Vulnerabilities
Summary — last 7 days
New vulnerabilities2,537▼ 356 vs. last week
Critical / high1,341▲ 75 vs. last week
New active exploitation (KEV)6▼ 5 vs. last week
Unscored (no CVSS)62▼ 466 vs. last week
18 results, sorted by published date (most recent first)
| CVE | Status | Severity | EPSS | Active exploitation | Affected technologies | Published ▼ | Modified | Description |
|---|---|---|---|---|---|---|---|---|
| Modified | High (7.5) | 0.54% | — | Lexmark C2132 FirmwareLexmark Cs310 FirmwareLexmark Cs317 FirmwareLexmark Cs410 Firmware+78 | 9/1/2023 | 6/17/2026 | Certain Lexmark devices (such as CS310) before 2023-08-25 allow XXE attacks, leading to information disclosure. The fixed firmware version is LW80.*.P246, i.e., '*' indicates that the full version specification varies across product model family, but firmware level P246 (or higher) is required to remediate the… | |
| Modified | High (8.8) | 1.4% | — | Lexmark B2236 FirmwareLexmark Mb2236 FirmwareLexmark Ms431 FirmwareLexmark Ms331 Firmware+230 | 1/20/2022 | 6/17/2026 | PJL directory traversal vulnerability in Lexmark devices through 2021-12-07 that can be leveraged to overwrite internal configuration files. | |
| Modified | Critical (9.8) | 6.4% | — | Lexmark B2236 FirmwareLexmark Mb2236 FirmwareLexmark Ms431 FirmwareLexmark Ms331 Firmware+230 | 1/20/2022 | 6/17/2026 | Embedded web server input sanitization vulnerability in Lexmark devices through 2021-12-07, which can which can lead to remote code execution on the device. | |
| Modified | Critical (9.8) | 3.3% | — | Lexmark B2236 FirmwareLexmark Mb2236 FirmwareLexmark Ms431 FirmwareLexmark Ms331 Firmware+230 | 1/20/2022 | 6/17/2026 | Buffer overflow vulnerability has been identified in Lexmark devices through 2021-12-07 in postscript interpreter. | |
| Modified | Medium (5.4) | 0.65% | — | Lexmark Cs31x FirmwareLexmark Cs41x FirmwareLexmark Cs51x FirmwareLexmark Cx310 Firmware+76 | 4/28/2020 | 6/17/2026 | A cross-site scripting (XSS) vulnerability in Lexmark CS31x before LW74.VYL.P273; CS41x before LW74.VY2.P273; CS51x before LW74.VY4.P273; CX310 before LW74.GM2.P273; CX410 & XC2130 before LW74.GM4.P273; CX510 & XC2132 before LW74.GM7.P273; MS310, MS312, MS317 before LW74.PRL.P273; MS410, M1140 before LW74.PRL.P273;… | |
| Modified | Medium (5.4) | 0.66% | — | Lexmark Cs31x FirmwareLexmark Cs41x FirmwareLexmark Cs51x FirmwareLexmark Cx310 Firmware+76 | 4/28/2020 | 6/17/2026 | A cross-site scripting (XSS) vulnerability in Lexmark Pro910 series inkjet and other discontinued products. | |
| Modified | Medium (5.4) | 0.66% | — | Lexmark Cs31x FirmwareLexmark Cs41x FirmwareLexmark Cs51x FirmwareLexmark Cx310 Firmware+76 | 3/6/2020 | 6/17/2026 | Various Lexmark products have stored XSS in the embedded web server used in older generation Lexmark devices. Affected products are available in http://support.lexmark.com/index?page=content&id=TE935&locale=en&userlocale=EN_US. | |
| Modified | Medium (5.4) | 0.65% | — | Lexmark Cs31x FirmwareLexmark Cs41x FirmwareLexmark Cs51x FirmwareLexmark Cx310 Firmware+76 | 3/6/2020 | 6/17/2026 | Various Lexmark products have reflected XSS in the embedded web server used in older generation Lexmark devices. Affected products are available in http://support.lexmark.com/index?page=content&id=TE935&locale=en&userlocale=EN_US. | |
| Modified | Medium (5.4) | 0.53% | — | Lexmark Cx31x FirmwareLexmark Cx41x FirmwareLexmark Cx310 FirmwareLexmark Ms310 Firmware+76 | 2/13/2020 | 6/17/2026 | Lexmark printer MS812 and multiple older generation Lexmark devices have a stored XSS vulnerability in the embedded web server. The vulnerability can be exploited to expose session credentials and other information via the users web browser. | |
| Modified | Critical (9.8) | 1.5% | — | Lexmark Cs31x FirmwareLexmark Cs41x FirmwareLexmark Cx310 FirmwareLexmark Ms310 Firmware+67 | 8/28/2019 | 6/17/2026 | Various Lexmark products have a Buffer Overflow (issue 3 of 3). | |
| Modified | Critical (9.8) | 1.5% | — | Lexmark Cs31x FirmwareLexmark Cs41x FirmwareLexmark Cx310 FirmwareLexmark Ms310 Firmware+67 | 8/28/2019 | 6/17/2026 | Various Lexmark products have a Buffer Overflow (issue 2 of 3). | |
| Modified | High (7.5) | 1.1% | — | Lexmark Cs31x FirmwareLexmark Cs41x FirmwareLexmark Cx310 FirmwareLexmark Ms310 Firmware+67 | 8/28/2019 | 6/17/2026 | Various Lexmark printers contain a denial of service vulnerability in the SNMP service that can be exploited to crash the device. | |
| Modified | Critical (9.8) | 1.5% | — | Lexmark Cs31x FirmwareLexmark Cs41x FirmwareLexmark Cx310 FirmwareLexmark Ms310 Firmware+67 | 8/28/2019 | 6/17/2026 | Various Lexmark products have an Integer Overflow. | |
| Modified | Medium (5.3) | 0.87% | — | Lexmark Cs31x FirmwareLexmark Cs41x FirmwareLexmark Cx310 FirmwareLexmark Ms310 Firmware+67 | 8/28/2019 | 6/17/2026 | The legacy finger service (TCP port 79) is enabled by default on various older Lexmark devices. | |
| Modified | Medium (6.5) | 0.41% | — | Lexmark Cs31x FirmwareLexmark Cs41x FirmwareLexmark Cx310 FirmwareLexmark Ms310 Firmware+21 | 8/28/2019 | 6/17/2026 | Various Lexmark products have CSRF. | |
| Modified | Medium (5.3) | 0.83% | — | Lexmark Cs31x FirmwareLexmark Cs41x FirmwareLexmark Cx310 FirmwareLexmark Ms310 Firmware+21 | 8/28/2019 | 6/17/2026 | Various Lexmark products have Incorrect Access Control (issue 2 of 2). | |
| Modified | Medium (5.3) | 0.83% | — | Lexmark Cs31x FirmwareLexmark Cs41x FirmwareLexmark Cx310 FirmwareLexmark Ms310 Firmware+21 | 8/28/2019 | 6/17/2026 | Various Lexmark products have Incorrect Access Control (issue 1 of 2). | |
| Modified | Critical (9.1) | 1.1% | — | Lexmark Cs31x FirmwareLexmark Cs41x FirmwareLexmark Cx310 FirmwareLexmark Ms310 Firmware+70 | 8/28/2019 | 6/17/2026 | Various Lexmark products have Incorrect Access Control. |