Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2614▼ 473 respecto a la semana anterior
Críticas / altas1270▼ 74 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)243▼ 274 respecto a la semana anterior
37 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Pendiente de análisis | Media (6.9) | 0.38% | — | Papercut MFAIPapercut NGAI | 24/9/2026 | 24/9/2026 | An improper authentication vulnerability in PaperCut MF/NG allows an unauthenticated, remote attacker to trigger report generation. By submitting report generation requests without valid credentials, an attacker can generate reports and gain unauthorized access to sensitive information. | |
| Pendiente de análisis | Alta (7.3) | 0.74% | — | Papercut NGAIPapercut MFAI | 24/9/2026 | 25/9/2026 | An improper limitation of a pathname to a restricted directory (path traversal) vulnerability in the Scan-to-Fax component of PaperCut NG and PaperCut MF allows an authenticated administrator to execute arbitrary commands on the underlying host via crafted fax provider settings. | |
| Pendiente de análisis | Alta (7.5) | 0.31% | — | Papercut NGAIPapercut MFAI | 24/9/2026 | 25/9/2026 | A vulnerability exists in the PaperCut NG/MF platform's device-scripting functionality due to insufficient sanitization and access restrictions within the embedded execution engine. An authenticated user with administrative access to the management interface can supply a malicious script that escapes the runtime… | |
| Analizada | Crítica (9.4) | 61% | ⚠ Explotación activa | Papercut MFPapercut NG | 28/8/2026 | 14/9/2026 | An unsafe dynamic class loading vulnerability exists in the database connection utilities of PaperCut MF and PaperCut NG. The application instantiates database driver classes based on configurable driver names without validating against an allowlist of approved drivers. If an attacker can manipulate system… | |
| Analizada | Alta (8.8) | 85% | ⚠ Explotación activa | Papercut MFPapercut NG | 28/8/2026 | 14/9/2026 | An improper access control vulnerability exists in the web management interface of PaperCut MF and PaperCut NG. Under specific conditions, unauthenticated remote requests targeting administrative functions can trigger backend actions prior to the completion of access validation checks. This allows an unauthenticated… | |
| Pendiente de análisis | Media (6.9) | 0.68% | — | Papercut NGAIPapercut MFAI | 3/8/2026 | 9/9/2026 | PaperCut NG/MF contains an observable timing discrepancy in its authentication component. An unauthenticated remote attacker can exploit this vulnerability to perform username enumeration by measuring response times during login attempts. The system executes a password hash comparison only when a valid account is… | |
| Pendiente de análisis | Media (6.9) | 0.68% | — | Papercut NGAIPapercut MFAI | 3/8/2026 | 9/9/2026 | PaperCut NG/MF does not properly restrict excessive authentication attempts within its login component. An unauthenticated remote attacker can exploit this vulnerability to perform unrestricted brute-force or credential-stuffing attacks without triggering account lockout or rate-limiting mechanisms in some… | |
| Analizada | Media (4.6) | 0.56% | — | Papercut MFPapercut NG | 5/5/2026 | 17/6/2026 | An issue was discovered in the Shared Account Synchronization component of PaperCut MF (version 25.0.4). The application allows administrative users to configure a source path for account data synchronization. Due to a lack of proper path validation and sanitization, an authenticated user with administrative… | |
| Analizada | Media (4.1) | 0.41% | — | Papercut MFPapercut NG | 5/5/2026 | 17/6/2026 | A race condition exists in PaperCut MF when processing badge-swipe data from certain HP multifunction devices. Under specific network conditions involving dropped packets and out-of-order sequence counters, the server may incorrectly process fragmented data chunks. If a sequence reset notification fails to reach the… | |
| Analizada | Baja (2.1) | 0.23% | — | Papercut MFPapercut NG | 31/3/2026 | 17/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in PaperCut NG/MF before 25.0.10 allow authenticated administrator users to inject arbitrary web script or HTML code via different UI fields. This could be used to compromise other admininistrator's sessions or perform unauthorized actions via the administrator's… | |
| Aplazada | Alta (7.7) | 0.11% | — | Papercut Print DeployAIPapercut NGAIPapercut MFAI | 3/9/2025 | 25/9/2026 | PaperCut Print Deploy is an optional component that integrates with PaperCut NG/MF which simplifies printer deployment and management. When the component is deployed to an environment, the customer has an option to configure the system to use a self-signed certificate. If the customer does not fully configure the… | |
