Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2991▼ 71 respecto a la semana anterior
Críticas / altas1367▲ 28 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)458▼ 52 respecto a la semana anterior
–

89 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaMedia (6.9)0.58%—Lexmark Postscript InterpreterAI3/2/202617/6/2026
An out-of-bounds read vulnerability has been identified in the Postscript interpreter in various Lexmark devices. This vulnerability can be leveraged by an attacker to execute arbitrary code as an unprivileged user.
AplazadaMedia (6.9)0.54%—Lexmark Postscript InterpreterAI3/2/202617/6/2026
A type confusion vulnerability has been identified in the Postscript interpreter in various Lexmark devices. This vulnerability can be leveraged by an attacker to execute arbitrary code as an unprivileged user.
AplazadaMedia (6.9)0.54%—Lexmark Postscript InterpreterAI3/2/202617/6/2026
A heap-based buffer overflow vulnerability has been identified in the Postscript interpreter in various Lexmark devices. This vulnerability can be leveraged by an attacker to execute arbitrary code as an unprivileged user.
AplazadaCrítica (9.3)0.58%—Lexmark Embedded Solutions FrameworkAI3/2/202617/6/2026
An untrusted search path vulnerability has been identified in the Embedded Solutions Framework in various Lexmark devices. This vulnerability can be leveraged by an attacker to execute arbitrary code.
AplazadaAlta (8.8)0.69%—Lexmark Embedded Solutions FrameworkAI3/2/202617/6/2026
A relative path traversal vulnerability has been identified in the Embedded Solutions Framework in various Lexmark devices. This vulnerability can be leveraged by an attacker to execute arbitrary code as an unprivileged user.
AplazadaMedia (6.9)0.33%—Lexmark Embedded WEB ServerAI9/9/202517/6/2026
A Server-Side Request Forgery (SSRF) vulnerability has been identified in the embedded web server in various Lexmark devices. This vulnerability can be leveraged by an attacker to force the device to send an arbitrary HTTP request to a third-party server. Successful exploitation of this vulnerability can lead to…
AplazadaAlta (8.5)0.31%—Lexmark Cloud ServicesAI19/8/202517/6/2026
A missing authorization vulnerability in Lexmark Cloud Services badge management allows attacker to reassign badges within their organization
AplazadaAlta (8.2)0.15%—Lexmark Printer DriversAI19/8/202517/6/2026
Improper Restriction of XML External Entity Reference in various Lexmark printer drivers for Windows allows attacker to disclose sensitive information to an arbitrary URL.
AplazadaCrítica (9.1)0.36%—Lexmark Mx6500AI19/2/20255/7/2026
Lexmark MX6500 LW75.JD.P296 and previous devices have Incorrect Access Control via the access control settings.
AplazadaMedia (6.1)0.27%—Lexmark ProductsAI19/2/202517/6/2026
Certain Lexmark products through 2020-05-25 allow XSS which allows an attacker to obtain session credentials and other sensitive information.
AplazadaAlta (8.1)0.18%—Lexmark DevicesAI19/2/202517/6/2026
Various Lexmark devices have CSRF that allows an attacker to modify the configuration of the device.
AplazadaAlta (7.3)0.43%—Lexmark International XCAILexmark International CSAIMitel CXAI13/2/202517/6/2026
Integer Overflow or Wraparound vulnerability in Lexmark International CX, XC, CS, et. Al. (Postscript interpreter modules) allows Forced Integer Overflow.The vulnerability can be leveraged by an attacker to execute arbitrary code as an unprivileged user.
AplazadaAlta (7.3)0.45%—Lexmark CXAILexmark XCAILexmark CSAI13/2/202517/6/2026
: Access of Resource Using Incompatible Type ('Type Confusion') vulnerability in Lexmark International CX, XC, CS, et. Al. (Postscript interpreter modules) allows Resource Injection.This issue affects CX, XC, CS, et. Al.: from 001.001:0 through 081.231, from *.*.P001 through *.*.P233, from *.*.P001 through *.*.P759,…
AplazadaAlta (7.3)0.46%—Lexmark Postscript InterpreterAI13/2/202517/6/2026
A heap-based memory vulnerability has been identified in the Postscript interpreter in various Lexmark devices. The vulnerability can be leveraged by an attacker to execute arbitrary code.
AplazadaAlta (7.3)0.46%—Lexmark Postscript InterpreterAI13/2/202517/6/2026
A type confusion vulnerability has been identified in the Postscript interpreter in various Lexmark devices. The vulnerability can be leveraged by an attacker to execute arbitrary code.
AplazadaCrítica (9.3)0.25%—Lexmark Print Management ClientAI11/2/202517/6/2026
A Reliance on Untrusted Inputs in a Security Decision vulnerability has been identified in the Lexmark Print Management Client.
AplazadaAlta (8.6)0.42%—Lexmark WEB ServicesAI21/1/202517/6/2026
A Server-Side Request Forgery (SSRF) vulnerability has been identified in the Web Services feature of newer Lexmark devices.
AplazadaAlta (8.8)0.61%—Lexmark IPPAI18/1/202517/6/2026
A buffer overflow vulnerability has been identified in the Internet Printing Protocol (IPP) in various Lexmark devices. The vulnerability can be leveraged by an attacker to execute arbitrary code.
AplazadaMedia (4.3)0.27%—LexmarkAI17/1/202517/6/2026
A new feature to prevent Firmware downgrades was recently added to some Lexmark products. A method to override this downgrade protection has been identified.
AplazadaCrítica (9.1)0.97%—LexmarkAI28/2/202417/6/2026
The SE menu contains information used by Lexmark to diagnose device errors. A vulnerability in one of the SE menu routines can be leveraged by an attacker to execute arbitrary code.
AplazadaCrítica (9)0.77%—Lexmark Postscript InterpreterAI28/2/202417/6/2026
A memory corruption vulnerability has been identified in PostScript interpreter in various Lexmark devices. The vulnerability can be leveraged by an attacker to execute arbitrary code.
AplazadaCrítica (9)0.77%—Lexmark Postscript InterpreterAI28/2/202417/6/2026
A heap corruption vulnerability has been identified in PostScript interpreter in various Lexmark devices. The vulnerability can be leveraged by an attacker to execute arbitrary code.
AplazadaCrítica (9)0.77%—Lexmark Postscript InterpreterAI28/2/202417/6/2026
A buffer overflow vulnerability has been identified in PostScript interpreter in various Lexmark devices. The vulnerability can be leveraged by an attacker to execute arbitrary code.
ModificadaAlta (7.5)0.54%—Lexmark C2132 FirmwareLexmark Cs310 FirmwareLexmark Cs317 FirmwareLexmark Cs410 Firmware+781/9/202317/6/2026
Certain Lexmark devices (such as CS310) before 2023-08-25 allow XXE attacks, leading to information disclosure. The fixed firmware version is LW80.*.P246, i.e., '*' indicates that the full version specification varies across product model family, but firmware level P246 (or higher) is required to remediate the…
ModificadaCrítica (9.8)0.71%—Lexmark Cxtpc FirmwareLexmark Cstpc FirmwareLexmark Mxtct FirmwareLexmark Mxtpm Firmware+2210/4/202317/6/2026
Certain Lexmark devices through 2023-02-19 mishandle Input Validation (issue 4 of 4).