Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2991▼ 71 respecto a la semana anterior
Críticas / altas1367▲ 28 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)458▼ 52 respecto a la semana anterior
–

21 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaAlta (7.5)0.64%—Docuform Managed Print Service ClientAI11/5/202617/6/2026
docuFORM Managed Print Service Client 11.11c is vulnerable to a directory traversal allowing attackers to read arbitrary files via crafted url.
AplazadaMedia (6.1)0.24%—Docuform Managed Print Service ClientAI11/5/202617/6/2026
docuFORM Managed Print Service Client 11.11c is vulnerable to a reflected cross site scripting attack via the login page of the application.
AplazadaMedia (6.3)0.27%—Docuform Managed Print Service ClientAI11/5/202617/6/2026
docuFORM Managed Print Service Client 11.11c is vulnerable to arbitrary file upload via pmupdate.php.
AplazadaMedia (5.4)0.22%—Docuform Managed Print Service ClientAI11/5/202617/6/2026
docuFORM Managed Print Service Client 11.11c is vulnerable to a session fixation attack via the login page of the application.
AplazadaAlta (7.3)0.29%—Gmbh Mecury Managed Print ServicesAI11/5/202617/6/2026
A reflected cross-site scripted (XSS) vulnerability in the dfm-menu_orderopt.php component of GmbH Mecury Managed Print Services (docuForm) v11.11c allows attackers to execute arbitrary Javascript in the context of a user's browser via injecting a crafted payload into an unfiltered variable value.
AplazadaAlta (7.3)0.29%—Gmbh Mercury Managed Print ServicesAIGmbh DocuformAI11/5/202617/6/2026
A reflected cross-site scripted (XSS) vulnerability in the dfm-menu_markeralerts.php component of GmbH Mecury Managed Print Services (docuForm) v11.11c allows attackers to execute arbitrary Javascript in the context of a user's browser via injecting a crafted payload into an unfiltered variable value.
AplazadaAlta (7.3)0.29%—Gmbh Mecury Managed Print ServicesAI11/5/202617/6/2026
A reflected cross-site scripted (XSS) vulnerability in the acc-menu_pricess.php component of GmbH Mecury Managed Print Services (docuForm) v11.11c allows attackers to execute arbitrary Javascript in the context of a user's browser via injecting a crafted payload into an unfiltered variable value.
AplazadaAlta (7.3)0.29%—Gmbh Mercury Managed Print ServicesAI11/5/202617/6/2026
A reflected cross-site scripted (XSS) vulnerability in the dfm-menu_alerts.php component of GmbH Mecury Managed Print Services (docuForm) v11.11c allows attackers to execute arbitrary Javascript in the context of a user's browser via injecting a crafted payload into an unfiltered variable value.
AplazadaMedia (6.1)0.24%—Gmbh Mecury Managed Print ServicesAI11/5/202617/6/2026
A reflected cross-site scripted (XSS) vulnerability in the acc-menu_billings.php component of GmbH Mecury Managed Print Services (docuForm) v11.11c allows attackers to execute arbitrary Javascript in the context of a user's browser via injecting a crafted payload into an unfiltered variable value.
AplazadaMedia (6.1)0.24%—Gmbh Mecury Managed Print ServicesAI11/5/202617/6/2026
A reflected cross-site scripted (XSS) vulnerability in the dfm-menu_departments.php component of GmbH Mecury Managed Print Services (docuForm) v11.11c allows attackers to execute arbitrary Javascript in the context of a user's browser via injecting a crafted payload into an unfiltered variable value.
AplazadaMedia (6.1)0.24%—Gmbh Mecury Managed Print ServicesAI11/5/202617/6/2026
A reflected cross-site scripted (XSS) vulnerability in the dfm-menu_maintenance.php component of GmbH Mecury Managed Print Services (docuForm) v11.11c allows attackers to execute arbitrary Javascript in the context of a user's browser via injecting a crafted payload into an unfiltered variable value.
AplazadaMedia (6.1)0.24%—Gmbh Mecury Managed Print ServicesAIDocuformAI11/5/202617/6/2026
A reflected cross-site scripted (XSS) vulnerability in the acc-menu_papers.php component of GmbH Mecury Managed Print Services (docuForm) v11.11c allows attackers to execute arbitrary Javascript in the context of a user's browser via injecting a crafted payload into an unfiltered variable value.
AplazadaMedia (6.1)0.24%—Gmbh Mecury Managed Print ServicesAIGmbh DocuformAI11/5/202617/6/2026
A reflected cross-site scripted (XSS) vulnerability in the dfm-menu_coveragealerts.php component of GmbH Mecury Managed Print Services (docuForm) v11.11c allows attackers to execute arbitrary Javascript in the context of a user's browser via injecting a crafted payload into an unfiltered variable value.
AplazadaMedia (6.1)0.24%—Gmbh Mecury Managed Print ServicesAI11/5/202617/6/2026
A reflected cross-site scripted (XSS) vulnerability in the dfm-menu_firmware.php component of GmbH Mecury Managed Print Services (docuForm) v11.11c allows attackers to execute arbitrary Javascript in the context of a user's browser via injecting a crafted payload into an unfiltered variable value.
AnalizadaMedia (6.9)0.14%—HP Samsung Print Service Plugin6/5/202617/6/2026
Samsung Print Service Plugin for Android is potentially vulnerable to information disclosure when using an outdated version of the application via mobile devices. HP is releasing updates to mitigate these potential vulnerabilities.
AplazadaCrítica (9.8)0.74%—SAP Print ServiceAI14/10/202517/6/2026
SAP Print Service (SAPSprint) performs insufficient validation of path information provided by users. An unauthenticated attacker could traverse to the parent directory and over-write system files causing high impact on confidentiality integrity and availability of the application.
ModificadaMedia (5.9)1.3%—Ecisolutions Printanista Managed Print Service15/9/202217/6/2026
The login form /Login in ECi Printanista Hub (formerly FMAudit Printscout) before 5.5.2 (July 2023) performs expensive RSA key-generation operations, which allows attackers to cause a denial of service (DoS) by requesting that form repeatedly.
ModificadaAlta (8.8)1.4%—Printeron Central Print Services29/7/201917/6/2026
An issue was discovered in PrinterOn Central Print Services (CPS) through 4.1.4. A user without valid credentials can bypass the authentication process, obtaining a valid session cookie with guest/pseudo-guest level privileges. This cookie can then be further used to perform other attacks.
ModificadaMedia (5.3)1.7%—Printeron Central Print Services29/7/201917/6/2026
An issue was discovered in PrinterOn Central Print Services (CPS) through 4.1.4. An unauthenticated attacker can view details about the printers associated with CPS via a crafted HTTP GET request.
ModificadaAlta (8.8)1.7%—Printeron Central Print Services20/7/201917/6/2026
An issue was discovered in PrinterOn Central Print Services (CPS) through 4.1.4. The core components that create and launch a print job do not perform complete verification of the session cookie that is supplied to them. As a result, an attacker with guest/pseudo-guest level permissions can bypass the session checks…
ModificadaMedia (6.5)1.1%—Hitachi EUR Print ServiceHitachi EUR Print Service FOR ILFHitachi EUR ProfessionalHitachi EUR Viewer22/5/200616/6/2026
SQL injection vulnerability in Hitachi EUR Professional Edition, EUR Viewer, EUR Print Service, and EUR Print Service for ILF allows remote authenticated users to execute arbitrary SQL commands via unknown attack vectors.