| Analizada | Media (6.3) | 0.23% | — | Papercut MFPapercut NG | 10/12/2024 | 17/6/2026 | A reflected cross-site scripting (XSS) vulnerability exists in PaperCut NG/MF. This issue can be used to execute specially created JavaScript payloads in the browser. A user must click on a malicious link for this issue to occur. | |
| Analizada | Alta (7.2) | 1.8% | — | Papercut NG | 22/11/2024 | 17/6/2026 | PaperCut NG print.script.sandboxed Exposed Dangerous Function Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of PaperCut NG. Authentication is required to exploit this vulnerability. The specific flaw exists within the management of… | |
| Analizada | Media (5.5) | 0.24% | — | Papercut MFPapercut NG | 26/9/2024 | 17/6/2026 | An arbitrary file creation vulnerability exists in PaperCut NG/MF that only affects Windows servers with Web Print enabled. This specific flaw exists within the web-print.exe process, which can incorrectly create files that don’t exist when a maliciously formed payload is provided. This can be used to flood disk space… | |
| Modificada | Alta (7.8) | 0.39% | — | Papercut MFPapercut NG | 26/9/2024 | 17/6/2026 | An arbitrary file deletion vulnerability exists in PaperCut NG/MF, specifically affecting Windows servers with Web Print enabled. To exploit this vulnerability, an attacker must first obtain local login access to the Windows Server hosting PaperCut NG/MF and be capable of executing low-privilege code directly on the… | |
| Analizada | Alta (7.8) | 0.41% | — | Papercut MFPapercut NG | 14/5/2024 | 17/6/2026 | An arbitrary file creation vulnerability exists in PaperCut NG/MF that only affects Windows servers with Web Print enabled. This specific flaw exists within the image-handler process, which can incorrectly create files that don’t exist when a maliciously formed payload is provided. This can lead to local privilege… | |
| Analizada | Alta (7.8) | 0.40% | — | Papercut MFPapercut NG | 14/5/2024 | 17/6/2026 | An arbitrary file deletion vulnerability exists in PaperCut NG/MF, specifically affecting Windows servers with Web Print enabled. To exploit this vulnerability, an attacker must first obtain local login access to the Windows Server hosting PaperCut NG/MF and be capable of executing low-privilege code directly on the… | |
| Analizada | Alta (7.2) | 61% | — | Papercut MFPapercut NG | 3/5/2024 | 17/6/2026 | PaperCut NG External User Lookup Code Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of PaperCut NG. Authentication is required to exploit this vulnerability. The specific flaw exists within the External User Lookup… | |
| Analizada | Media (6.5) | 38% | — | Papercut MFPapercut NG | 14/3/2024 | 17/6/2026 | This is a Server-Side Request Forgery (SSRF) vulnerability in the PaperCut NG/MF server-side module that allows an attacker to induce the server-side application to make HTTP requests to an arbitrary domain of the attacker's choosing. | |
| Analizada | Media (6.1) | 61% | — | Papercut MFPapercut NG | 14/3/2024 | 17/6/2026 | This is a reflected cross site scripting vulnerability in the PaperCut NG/MF application server. An attacker can exploit this weakness by crafting a malicious URL that contains a script. When an unsuspecting user clicks on this malicious link, it could potentially lead to limited loss of confidentiality, integrity or… | |
| Analizada | Alta (7.2) | 1.4% | — | Papercut MFPapercut NG | 14/3/2024 | 17/6/2026 | This vulnerability allows an already authenticated admin user to create a malicious payload that could be leveraged for remote code execution on the server hosting the PaperCut NG/MF application server. | |
| Analizada | Alta (7.2) | 1.3% | — | Papercut MFPapercut NG | 14/3/2024 | 17/6/2026 | This vulnerability potentially allows unauthorized write operations which may lead to remote code execution. An attacker must already have authenticated admin access and knowledge of both an internal system identifier and details of another valid user to exploit this. | |
| Analizada | Media (4.8) | 0.45% | — | Papercut MFPapercut NG | 14/3/2024 | 17/6/2026 | This vulnerability potentially allows unauthorized enumeration of information from the embedded device APIs. An attacker must already have existing knowledge of some combination of valid usernames, device names and an internal system key. For such an attack to be successful the system must be in a specific runtime… | |
| Analizada | Crítica (9.8) | 64% | — | Papercut MFPapercut NG | 14/3/2024 | 17/6/2026 | This allows attackers to use a maliciously formed API request to gain access to an API authorization level with elevated privileges. This applies to a small subset of PaperCut NG/MF API calls. | |
| Analizada | Baja (3.1) | 0.55% | — | Papercut MFPapercut NG | 14/3/2024 | 17/6/2026 | This vulnerability potentially allows files on a PaperCut NG/MF server to be exposed using a specifically formed payload against the impacted API endpoint. The attacker must carry out some reconnaissance to gain knowledge of a system token. This CVE only affects Linux and macOS PaperCut NG/MF servers. |