Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2738▼ 488 respecto a la semana anterior
Críticas / altas1301▼ 189 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)229▼ 273 respecto a la semana anterior
–

19 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaMedia (5.3)0.45%—Rexrainbow Phaser3-rex-notesAI24/8/202624/8/2026
A vulnerability was identified in rexrainbow phaser3-rex-notes up to 1.80.17. This vulnerability affects the function SetValue of the file plugins/utils/object/SetValue.js of the component BehaviorTree Blackboard Data Interface. Such manipulation of the argument key leads to improperly controlled modification of…
ModificadaCrítica (9.8)1.4%—Xerox Phaser 4622 Firmware15/2/202217/6/2026
Xerox Phaser 4622 v35.013.01.000 was discovered to contain a buffer overflow in the function sub_3226AC via the TIMEZONE variable. This vulnerability allows attackers to cause a Denial of Service (DoS) via crafted overflow data.
ModificadaCrítica (9.8)2.2%—Xerox Phaser 6510 FirmwareXerox Workcentre 6515 FirmwareXerox Versalink B400 FirmwareXerox Versalink B405 Firmware+2029/3/202117/6/2026
Xerox Phaser 6510 before 64.65.51 and 64.59.11 (Bridge), WorkCentre 6515 before 65.65.51 and 65.59.11 (Bridge), VersaLink B400 before 37.65.51 and 37.59.01 (Bridge), B405 before 38.65.51 and 38.59.01 (Bridge), B600/B610 before 32.65.51 and 32.59.01 (Bridge), B605/B615 before 33.65.51 and 33.59.01 (Bridge), B7025/30/35…
ModificadaCrítica (9.8)2.6%—Xerox Phaser 6510 FirmwareXerox Workcentre 6515 FirmwareXerox Versalink B400 FirmwareXerox Versalink B405 Firmware+2029/3/202117/6/2026
Xerox Phaser 6510 before 64.65.51 and 64.59.11 (Bridge), WorkCentre 6515 before 65.65.51 and 65.59.11 (Bridge), VersaLink B400 before 37.65.51 and 37.59.01 (Bridge), B405 before 38.65.51 and 38.59.01 (Bridge), B600/B610 before 32.65.51 and 32.59.01 (Bridge), B605/B615 before 33.65.51 and 33.59.01 (Bridge), B7025/30/35…
ModificadaCrítica (9.8)1.9%—Xerox Phaser 6510 FirmwareXerox Workcentre 6515 FirmwareXerox Versalink B400 FirmwareXerox Versalink B405 Firmware+1929/3/202117/6/2026
Xerox Phaser 6510 before 64.61.23 and 64.59.11 (Bridge), WorkCentre 6515 before 65.61.23 and 65.59.11 (Bridge), VersaLink B400 before 37.61.23 and 37.59.01 (Bridge), B405 before 38.61.23 and 38.59.01 (Bridge), B600/B610 before 32.61.23 and 32.59.01 (Bridge), B605/B615 before 33.61.23 and 33.59.01 (Bridge), B7025/30/35…
ModificadaCrítica (9.8)3.0%—Xerox Phaser 3320 Firmware13/3/202017/6/2026
Some Xerox printers (such as the Phaser 3320 V53.006.16.000) were affected by a buffer overflow vulnerability in the Authentication Cookie of the web application that would allow an attacker to execute arbitrary code on the device.
ModificadaCrítica (9.8)2.8%—Xerox Phaser 3320 Firmware13/3/202017/6/2026
Some Xerox printers (such as the Phaser 3320 V53.006.16.000) were affected by one or more stack-based buffer overflow vulnerabilities in the Google Cloud Print implementation that would allow an unauthenticated attacker to execute arbitrary code on the device. This was caused by an insecure handling of the register…
ModificadaMedia (6.5)0.41%—Xerox Phaser 3320 Firmware13/3/202017/6/2026
Some Xerox printers (such as the Phaser 3320 V53.006.16.000) did not implement any mechanism to avoid CSRF attacks. Successful exploitation of this vulnerability can lead to the takeover of a local account on the device.
