Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2558▼ 318 respecto a la semana anterior
Críticas / altas1344▲ 80 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 7 respecto a la semana anterior
Sin puntuar (sin CVSS)62▼ 466 respecto a la semana anterior
–

58 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaAlta (7.2)1.2%—Xerox AltalinkAIXerox VersalinkAIXerox WorkcentreAI17/10/202417/6/2026
Authenticated Remote Code Execution in Altalink, Versalink & WorkCentre Products.
ModificadaMedia (5.9)0.35%—Xerox Primelink C9065 FirmwareXerox Primelink C9070 FirmwareXerox Primelink B9136 FirmwareXerox Primelink B9125 Firmware+892/11/202317/6/2026
Multiple MFPs (multifunction printers) provided by FUJIFILM Business Innovation Corp. and Xerox Corporation provide a facility to export the contents of their Address Book with encrypted form, but the encryption strength is insufficient. With the knowledge of the encryption process and the encryption key, the…
ModificadaMedia (6.5)0.39%—Xerox Workcentre 3550 Firmware31/1/202317/6/2026
On Xerox WorkCentre 3550 25.003.03.000 devices, an authenticated attacker can view the SMB server settings and can obtain the stored cleartext credentials associated with those settings.
ModificadaCrítica (9.8)2.2%—Xerox Phaser 6510 FirmwareXerox Workcentre 6515 FirmwareXerox Versalink B400 FirmwareXerox Versalink B405 Firmware+2029/3/202117/6/2026
Xerox Phaser 6510 before 64.65.51 and 64.59.11 (Bridge), WorkCentre 6515 before 65.65.51 and 65.59.11 (Bridge), VersaLink B400 before 37.65.51 and 37.59.01 (Bridge), B405 before 38.65.51 and 38.59.01 (Bridge), B600/B610 before 32.65.51 and 32.59.01 (Bridge), B605/B615 before 33.65.51 and 33.59.01 (Bridge), B7025/30/35…
ModificadaCrítica (9.8)2.6%—Xerox Phaser 6510 FirmwareXerox Workcentre 6515 FirmwareXerox Versalink B400 FirmwareXerox Versalink B405 Firmware+2029/3/202117/6/2026
Xerox Phaser 6510 before 64.65.51 and 64.59.11 (Bridge), WorkCentre 6515 before 65.65.51 and 65.59.11 (Bridge), VersaLink B400 before 37.65.51 and 37.59.01 (Bridge), B405 before 38.65.51 and 38.59.01 (Bridge), B600/B610 before 32.65.51 and 32.59.01 (Bridge), B605/B615 before 33.65.51 and 33.59.01 (Bridge), B7025/30/35…
ModificadaCrítica (9.8)1.9%—Xerox Phaser 6510 FirmwareXerox Workcentre 6515 FirmwareXerox Versalink B400 FirmwareXerox Versalink B405 Firmware+1929/3/202117/6/2026
Xerox Phaser 6510 before 64.61.23 and 64.59.11 (Bridge), WorkCentre 6515 before 65.61.23 and 65.59.11 (Bridge), VersaLink B400 before 37.61.23 and 37.59.01 (Bridge), B405 before 38.61.23 and 38.59.01 (Bridge), B600/B610 before 32.61.23 and 32.59.01 (Bridge), B605/B615 before 33.61.23 and 33.59.01 (Bridge), B7025/30/35…
ModificadaAlta (7.5)0.80%—Xerox Workcentre 3655 FirmwareXerox Workcentre 3655i FirmwareXerox Workcentre 5865 FirmwareXerox Workcentre 5875 Firmware+2626/1/202117/6/2026
An issue was discovered in certain Xerox WorkCentre products. They do not properly encrypt passwords. This affects 3655, 3655i, 58XX, 58XXi 59XX, 59XXi, 6655, 6655i, 72XX, 72XXi 78XX, 78XXi, 7970, 7970i, EC7836, and EC7856 devices.
