Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2738▼ 488 respecto a la semana anterior
Críticas / altas1301▼ 189 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)229▼ 273 respecto a la semana anterior
–

65 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaMedia (5.7)0.42%—Ricoh SP 330dnAIRicoh SP 221AIRicoh SP C252sfAIRicoh Aficio SP 3500sfAI28/9/20261/10/2026
A security flaw has been discovered in Ricoh SP 330DN, SP 221, SP C252SF and Aficio SP 3500SF up to 20260813. This affects an unknown part of the component HTTP Multipart Form-Data Parser. Performing a manipulation results in denial of service. The attack is possible to be carried out remotely. The exploit has been…
Pendiente de análisisBaja (3.8)0.17%—Papercut HiveAIRicohAI24/9/202624/9/2026
An input validation vulnerability exists in the PaperCut Hive embedded application for Ricoh devices. The application fails to properly sanitize input received during the NFC card reading process before passing it to the application's web view interface. A local attacker with physical access to the device and a…
AplazadaMedia (6.9)0.38%—Ricoh PrintersAIRicoh Multifunction PrintersAI23/7/202623/7/2026
Printers and Multifunction Printers (MFPs) provided by Ricoh Company, Ltd. do not implement restrictions on SSH port forwarding, allowing to connect to arbitrary destinations. When SSH is enabled on an affected product, SSH port forwarding may be leveraged to connect to other node on the LAN.
AplazadaMedia (5.1)0.34%—Ricoh WEB Image MonitorAI30/6/202631/8/2026
Multiple laser printers and MFPs (multifunction printers) which implement Ricoh Web Image Monitor contain a reflected cross-site scripting vulnerability. An arbitrary script may be executed on the web browser of the user who accesses a crafted URL.
AplazadaAlta (8.5)0.18%—Ricoh Printer DriversAIKonicaminolta Printer DriversAI15/6/202624/7/2026
Multiple printer drivers provided by Ricoh Company, Ltd. and KONICA MINOLTA JAPAN, INC. contain a privilege escalation vulnerability. If this vulnerability is exploited, an attacker who can log in to a computer running an affected printer driver could elevate privileges by using a specially crafted driver.
Pendiente de análisisMedia (5.1)0.38%—Ricoh WEB Image MonitorAI30/4/202631/8/2026
Open redirect vulnerability exists in Multiple laser printers and MFPs which implement Ricoh Web Image Monitor. When accessing a specially crafted URL, the user may be redirected to an arbitrary website. As a result, the user may become a victim of a phishing attack.
AplazadaAlta (8.4)0.19%—Ricoh JOB LOG Aggregation ToolAI20/2/202617/6/2026
The installer for ジョブログ集計/分析ソフトウェア RICOHジョブログ集計ツール versions prior to Ver.1.3.7 contains an issue with the DLL search path, which may lead to insecurely loading Dynamic Link Libraries. As a result, arbitrary code may be executed with administrative privileges.
AplazadaMedia (5.1)0.23%—Ricoh WEB Image MonitorAI12/2/202617/6/2026
RICOH Web Image Monitor 1.09 contains an HTML injection vulnerability in the address configuration CGI script that allows attackers to inject malicious HTML code. Attackers can exploit the entryNameIn and entryDisplayNameIn parameters to insert arbitrary HTML content, potentially enabling cross-site scripting attacks.
AplazadaAlta (8.4)0.16%—OKI Electric Industry OKI ProductsAIRicoh ProductsAIMurata Machinery Murata ProductsAI9/2/202617/6/2026
Products provided by Oki Electric Industry Co., Ltd. and its OEM products (Ricoh Co., Ltd., Murata Machinery, Ltd.) register Windows services with unquoted file paths. A user with the write permission on the root directory of the system drive may execute arbitrary code with SYSTEM privilege.
AplazadaAlta (8.2)0.33%—Ricoh Streamline NXAI9/1/202617/6/2026
Improper authorization vulnerability exists in RICOH Streamline NX 3.5.1 to 24R3. If a man-in-the-middle attack is conducted on the communication between the affected product and its user, and some crafted request is processed by the product, the user's registration information and/or OIDC (OpenID Connect) tokens may…
AplazadaBaja (2.3)0.11%—Ricoh Streamline NXAI8/9/202530/9/2026
RICOH Streamline NX versions 3.5.1 to 24R3 are vulnerable to tampering with operation history. If an attacker can perform a man-in-the-middle attack, they may alter the values of HTTP requests, which could result in tampering with the operation history of the product’s management tool.
