Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2614▼ 473 respecto a la semana anterior
Críticas / altas1270▼ 74 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)243▼ 274 respecto a la semana anterior
–

19 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaAlta (7.9)0.17%—ARM C1-ultra FirmwareARM C1-premium FirmwareARM Cortex-a710 FirmwareARM Cortex-x2 Firmware+714/1/202617/6/2026
In certain Arm CPUs, a CPP RCTX instruction executed on one Processing Element (PE) may inhibit TLB invalidation when a TLBI is issued to the PE, either by the same PE or another PE in the shareability domain. In this case, the PE may retain stale TLB entries which should have been invalidated by the TLBI.
AnalizadaMedia (5.1)0.20%—ARM C1-premium FirmwareARM C1-pro FirmwareARM C1-ultra FirmwareARM Cortex-x3 Firmware+528/1/202517/6/2026
An unprivileged context can trigger a data memory-dependent prefetch engine to fetch the contents of a privileged location and consume those contents as an address that is also dereferenced.
AnalizadaCrítica (9.8)0.56%—ARM Cortex-a710 FirmwareARM Cortex-a77 FirmwareARM Cortex-a78 FirmwareARM Cortex-a78ae Firmware+1210/12/202417/6/2026
Use of Hardware Page Aggregation (HPA) and Stage-1 and/or Stage-2 translation on Cortex-A77, Cortex-A78, Cortex-A78C, Cortex-A78AE, Cortex-A710, Cortex-X1, Cortex-X1C, Cortex-X2, Cortex-X3, Cortex-X4, Cortex-X925, Neoverse V1, Neoverse V2, Neoverse V3, Neoverse V3AE, Neoverse N2 may permit bypass of Stage-2…
ModificadaAlta (8.8)1.4%—Lexmark B2236 FirmwareLexmark Mb2236 FirmwareLexmark Ms431 FirmwareLexmark Ms331 Firmware+23020/1/202217/6/2026
PJL directory traversal vulnerability in Lexmark devices through 2021-12-07 that can be leveraged to overwrite internal configuration files.
ModificadaCrítica (9.8)6.2%—Lexmark B2236 FirmwareLexmark Mb2236 FirmwareLexmark Ms431 FirmwareLexmark Ms331 Firmware+23020/1/202217/6/2026
Embedded web server input sanitization vulnerability in Lexmark devices through 2021-12-07, which can which can lead to remote code execution on the device.
ModificadaCrítica (9.8)3.3%—Lexmark B2236 FirmwareLexmark Mb2236 FirmwareLexmark Ms431 FirmwareLexmark Ms331 Firmware+23020/1/202217/6/2026
Buffer overflow vulnerability has been identified in Lexmark devices through 2021-12-07 in postscript interpreter.
ModificadaMedia (5.4)0.65%—Lexmark Cs31x FirmwareLexmark Cs41x FirmwareLexmark Cs51x FirmwareLexmark Cx310 Firmware+7628/4/202017/6/2026
A cross-site scripting (XSS) vulnerability in Lexmark CS31x before LW74.VYL.P273; CS41x before LW74.VY2.P273; CS51x before LW74.VY4.P273; CX310 before LW74.GM2.P273; CX410 & XC2130 before LW74.GM4.P273; CX510 & XC2132 before LW74.GM7.P273; MS310, MS312, MS317 before LW74.PRL.P273; MS410, M1140 before LW74.PRL.P273;…
ModificadaMedia (5.4)0.66%—Lexmark Cs31x FirmwareLexmark Cs41x FirmwareLexmark Cs51x FirmwareLexmark Cx310 Firmware+7628/4/202017/6/2026
A cross-site scripting (XSS) vulnerability in Lexmark Pro910 series inkjet and other discontinued products.
ModificadaAlta (7.5)1.7%—Lexmark 6500e FirmwareLexmark C748 FirmwareLexmark C79x FirmwareLexmark C925 Firmware+4510/3/202017/6/2026
Certain older Lexmark devices (C, M, X, and 6500e before 2018-12-18) contain a directory traversal vulnerability in the embedded web server.
ModificadaMedia (5.4)0.66%—Lexmark Cs31x FirmwareLexmark Cs41x FirmwareLexmark Cs51x FirmwareLexmark Cx310 Firmware+766/3/202017/6/2026
Various Lexmark products have stored XSS in the embedded web server used in older generation Lexmark devices. Affected products are available in http://support.lexmark.com/index?page=content&id=TE935&locale=en&userlocale=EN_US.
ModificadaMedia (5.4)0.65%—Lexmark Cs31x FirmwareLexmark Cs41x FirmwareLexmark Cs51x FirmwareLexmark Cx310 Firmware+766/3/202017/6/2026
Various Lexmark products have reflected XSS in the embedded web server used in older generation Lexmark devices. Affected products are available in http://support.lexmark.com/index?page=content&id=TE935&locale=en&userlocale=EN_US.
ModificadaMedia (5.4)0.53%—Lexmark Cx31x FirmwareLexmark Cx41x FirmwareLexmark Cx310 FirmwareLexmark Ms310 Firmware+7613/2/202017/6/2026
Lexmark printer MS812 and multiple older generation Lexmark devices have a stored XSS vulnerability in the embedded web server. The vulnerability can be exploited to expose session credentials and other information via the users web browser.
ModificadaCrítica (9.8)1.5%—Lexmark Cs31x FirmwareLexmark Cs41x FirmwareLexmark Cx310 FirmwareLexmark Ms310 Firmware+6728/8/201917/6/2026
Various Lexmark products have a Buffer Overflow (issue 3 of 3).
ModificadaCrítica (9.8)1.5%—Lexmark Cs31x FirmwareLexmark Cs41x FirmwareLexmark Cx310 FirmwareLexmark Ms310 Firmware+6728/8/201917/6/2026
Various Lexmark products have a Buffer Overflow (issue 2 of 3).
ModificadaAlta (7.5)1.1%—Lexmark Cs31x FirmwareLexmark Cs41x FirmwareLexmark Cx310 FirmwareLexmark Ms310 Firmware+6728/8/201917/6/2026
Various Lexmark printers contain a denial of service vulnerability in the SNMP service that can be exploited to crash the device.
ModificadaCrítica (9.8)1.5%—Lexmark Cs31x FirmwareLexmark Cs41x FirmwareLexmark Cx310 FirmwareLexmark Ms310 Firmware+6728/8/201917/6/2026
Various Lexmark products have an Integer Overflow.
ModificadaMedia (5.3)0.87%—Lexmark Cs31x FirmwareLexmark Cs41x FirmwareLexmark Cx310 FirmwareLexmark Ms310 Firmware+6728/8/201917/6/2026
The legacy finger service (TCP port 79) is enabled by default on various older Lexmark devices.
ModificadaCrítica (9.1)1.1%—Lexmark Cs31x FirmwareLexmark Cs41x FirmwareLexmark Cx310 FirmwareLexmark Ms310 Firmware+7028/8/201917/6/2026
Various Lexmark products have Incorrect Access Control.
ModificadaMedia (5.3)0.94%—Lexmark Xm5163 FirmwareLexmark Xm5170 FirmwareLexmark Xm7155 FirmwareLexmark Xm7163 Firmware+3611/2/201917/6/2026
Certain Lexmark CX, MX, X, XC, XM, XS, and 6500e devices before 2019-02-11 allow remote attackers to erase stored shortcuts.