Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas3059▲ 556 respecto a la semana anterior
Críticas / altas1460▲ 282 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▲ 175 respecto a la semana anterior
–

13 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
Pendiente de análisisAlta (8.9)0.43%—HP WEB JetadminAI17/8/202631/8/2026
HP has identified a potential vulnerability in HP Web Jetadmin (WJA) that may allow an unauthenticated actor to read from or write to arbitrary files through a DLL hijacking mechanism.
ModificadaAlta (7.5)3.5%—HP WEB Jetadmin23/1/201817/6/2026
A potential security vulnerability has been identified with HP Web Jetadmin before 10.4 SR2. This vulnerability could potentially be exploited to create a denial of service.
ModificadaMedia (4.3)1.6%—HP WEB Jetadmin13/6/201216/6/2026
Multiple cross-site scripting (XSS) vulnerabilities in HP Web Jetadmin 8.x allow remote attackers to inject arbitrary web script or HTML via unspecified vectors.
ModificadaMedia (4.3)0.28%—HP WEB Jetadmin1/3/201116/6/2026
Unspecified vulnerability in HP Web Jetadmin 10.2 Service Release 3 and 4 allows local users to bypass intended access restrictions via unknown vectors.
ModificadaAlta (9)1.8%—HP WEB Jetadmin14/1/201016/6/2026
Multiple unspecified vulnerabilities in HP Web Jetadmin 10.2, when a remote SQL server is used, allow remote attackers to obtain access to data or cause a denial of service, possibly by leveraging authentication and encryption weaknesses on the SQL server.
ModificadaMedia (5)1.2%—HP WEB JetadminAI31/12/200416/6/2026
HP Web Jetadmin 7.5.2546 allows remote attackers to cause a denial of service (crash) via a malformed request, possibly due to a stricmp() error from an invalid use of the "$" character.
ModificadaMedia (5)30%—HP WEB Jetadmin24/3/200416/6/2026
devices_update_printer_fw_upload.hts in HP Web JetAdmin 7.5.2546, when no password is set, allows remote attackers to upload arbitrary files to the printer directory.
ModificadaBaja (2.1)87%—HP WEB Jetadmin24/3/200416/6/2026
Directory traversal vulnerability in setinfo.hts in HP Web Jetadmin 7.5.2546 allows remote authenticated attackers to read arbitrary files via a .. (dot dot) in the setinclude parameter.
ModificadaAlta (7.5)2.4%—HP Jetadmin31/8/200116/6/2026
The JetAdmin web interface for HP JetDirect does not set a password for the telnet interface when the admin password is changed, which allows remote attackers to gain access to the printer.
ModificadaMedia (6.4)2.5%—HP Jetadmin31/8/200116/6/2026
HP LaserJet, and possibly other JetDirect devices, resets the admin password when the device is turned off, which could allow remote attackers to access the device without the password.
ModificadaMedia (5)8.2%—HP Jetadmin24/5/200016/6/2026
HP Web JetAdmin 6.0 allows remote attackers to cause a denial of service via a malformed URL to port 8000.
ModificadaAlta (7.5)10%—HP Jetadmin24/5/200016/6/2026
The web interface server in HP Web JetAdmin 5.6 allows remote attackers to read arbitrary files via a .. (dot dot) attack.
ModificadaAlta (7.2)0.94%—HP Jetadmin15/7/199816/6/2026
HP JetAdmin D.01.09 on Solaris allows local users to change the permissions of arbitrary files via a symlink attack on the /tmp/jetadmin.log file.