AplazadaMedia (5.1)0.22%—Ricoh Streamline NXAI30/6/202517/6/2026
A reflected cross-site scripting vulnerability via a specific parameter exists in SLNX Help Documentation of RICOH Streamline NX. If this vulnerability is exploited, an arbitrary script may be executed in the web browser of the user who accessed the product.
AplazadaBaja (2)0.12%—Ricoh Streamline NX V3 PC ClientAI13/6/202517/6/2026
RICOH Streamline NX V3 PC Client versions 3.5.0 to 3.7.0 contains an issue with use of less trusted source, which may allow an attacker who can conduct a man-in-the-middle attack to eavesdrop upgrade requests and execute a malicious DLL with custom code.
AplazadaCrítica (9.3)0.88%—Ricoh Streamline NX V3 PC ClientAI13/6/202517/6/2026
Path traversal vulnerability exists in RICOH Streamline NX V3 PC Client versions 3.5.0 to 3.242.0. If this vulnerability is exploited, arbitrary code may be executed on the PC where the product is running by tampering with specific files used on the product.
AplazadaMedia (6.9)0.42%—Ricoh Streamline NX V3 PC ClientAI13/6/202517/6/2026
External control of file name or path issue exists in RICOH Streamline NX V3 PC Client versions 3.5.0 to 3.242.0. If an attacker sends a specially crafted request, arbitrary files in the file system can be overwritten with log data.
AplazadaMedia (5.1)0.69%💥 ExploitRicoh WEB Image MonitorAI12/5/202517/6/2026
Reflected cross-site scripting vulnerability exists in the laser printers and MFPs (multifunction printers) which implement Ricoh Web Image Monitor. If exploited, an arbitrary script may be executed on the web browser of the user who accessed Web Image Monitor. As for the details of affected product names and…
AplazadaAlta (7.7)0.70%—Ricoh WEB Image MonitorAI1/11/202417/6/2026
Stack-based buffer overflow vulnerability exists in multiple laser printers and MFPs which implement Ricoh Web Image Monitor. If this vulnerability is exploited, receiving a specially crafted request created and sent by an attacker may lead to arbitrary code execution and/or a denial-of-service (DoS) condition. As for…
AplazadaAlta (8.2)0.58%—Ricoh MFPAIRicoh PrinterAI10/7/202417/6/2026
Out-of-bounds write vulnerability exists in Ricoh MFPs and printers. If a remote attacker sends a specially crafted request to the affected products, the products may be able to cause a denial-of-service (DoS) condition and/or user's data may be destroyed.
AplazadaMedia (4)0.16%—Ricoh Streamline NX PC ClientAI19/6/202417/6/2026
Use of potentially dangerous function issue exists in Ricoh Streamline NX PC Client. If this vulnerability is exploited, files in the PC where the product is installed may be altered.
AplazadaCrítica (9.8)0.51%—Ricoh Streamline NX PC ClientAI19/6/202417/6/2026
Use of potentially dangerous function issue exists in Ricoh Streamline NX PC Client. If this vulnerability is exploited, an attacker may create an arbitrary file in the PC where the product is installed.
AplazadaCrítica (9.8)0.43%—Ricoh Streamline NX PC ClientAI19/6/202417/6/2026
Use of hard-coded credentials issue exists in Ricoh Streamline NX PC Client ver.3.7.2 and earlier. If this vulnerability is exploited, an attacker may obtain LocalSystem Account of the PC where the product is installed. As a result, unintended operations may be performed on the PC.
AplazadaMedia (6.3)0.22%—Ricoh Streamline NX PC ClientAI19/6/202417/6/2026
Improper restriction of communication channel to intended endpoints issue exists in Ricoh Streamline NX PC Client ver.3.6.x and earlier. If this vulnerability is exploited, arbitrary code may be executed on the PC where the product is installed.
ModificadaAlta (7.8)0.14%—Ricoh Printer Driver Packager NX19/6/202317/6/2026
The driver installation package created by Printer Driver Packager NX v1.0.02 to v1.1.25 fails to detect its modification and may spawn an unexpected process with the administrative privilege. If a non-administrative user modifies the driver installation package and runs it on the target PC, an arbitrary program may…
ModificadaCrítica (9.1)0.54%—Ricoh MP C307 FirmwareRicoh MP C407 FirmwareRicoh MP C406 FirmwareRicoh MP C306 Firmware+7316/2/202317/6/2026
Ricoh mp_c4504ex devices with firmware 1.06 mishandle credentials.
ModificadaMedia (4.8)0.64%—Ricoh Aficio SP 4210n Firmware7/12/202217/6/2026
Cross-site scripting vulnerability in Aficio SP 4210N firmware versions prior to Web Support 1.05 allows a remote authenticated attacker with an administrative privilege to inject an arbitrary script.