ModificadaMedia (6.1)0.65%—Xerox Workcentre Ec7836 FirmwareXerox Workcentre Ec7856 Firmware9/10/202017/6/2026
Xerox WorkCentre EC7836 before 073.050.059.25300 and EC7856 before 073.020.059.25300 devices allow XSS via Description pages.
ModificadaCrítica (9.8)2.0%—Xerox Workcentre 3655 FirmwareXerox Workcentre 3655i FirmwareXerox Workcentre 5865 FirmwareXerox Workcentre 5875 Firmware+2129/4/202017/6/2026
Xerox WorkCentre 3655, 3655i, 58XX, 58XXi, 59XX, 59XXi, 6655, 6655i, 72XX, 72XXi, 78XX, 78XXi, 7970, and 7970i devices before 073.xxx.086.15410 do not properly escape parameters in the support/remoteUI/configrui.php script, which can allow an unauthenticated attacker to execute OS commands on the device.
ModificadaAlta (8.8)1.1%—Xerox Workcentre 3655 FirmwareXerox Workcentre 3655i FirmwareXerox Workcentre 5845 FirmwareXerox Workcentre 5855 Firmware+1421/2/202017/6/2026
Certain Xerox WorkCentre printers before 073.xxx.000.02300 do not require the user to reenter or validate LDAP bind credentials when changing the LDAP connector IP address. A malicious actor who gains access to affected devices (e.g., by using default credentials) can change the LDAP connection IP address to a system…
ModificadaCrítica (9.8)1.2%—Xerox Colorqube 9201 FirmwareXerox Colorqube 9202 FirmwareXerox Colorqube 9203 FirmwareXerox Workcentre 6400 Firmware+813/2/202017/6/2026
Xerox ColorCube and WorkCenter devices in 2013 had hardcoded FTP and shell user accounts.
ModificadaCrítica (9.8)3.1%—Xerox Workcentre 3655i FirmwareXerox Workcentre 3655 FirmwareXerox Workcentre 5890i FirmwareXerox Workcentre 5865i Firmware+2510/2/201917/6/2026
An issue was discovered on Xerox WorkCentre 3655, 3655i, 58XX, 58XXi, 59XX, 59XXi, 6655, 6655i, 72XX, 72XXi, 78XX, 78XXi, 7970, 7970i, EC7836, and EC7856 devices before R18-05 073.xxx.0487.15000. There is unauthenticated Remote Command Execution.
ModificadaCrítica (9.8)1.1%—Xerox Workcentre 3655i FirmwareXerox Workcentre 3655 FirmwareXerox Workcentre 5890i FirmwareXerox Workcentre 5865i Firmware+2510/2/201917/6/2026
An issue was discovered on Xerox WorkCentre 3655, 3655i, 58XX, 58XXi, 59XX, 59XXi, 6655, 6655i, 72XX, 72XXi, 78XX, 78XXi, 7970, 7970i, EC7836, and EC7856 devices before R18-05 073.xxx.0487.15000. There is Blind SQL Injection.
ModificadaAlta (7.5)1.4%—Xerox Workcentre 3655i FirmwareXerox Workcentre 3655 FirmwareXerox Workcentre 5890i FirmwareXerox Workcentre 5865i Firmware+2510/2/201917/6/2026
An issue was discovered on Xerox WorkCentre 3655, 3655i, 58XX, 58XXi, 59XX, 59XXi, 6655, 6655i, 72XX, 72XXi, 78XX, 78XXi, 7970, 7970i, EC7836, and EC7856 devices before R18-05 073.xxx.0487.15000. There is a Local File Inclusion vulnerability.
ModificadaCrítica (9.8)1.2%—Xerox Workcentre 3655i FirmwareXerox Workcentre 3655 FirmwareXerox Workcentre 5890i FirmwareXerox Workcentre 5865i Firmware+2510/2/201917/6/2026
An issue was discovered on Xerox WorkCentre 3655, 3655i, 58XX, 58XXi, 59XX, 59XXi, 6655, 6655i, 72XX, 72XXi, 78XX, 78XXi, 7970, 7970i, EC7836, and EC7856 devices before R18-05 073.xxx.0487.15000. An attacker can execute PHP code by leveraging a writable file.
