Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2991▼ 71 respecto a la semana anterior
Críticas / altas1367▲ 28 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)458▼ 52 respecto a la semana anterior
21 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (7.5) | 0.64% | — | Docuform Managed Print Service ClientAI | 11/5/2026 | 17/6/2026 | docuFORM Managed Print Service Client 11.11c is vulnerable to a directory traversal allowing attackers to read arbitrary files via crafted url. | |
| Aplazada | Media (6.1) | 0.24% | — | Docuform Managed Print Service ClientAI | 11/5/2026 | 17/6/2026 | docuFORM Managed Print Service Client 11.11c is vulnerable to a reflected cross site scripting attack via the login page of the application. | |
| Aplazada | Media (6.3) | 0.27% | — | Docuform Managed Print Service ClientAI | 11/5/2026 | 17/6/2026 | docuFORM Managed Print Service Client 11.11c is vulnerable to arbitrary file upload via pmupdate.php. | |
| Aplazada | Media (5.4) | 0.22% | — | Docuform Managed Print Service ClientAI | 11/5/2026 | 17/6/2026 | docuFORM Managed Print Service Client 11.11c is vulnerable to a session fixation attack via the login page of the application. | |
| Aplazada | Alta (7.3) | 0.29% | — | Gmbh Mecury Managed Print ServicesAI | 11/5/2026 | 17/6/2026 | A reflected cross-site scripted (XSS) vulnerability in the dfm-menu_orderopt.php component of GmbH Mecury Managed Print Services (docuForm) v11.11c allows attackers to execute arbitrary Javascript in the context of a user's browser via injecting a crafted payload into an unfiltered variable value. | |
| Aplazada | Alta (7.3) | 0.29% | — | Gmbh Mercury Managed Print ServicesAIGmbh DocuformAI | 11/5/2026 | 17/6/2026 | A reflected cross-site scripted (XSS) vulnerability in the dfm-menu_markeralerts.php component of GmbH Mecury Managed Print Services (docuForm) v11.11c allows attackers to execute arbitrary Javascript in the context of a user's browser via injecting a crafted payload into an unfiltered variable value. | |
| Aplazada | Alta (7.3) | 0.29% | — | Gmbh Mecury Managed Print ServicesAI | 11/5/2026 | 17/6/2026 | A reflected cross-site scripted (XSS) vulnerability in the acc-menu_pricess.php component of GmbH Mecury Managed Print Services (docuForm) v11.11c allows attackers to execute arbitrary Javascript in the context of a user's browser via injecting a crafted payload into an unfiltered variable value. | |
| Aplazada | Alta (7.3) | 0.29% | — | Gmbh Mercury Managed Print ServicesAI | 11/5/2026 | 17/6/2026 | A reflected cross-site scripted (XSS) vulnerability in the dfm-menu_alerts.php component of GmbH Mecury Managed Print Services (docuForm) v11.11c allows attackers to execute arbitrary Javascript in the context of a user's browser via injecting a crafted payload into an unfiltered variable value. | |
| Aplazada | Media (6.1) | 0.24% | — | Gmbh Mecury Managed Print ServicesAI | 11/5/2026 | 17/6/2026 | A reflected cross-site scripted (XSS) vulnerability in the acc-menu_billings.php component of GmbH Mecury Managed Print Services (docuForm) v11.11c allows attackers to execute arbitrary Javascript in the context of a user's browser via injecting a crafted payload into an unfiltered variable value. | |
| Aplazada | Media (6.1) | 0.24% | — | Gmbh Mecury Managed Print ServicesAI | 11/5/2026 | 17/6/2026 | A reflected cross-site scripted (XSS) vulnerability in the dfm-menu_departments.php component of GmbH Mecury Managed Print Services (docuForm) v11.11c allows attackers to execute arbitrary Javascript in the context of a user's browser via injecting a crafted payload into an unfiltered variable value. | |
| Aplazada | Media (6.1) | 0.24% | — | Gmbh Mecury Managed Print ServicesAI | 11/5/2026 | 17/6/2026 | A reflected cross-site scripted (XSS) vulnerability in the dfm-menu_maintenance.php component of GmbH Mecury Managed Print Services (docuForm) v11.11c allows attackers to execute arbitrary Javascript in the context of a user's browser via injecting a crafted payload into an unfiltered variable value. | |
