Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2882▼ 181 respecto a la semana anterior
Críticas / altas1279▼ 60 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)487▼ 22 respecto a la semana anterior
11 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (8.2) | 0.33% | — | Ricoh Streamline NXAI | 9/1/2026 | 17/6/2026 | Improper authorization vulnerability exists in RICOH Streamline NX 3.5.1 to 24R3. If a man-in-the-middle attack is conducted on the communication between the affected product and its user, and some crafted request is processed by the product, the user's registration information and/or OIDC (OpenID Connect) tokens may… | |
| Aplazada | Baja (2.3) | 0.11% | — | Ricoh Streamline NXAI | 8/9/2025 | 30/9/2026 | RICOH Streamline NX versions 3.5.1 to 24R3 are vulnerable to tampering with operation history. If an attacker can perform a man-in-the-middle attack, they may alter the values of HTTP requests, which could result in tampering with the operation history of the product’s management tool. | |
| Aplazada | Media (5.1) | 0.22% | — | Ricoh Streamline NXAI | 30/6/2025 | 17/6/2026 | A reflected cross-site scripting vulnerability via a specific parameter exists in SLNX Help Documentation of RICOH Streamline NX. If this vulnerability is exploited, an arbitrary script may be executed in the web browser of the user who accessed the product. | |
| Aplazada | Baja (2) | 0.12% | — | Ricoh Streamline NX V3 PC ClientAI | 13/6/2025 | 17/6/2026 | RICOH Streamline NX V3 PC Client versions 3.5.0 to 3.7.0 contains an issue with use of less trusted source, which may allow an attacker who can conduct a man-in-the-middle attack to eavesdrop upgrade requests and execute a malicious DLL with custom code. | |
| Aplazada | Crítica (9.3) | 0.88% | — | Ricoh Streamline NX V3 PC ClientAI | 13/6/2025 | 17/6/2026 | Path traversal vulnerability exists in RICOH Streamline NX V3 PC Client versions 3.5.0 to 3.242.0. If this vulnerability is exploited, arbitrary code may be executed on the PC where the product is running by tampering with specific files used on the product. | |
| Aplazada | Media (6.9) | 0.42% | — | Ricoh Streamline NX V3 PC ClientAI | 13/6/2025 | 17/6/2026 | External control of file name or path issue exists in RICOH Streamline NX V3 PC Client versions 3.5.0 to 3.242.0. If an attacker sends a specially crafted request, arbitrary files in the file system can be overwritten with log data. | |
| Aplazada | Media (4) | 0.16% | — | Ricoh Streamline NX PC ClientAI | 19/6/2024 | 17/6/2026 | Use of potentially dangerous function issue exists in Ricoh Streamline NX PC Client. If this vulnerability is exploited, files in the PC where the product is installed may be altered. | |
| Aplazada | Crítica (9.8) | 0.51% | — | Ricoh Streamline NX PC ClientAI | 19/6/2024 | 17/6/2026 | Use of potentially dangerous function issue exists in Ricoh Streamline NX PC Client. If this vulnerability is exploited, an attacker may create an arbitrary file in the PC where the product is installed. | |
| Aplazada | Crítica (9.8) | 0.43% | — | Ricoh Streamline NX PC ClientAI | 19/6/2024 | 17/6/2026 | Use of hard-coded credentials issue exists in Ricoh Streamline NX PC Client ver.3.7.2 and earlier. If this vulnerability is exploited, an attacker may obtain LocalSystem Account of the PC where the product is installed. As a result, unintended operations may be performed on the PC. | |
| Aplazada | Media (6.3) | 0.22% | — | Ricoh Streamline NX PC ClientAI | 19/6/2024 | 17/6/2026 | Improper restriction of communication channel to intended endpoints issue exists in Ricoh Streamline NX PC Client ver.3.6.x and earlier. If this vulnerability is exploited, arbitrary code may be executed on the PC where the product is installed. | |
| Modificada | Alta (7.8) | 0.31% | — | Ricoh Streamline NX Client ToolRicoh Streamline NX PC Client | 4/8/2020 | 17/6/2026 | An issue was discovered in RICOH Streamline NX Client Tool and RICOH Streamline NX PC Client that allows attackers to escalate local privileges. |