Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2882▼ 181 respecto a la semana anterior
Críticas / altas1279▼ 60 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)487▼ 22 respecto a la semana anterior
–

11 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaAlta (8.2)0.33%—Ricoh Streamline NXAI9/1/202617/6/2026
Improper authorization vulnerability exists in RICOH Streamline NX 3.5.1 to 24R3. If a man-in-the-middle attack is conducted on the communication between the affected product and its user, and some crafted request is processed by the product, the user's registration information and/or OIDC (OpenID Connect) tokens may…
AplazadaBaja (2.3)0.11%—Ricoh Streamline NXAI8/9/202530/9/2026
RICOH Streamline NX versions 3.5.1 to 24R3 are vulnerable to tampering with operation history. If an attacker can perform a man-in-the-middle attack, they may alter the values of HTTP requests, which could result in tampering with the operation history of the product’s management tool.
AplazadaMedia (5.1)0.22%—Ricoh Streamline NXAI30/6/202517/6/2026
A reflected cross-site scripting vulnerability via a specific parameter exists in SLNX Help Documentation of RICOH Streamline NX. If this vulnerability is exploited, an arbitrary script may be executed in the web browser of the user who accessed the product.
AplazadaBaja (2)0.12%—Ricoh Streamline NX V3 PC ClientAI13/6/202517/6/2026
RICOH Streamline NX V3 PC Client versions 3.5.0 to 3.7.0 contains an issue with use of less trusted source, which may allow an attacker who can conduct a man-in-the-middle attack to eavesdrop upgrade requests and execute a malicious DLL with custom code.
AplazadaCrítica (9.3)0.88%—Ricoh Streamline NX V3 PC ClientAI13/6/202517/6/2026
Path traversal vulnerability exists in RICOH Streamline NX V3 PC Client versions 3.5.0 to 3.242.0. If this vulnerability is exploited, arbitrary code may be executed on the PC where the product is running by tampering with specific files used on the product.
AplazadaMedia (6.9)0.42%—Ricoh Streamline NX V3 PC ClientAI13/6/202517/6/2026
External control of file name or path issue exists in RICOH Streamline NX V3 PC Client versions 3.5.0 to 3.242.0. If an attacker sends a specially crafted request, arbitrary files in the file system can be overwritten with log data.
AplazadaMedia (4)0.16%—Ricoh Streamline NX PC ClientAI19/6/202417/6/2026
Use of potentially dangerous function issue exists in Ricoh Streamline NX PC Client. If this vulnerability is exploited, files in the PC where the product is installed may be altered.
AplazadaCrítica (9.8)0.51%—Ricoh Streamline NX PC ClientAI19/6/202417/6/2026
Use of potentially dangerous function issue exists in Ricoh Streamline NX PC Client. If this vulnerability is exploited, an attacker may create an arbitrary file in the PC where the product is installed.
AplazadaCrítica (9.8)0.43%—Ricoh Streamline NX PC ClientAI19/6/202417/6/2026
Use of hard-coded credentials issue exists in Ricoh Streamline NX PC Client ver.3.7.2 and earlier. If this vulnerability is exploited, an attacker may obtain LocalSystem Account of the PC where the product is installed. As a result, unintended operations may be performed on the PC.
AplazadaMedia (6.3)0.22%—Ricoh Streamline NX PC ClientAI19/6/202417/6/2026
Improper restriction of communication channel to intended endpoints issue exists in Ricoh Streamline NX PC Client ver.3.6.x and earlier. If this vulnerability is exploited, arbitrary code may be executed on the PC where the product is installed.
ModificadaAlta (7.8)0.31%—Ricoh Streamline NX Client ToolRicoh Streamline NX PC Client4/8/202017/6/2026
An issue was discovered in RICOH Streamline NX Client Tool and RICOH Streamline NX PC Client that allows attackers to escalate local privileges.