| Aplazada | Media (6.1) | 0.24% | — | Gmbh Mecury Managed Print ServicesAIDocuformAI | 11/5/2026 | 17/6/2026 | A reflected cross-site scripted (XSS) vulnerability in the acc-menu_papers.php component of GmbH Mecury Managed Print Services (docuForm) v11.11c allows attackers to execute arbitrary Javascript in the context of a user's browser via injecting a crafted payload into an unfiltered variable value. | |
| Aplazada | Media (6.1) | 0.24% | — | Gmbh Mecury Managed Print ServicesAIGmbh DocuformAI | 11/5/2026 | 17/6/2026 | A reflected cross-site scripted (XSS) vulnerability in the dfm-menu_coveragealerts.php component of GmbH Mecury Managed Print Services (docuForm) v11.11c allows attackers to execute arbitrary Javascript in the context of a user's browser via injecting a crafted payload into an unfiltered variable value. | |
| Aplazada | Media (6.1) | 0.24% | — | Gmbh Mecury Managed Print ServicesAI | 11/5/2026 | 17/6/2026 | A reflected cross-site scripted (XSS) vulnerability in the dfm-menu_firmware.php component of GmbH Mecury Managed Print Services (docuForm) v11.11c allows attackers to execute arbitrary Javascript in the context of a user's browser via injecting a crafted payload into an unfiltered variable value. | |
| Analizada | Media (6.9) | 0.14% | — | HP Samsung Print Service Plugin | 6/5/2026 | 17/6/2026 | Samsung Print Service Plugin for Android is potentially vulnerable to information disclosure when using an outdated version of the application via mobile devices. HP is releasing updates to mitigate these potential vulnerabilities. | |
| Aplazada | Crítica (9.8) | 0.74% | — | SAP Print ServiceAI | 14/10/2025 | 17/6/2026 | SAP Print Service (SAPSprint) performs insufficient validation of path information provided by users. An unauthenticated attacker could traverse to the parent directory and over-write system files causing high impact on confidentiality integrity and availability of the application. | |
| Modificada | Media (5.9) | 1.3% | — | Ecisolutions Printanista Managed Print Service | 15/9/2022 | 17/6/2026 | The login form /Login in ECi Printanista Hub (formerly FMAudit Printscout) before 5.5.2 (July 2023) performs expensive RSA key-generation operations, which allows attackers to cause a denial of service (DoS) by requesting that form repeatedly. | |
| Modificada | Alta (8.8) | 1.4% | — | Printeron Central Print Services | 29/7/2019 | 17/6/2026 | An issue was discovered in PrinterOn Central Print Services (CPS) through 4.1.4. A user without valid credentials can bypass the authentication process, obtaining a valid session cookie with guest/pseudo-guest level privileges. This cookie can then be further used to perform other attacks. | |
| Modificada | Media (5.3) | 1.7% | — | Printeron Central Print Services | 29/7/2019 | 17/6/2026 | An issue was discovered in PrinterOn Central Print Services (CPS) through 4.1.4. An unauthenticated attacker can view details about the printers associated with CPS via a crafted HTTP GET request. | |
| Modificada | Alta (8.8) | 1.7% | — | Printeron Central Print Services | 20/7/2019 | 17/6/2026 | An issue was discovered in PrinterOn Central Print Services (CPS) through 4.1.4. The core components that create and launch a print job do not perform complete verification of the session cookie that is supplied to them. As a result, an attacker with guest/pseudo-guest level permissions can bypass the session checks… | |
| Modificada | Media (6.5) | 1.1% | — | Hitachi EUR Print ServiceHitachi EUR Print Service FOR ILFHitachi EUR ProfessionalHitachi EUR Viewer | 22/5/2006 | 16/6/2026 | SQL injection vulnerability in Hitachi EUR Professional Edition, EUR Viewer, EUR Print Service, and EUR Print Service for ILF allows remote authenticated users to execute arbitrary SQL commands via unknown attack vectors. |