Vulnerabilities

Summary — last 7 days

New vulnerabilities2,537▼ 356 vs. last week
Critical / high1,341▲ 75 vs. last week
New active exploitation (KEV)6▼ 5 vs. last week
Unscored (no CVSS)62▼ 466 vs. last week
–

18 results, sorted by published date (most recent first)

CVEStatusSeverityEPSS Active exploitationAffected technologiesPublished ▼Modified Description
ModifiedHigh (7.5)0.54%—Lexmark C2132 FirmwareLexmark Cs310 FirmwareLexmark Cs317 FirmwareLexmark Cs410 Firmware+789/1/20236/17/2026
Certain Lexmark devices (such as CS310) before 2023-08-25 allow XXE attacks, leading to information disclosure. The fixed firmware version is LW80.*.P246, i.e., '*' indicates that the full version specification varies across product model family, but firmware level P246 (or higher) is required to remediate the…
ModifiedHigh (8.8)1.4%—Lexmark B2236 FirmwareLexmark Mb2236 FirmwareLexmark Ms431 FirmwareLexmark Ms331 Firmware+2301/20/20226/17/2026
PJL directory traversal vulnerability in Lexmark devices through 2021-12-07 that can be leveraged to overwrite internal configuration files.
ModifiedCritical (9.8)6.4%—Lexmark B2236 FirmwareLexmark Mb2236 FirmwareLexmark Ms431 FirmwareLexmark Ms331 Firmware+2301/20/20226/17/2026
Embedded web server input sanitization vulnerability in Lexmark devices through 2021-12-07, which can which can lead to remote code execution on the device.
ModifiedCritical (9.8)3.3%—Lexmark B2236 FirmwareLexmark Mb2236 FirmwareLexmark Ms431 FirmwareLexmark Ms331 Firmware+2301/20/20226/17/2026
Buffer overflow vulnerability has been identified in Lexmark devices through 2021-12-07 in postscript interpreter.
ModifiedMedium (5.4)0.65%—Lexmark Cs31x FirmwareLexmark Cs41x FirmwareLexmark Cs51x FirmwareLexmark Cx310 Firmware+764/28/20206/17/2026
A cross-site scripting (XSS) vulnerability in Lexmark CS31x before LW74.VYL.P273; CS41x before LW74.VY2.P273; CS51x before LW74.VY4.P273; CX310 before LW74.GM2.P273; CX410 & XC2130 before LW74.GM4.P273; CX510 & XC2132 before LW74.GM7.P273; MS310, MS312, MS317 before LW74.PRL.P273; MS410, M1140 before LW74.PRL.P273;…
ModifiedMedium (5.4)0.66%—Lexmark Cs31x FirmwareLexmark Cs41x FirmwareLexmark Cs51x FirmwareLexmark Cx310 Firmware+764/28/20206/17/2026
A cross-site scripting (XSS) vulnerability in Lexmark Pro910 series inkjet and other discontinued products.
ModifiedMedium (5.4)0.66%—Lexmark Cs31x FirmwareLexmark Cs41x FirmwareLexmark Cs51x FirmwareLexmark Cx310 Firmware+763/6/20206/17/2026
Various Lexmark products have stored XSS in the embedded web server used in older generation Lexmark devices. Affected products are available in http://support.lexmark.com/index?page=content&id=TE935&locale=en&userlocale=EN_US.
ModifiedMedium (5.4)0.65%—Lexmark Cs31x FirmwareLexmark Cs41x FirmwareLexmark Cs51x FirmwareLexmark Cx310 Firmware+763/6/20206/17/2026
Various Lexmark products have reflected XSS in the embedded web server used in older generation Lexmark devices. Affected products are available in http://support.lexmark.com/index?page=content&id=TE935&locale=en&userlocale=EN_US.
ModifiedMedium (5.4)0.53%—Lexmark Cx31x FirmwareLexmark Cx41x FirmwareLexmark Cx310 FirmwareLexmark Ms310 Firmware+762/13/20206/17/2026
Lexmark printer MS812 and multiple older generation Lexmark devices have a stored XSS vulnerability in the embedded web server. The vulnerability can be exploited to expose session credentials and other information via the users web browser.
ModifiedCritical (9.8)1.5%—Lexmark Cs31x FirmwareLexmark Cs41x FirmwareLexmark Cx310 FirmwareLexmark Ms310 Firmware+678/28/20196/17/2026
Various Lexmark products have a Buffer Overflow (issue 3 of 3).
ModifiedCritical (9.8)1.5%—Lexmark Cs31x FirmwareLexmark Cs41x FirmwareLexmark Cx310 FirmwareLexmark Ms310 Firmware+678/28/20196/17/2026
Various Lexmark products have a Buffer Overflow (issue 2 of 3).
ModifiedHigh (7.5)1.1%—Lexmark Cs31x FirmwareLexmark Cs41x FirmwareLexmark Cx310 FirmwareLexmark Ms310 Firmware+678/28/20196/17/2026
Various Lexmark printers contain a denial of service vulnerability in the SNMP service that can be exploited to crash the device.
ModifiedCritical (9.8)1.5%—Lexmark Cs31x FirmwareLexmark Cs41x FirmwareLexmark Cx310 FirmwareLexmark Ms310 Firmware+678/28/20196/17/2026
Various Lexmark products have an Integer Overflow.
ModifiedMedium (5.3)0.87%—Lexmark Cs31x FirmwareLexmark Cs41x FirmwareLexmark Cx310 FirmwareLexmark Ms310 Firmware+678/28/20196/17/2026
The legacy finger service (TCP port 79) is enabled by default on various older Lexmark devices.
ModifiedMedium (6.5)0.41%—Lexmark Cs31x FirmwareLexmark Cs41x FirmwareLexmark Cx310 FirmwareLexmark Ms310 Firmware+218/28/20196/17/2026
Various Lexmark products have CSRF.
ModifiedMedium (5.3)0.83%—Lexmark Cs31x FirmwareLexmark Cs41x FirmwareLexmark Cx310 FirmwareLexmark Ms310 Firmware+218/28/20196/17/2026
Various Lexmark products have Incorrect Access Control (issue 2 of 2).
ModifiedMedium (5.3)0.83%—Lexmark Cs31x FirmwareLexmark Cs41x FirmwareLexmark Cx310 FirmwareLexmark Ms310 Firmware+218/28/20196/17/2026
Various Lexmark products have Incorrect Access Control (issue 1 of 2).
ModifiedCritical (9.1)1.1%—Lexmark Cs31x FirmwareLexmark Cs41x FirmwareLexmark Cx310 FirmwareLexmark Ms310 Firmware+708/28/20196/17/2026
Various Lexmark products have Incorrect Access Control.