ModificadaAlta (8.8)2.2%—Xerox Workcentre 3655i FirmwareXerox Workcentre 3655 FirmwareXerox Workcentre 5890i FirmwareXerox Workcentre 5865i Firmware+2510/2/201917/6/2026
An issue was discovered on Xerox WorkCentre 3655, 3655i, 58XX, 58XXi, 59XX, 59XXi, 6655, 6655i, 72XX, 72XXi, 78XX, 78XXi, 7970, 7970i, EC7836, and EC7856 devices before R18-05 073.xxx.0487.15000. There is authenticated remote command execution.
ModificadaMedia (5)1.2%—Xerox Workcentre 6400 NET ControllerXerox Workcentre 6400 System Software4/2/201016/6/2026
Unspecified vulnerability in the Network Controller in Xerox WorkCentre 6400 System Software 060.070.109.11407 through 060.070.109.29510, and Net Controller 060.079.11410 through 060.079.29310, allows remote attackers to access "directory structure" via a crafted PostScript file, aka "Unauthorized Directory Structure…
ModificadaMedia (5)2.0%—Xerox Workcentre 5632Xerox Workcentre 5638Xerox Workcentre 5645Xerox Workcentre 5655+34/2/201016/6/2026
Multiple unspecified vulnerabilities in the Network Controller and Web Server in Xerox WorkCentre 5632, 5638, 5645, 5655, 5665, 5675, and 5687 allow remote attackers to (1) access mailboxes via unknown vectors that bypass Scan to Mailbox authorization or (2) read device configuration information via via unknown…
ModificadaAlta (10)3.6%—Xerox Workcentre16/5/200916/6/2026
Xerox WorkCentre and WorkCentre Pro 232, 238, 245, 255, 265, 275; and WorkCentre 5632, 5638, 5645, 5655, 5665, 5675, 5687, 7655, 7656, and 7675 allows remote attackers to execute arbitrary commands via unknown attack vectors, aka "command injection vulnerability."
ModificadaMedia (4.3)1.2%—Xerox Workcentre6/3/200916/6/2026
Cross-site scripting (XSS) vulnerability in the Web Server in Xerox WorkCentre 7132, 7228, 7235, and 7245 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
ModificadaAlta (10)2.6%—Xerox Workcentre23/6/200816/6/2026
Unspecified vulnerability in the Extensible Interface Platform in Web Services in Xerox WorkCentre 7655, 7665, and 7675 allows remote attackers to make configuration changes via unknown vectors.
ModificadaMedia (4.3)1.2%—Xerox Workcentre23/6/200816/6/2026
Cross-site scripting (XSS) vulnerability in the embedded Web Server in Xerox WorkCentre M123, M128, and 133 and WorkCentre Pro 123, 128, and 133 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
ModificadaMedia (5.8)0.45%—Xerox Workcentre11/12/200616/6/2026
Xerox WorkCentre and WorkCentre Pro before 12.050.03.000, 13.x before 13.050.03.000, and 14.x before 14.050.03.000 do not block the postgres port (5432/tcp), which has unknown impact and remote attack vectors, probably related to unauthorized connections to a PostgreSQL daemon.
ModificadaAlta (10)1.4%—Xerox Workcentre11/12/200616/6/2026
Xerox WorkCentre and WorkCentre Pro before 12.050.03.000, 13.x before 13.050.03.000, and 14.x before 14.050.03.000 use weak permissions for certain files, which allows unspecified file access.
ModificadaAlta (10)1.4%—Xerox Workcentre11/12/200616/6/2026
The httpd.conf file in Xerox WorkCentre and WorkCentre Pro before 12.050.03.000, 13.x before 13.050.03.000, and 14.x before 14.050.03.000 configures port 443 to be always active, which has unknown impact and remote attack vectors.