetadminAI | 31/12/2004 | 16/6/2026 | HP Web Jetadmin 7.5.2546 allows remote attackers to cause a denial of service (crash) via a malformed request, possibly due to a stricmp() error from an invalid use of the "$" character. | |
| Modificada | Media (5) | 30% | — | HP WEB Jetadmin | 24/3/2004 | 16/6/2026 | devices_update_printer_fw_upload.hts in HP Web JetAdmin 7.5.2546, when no password is set, allows remote attackers to upload arbitrary files to the printer directory. | |
| Modificada | Baja (2.1) | 87% | — | HP WEB Jetadmin | 24/3/2004 | 16/6/2026 | Directory traversal vulnerability in setinfo.hts in HP Web Jetadmin 7.5.2546 allows remote authenticated attackers to read arbitrary files via a .. (dot dot) in the setinclude parameter. | |
| Modificada | Alta (7.5) | 2.4% | — | HP Jetadmin | 31/8/2001 | 16/6/2026 | The JetAdmin web interface for HP JetDirect does not set a password for the telnet interface when the admin password is changed, which allows remote attackers to gain access to the printer. | |
| Modificada | Media (6.4) | 2.5% | — | HP Jetadmin | 31/8/2001 | 16/6/2026 | HP LaserJet, and possibly other JetDirect devices, resets the admin password when the device is turned off, which could allow remote attackers to access the device without the password. | |
| Modificada | Media (5) | 8.2% | — | HP Jetadmin | 24/5/2000 | 16/6/2026 | HP Web JetAdmin 6.0 allows remote attackers to cause a denial of service via a malformed URL to port 8000. | |
| Modificada | Alta (7.5) | 10% | — | HP Jetadmin | 24/5/2000 | 16/6/2026 | The web interface server in HP Web JetAdmin 5.6 allows remote attackers to read arbitrary files via a .. (dot dot) attack. | |
| Modificada | Alta (7.2) | 0.94% | — | HP Jetadmin | 15/7/1998 | 16/6/2026 | HP JetAdmin D.01.09 on Solaris allows local users to change the permissions of arbitrary files via a symlink attack on the /tmp/jetadmin.log file. |