ModificadaCrítica (9.8)2.7%—Xerox Phaser 3320 Firmware13/3/202017/6/2026
Some Xerox printers (such as the Phaser 3320 V53.006.16.000) were affected by a buffer overflow vulnerability in the Content-Type HTTP Header of the web application that would allow an attacker to execute arbitrary code on the device.
ModificadaCrítica (9.8)2.8%—Xerox Phaser 3320 Firmware13/3/202017/6/2026
Some Xerox printers (such as the Phaser 3320 V53.006.16.000) were affected by a buffer overflow vulnerability in the attributes parser of the IPP service. This would allow an unauthenticated attacker to cause a Denial of Service (DoS) and potentially execute arbitrary code on the device.
ModificadaMedia (6.1)1.0%—Xerox Phaser 3320 Firmware13/3/202017/6/2026
Multiple Stored XSS vulnerabilities were found in the Xerox Web Application, used by the Phaser 3320 V53.006.16.000 and other printers. Successful exploitation of this vulnerability can lead to session hijacking of the administrator in the web application or the execution of unwanted actions.
ModificadaAlta (7.5)1.0%—Xerox Phaser 3320 Firmware13/3/202017/6/2026
Some Xerox printers (such as the Phaser 3320 V53.006.16.000) did not implement account lockout. Local account credentials may be extracted from the device via brute force guessing attacks.
ModificadaCrítica (9.8)2.8%—Xerox Phaser 3320 Firmware13/3/202017/6/2026
Some Xerox printers (such as the Phaser 3320 V53.006.16.000) were affected by a buffer overflow vulnerability in the request parser of the IPP service. This would allow an unauthenticated attacker to cause a Denial of Service (DoS) and potentially execute arbitrary code on the device.
ModificadaAlta (7.8)36%💥 ExploitXerox Phaser10/8/200816/6/2026
The Xerox Phaser 8400 allows remote attackers to cause a denial of service (reboot) via an empty UDP packet to port 1900.
ModificadaMedia (6.4)1.9%—Dell 3000cnDell 3010cnDell 3100cnDell 3110cn+1525/8/200616/6/2026
The embedded HTTP server in Fuji Xerox Printing Systems (FXPS) print engine, as used in products including (1) Dell 3000cn through 5110cn and (2) Fuji Xerox DocuPrint firmware before 20060628 and Network Option Card firmware before 5.13, does not properly perform authentication for HTTP requests, which allows remote…
ModificadaAlta (7.5)2.2%—Dell 3000cnDell 3010cnDell 3100cnDell 3110cn+1525/8/200616/6/2026
Fuji Xerox Printing Systems (FXPS) print engine, as used in products including (1) Dell 3000cn through 5110cn and (2) Fuji Xerox DocuPrint firmware before 20060628 and Network Option Card firmware before 5.13, allows remote attackers to use the FTP printing interface as a proxy ("FTP bounce") by using arbitrary PORT…
ModificadaAlta (10)73%💥 ExploitSendmailHP Alphaserver SCGentoo LinuxHp-ux+57/3/200316/6/2026
Buffer overflow in Sendmail 5.79 to 8.12.7 allows remote attackers to execute arbitrary code via certain formatted address fields, related to sender and recipient header comments as processed by the crackaddr function of headers.c.
ModificadaMedia (6.4)4.9%💥 ExploitTEK Phaserlink27/6/200116/6/2026
Tektronix PhaserLink 850 does not require authentication for access to configuration pages such as _ncl_subjects.shtml and _ncl_items.shtml, which allows remote attackers to modify configuration information and cause a denial of service by accessing the pages.
ModificadaAlta (10)8.1%💥 ExploitTEK Phaser Network Printer 740TEK Phaser Network Printer 750TEK Phaser Network Printer 750dpTEK Phaser Network Printer 840+116/11/199916/6/2026
Web server in Tektronix PhaserLink Printer 840.0 and earlier allows a remote attacker to gain administrator access by directly calling undocumented URLs such as ncl_items.html and ncl_subjects.html.
Orbitaley — Vulnerabilidades