Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2753▼ 55 respecto a la semana anterior
Críticas / altas1422▲ 195 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)106▼ 394 respecto a la semana anterior
644 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Recibida | Alta (8.7) | — | — | Sharp Multifunction PrinterAIToshibatec Multifunction PrinterAI | 1/10/2026 | 1/10/2026 | Sharp (and Toshiba Tec rebranded) multifunction printers contain an unauthenticated local file inclusion vulnerability that allows remote attackers to read arbitrary files by manipulating the path parameter in the installed_emanual_down.html endpoint. Attackers can supply directory traversal sequences such as… | |
| Aplazada | Crítica (9.8) | 0.57% | — | Honeywell Pd45 Industrial PrinterAI | 24/9/2026 | 24/9/2026 | An unauthenticated Remote Code Execution via Arbitrary File Upload vulnerability in the web management interface in Honeywell PD45 Industrial Printer version F10.19.010040, allows upload of attacker controlled files without requiring authentication. An attacker could potentially exploit this vulnerability, leading to… | |
| Aplazada | Alta (8.8) | 0.44% | — | Honeywell Pd45 Industrial PrinterAI | 24/9/2026 | 24/9/2026 | An Authenticated Remote Code Execution via Arbitrary File Write in the Intermec Fingerprint Command Interface vulnerability in the web management interface in Honeywell PD45 Industrial Printer version F10.19.010040, allows an authenticated user with access to the admin or itadmin account to submit commands written in… | |
| Pendiente de análisis | Media (6.9) | 0.37% | — | Sprintf-jsAI | 24/9/2026 | 24/9/2026 | sprintf-js through 1.1.3 passes unbounded precision specifiers to toFixed, toExponential, and toPrecision methods without validation, causing uncaught RangeError exceptions. Attackers who control format strings can inject precision values exceeding ECMAScript limits to abort calling operations with minimal payload. | |
| Aplazada | Baja (2) | 2.1% | — | OctoprintAI | 21/9/2026 | 22/9/2026 | A security flaw has been discovered in OctoPrint 1.0.0. Affected by this issue is the function executeSystemCommand of the file src/octoprint/server/api/system.py of the component Command API. Performing a manipulation of the argument command results in os command injection. It is possible to initiate the attack… | |
| Aplazada | Baja (2.1) | 0.52% | — | OctoprintAI | 21/9/2026 | 22/9/2026 | A vulnerability was identified in OctoPrint 1.0.0. Affected by this vulnerability is the function _validate of the file src/octoprint/server/api/files.py of the component File Download API. Such manipulation of the argument filename leads to path traversal. The attack may be performed from remote. The exploit is… | |
| Aplazada | Media (6.5) | 0.48% | — | InventreeAIKozea WeasyprintAI | 21/9/2026 | 24/9/2026 | InvenTree is an Open Source Inventory Management System. Prior to 1.4.0, privileged staff users who can author report or label templates can cause WeasyPrint report rendering to retrieve attacker-selected resources through the HTTP and HTTPS URL schemes or the local file URI scheme. The HTML(string=html).write_pdf()… | |
| Aplazada | Crítica (9.8) | 0.55% | — | WEB TO Print Online DesignerAI | 21/9/2026 | 21/9/2026 | The Web to Print Online Designer WordPress plugin before 2.15.0 does not validate the type or extension of uploaded files, and hands the token protecting those uploads to any visitor who asks for it, allowing unauthenticated attackers to upload arbitrary files, including PHP ones, and run code on the server. | |
| Aplazada | Alta (7.5) | 0.94% | — | Printcart WEB TO Print Product DesignerAI | 18/9/2026 | 18/9/2026 | The Printcart Web to Print Product Designer for WooCommerce plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 2.8.5 via the 'mockups' parameter. This makes it possible for unauthenticated attackers to read the contents of arbitrary files on the server, which can contain… | |
| Analizada | Crítica (9.3) | 1.0% | — | HP Linux Imaging AND Printing | 16/9/2026 | 21/9/2026 | HP has identified and remediated multiple externally reported vulnerabilities within HPLIP. The findings affect several software components that could potentially enable remote code execution, privilege escalation, denial of service, information disclosure, or unauthorized file modification under certain conditions. | |
| Analizada | Alta (8.6) | 1.0% | — | HP Linux Imaging AND Printing | 16/9/2026 | 21/9/2026 | HP has identified and remediated multiple externally reported vulnerabilities within HPLIP. The findings affect several software components that could potentially enable remote code execution, privilege escalation, denial of service, information disclosure, or unauthorized file modification under certain conditions. | |
| Analizada | Crítica (9.3) | 1.1% | — | HP Linux Imaging AND Printing | 16/9/2026 | 21/9/2026 | HP has identified and remediated multiple externally reported vulnerabilities within HPLIP. The findings affect several software components that could potentially enable remote code execution, privilege escalation, denial of service, information disclosure, or unauthorized file modification under certain conditions. | |
| Analizada | Media (5.1) | 0.97% | — | HP Linux Imaging AND Printing | 16/9/2026 | 21/9/2026 | HP has identified and remediated multiple externally reported vulnerabilities within HPLIP. The findings affect several software components that could potentially enable remote code execution, privilege escalation, denial of service, information disclosure, or unauthorized file modification under certain conditions. | |
| Analizada | Alta (8.4) | 0.79% | — | HP Linux Imaging AND Printing | 16/9/2026 | 21/9/2026 | HP has identified and remediated multiple externally reported vulnerabilities within HPLIP. The findings affect several software components that could potentially enable remote code execution, privilege escalation, denial of service, information disclosure, or unauthorized file modification under certain conditions. | |
| Analizada | Media (5.1) | 0.97% | — | HP Linux Imaging AND Printing | 16/9/2026 | 21/9/2026 | HP has identified and remediated multiple externally reported vulnerabilities within HPLIP. The findings affect several software components that could potentially enable remote code execution, privilege escalation, denial of service, information disclosure, or unauthorized file modification under certain conditions. | |
| Analizada | Media (6.8) | 0.72% | — | HP Linux Imaging AND Printing | 16/9/2026 | 21/9/2026 | HP has identified and remediated multiple externally reported vulnerabilities within HPLIP. The findings affect several software components that could potentially enable remote code execution, privilege escalation, denial of service, information disclosure, or unauthorized file modification under certain conditions. | |
| Analizada | Media (5.1) | 0.98% | — | HP Linux Imaging AND Printing | 16/9/2026 | 21/9/2026 | HP has identified and remediated multiple externally reported vulnerabilities within HPLIP. The findings affect several software components that could potentially enable remote code execution, privilege escalation, denial of service, information disclosure, or unauthorized file modification under certain conditions. | |
| Analizada | Alta (8.6) | 1.0% | — | HP Linux Imaging AND Printing | 16/9/2026 | 21/9/2026 | HP has identified and remediated multiple externally reported vulnerabilities within HPLIP. The findings affect several software components that could potentially enable remote code execution, privilege escalation, denial of service, information disclosure, or unauthorized file modification under certain conditions. | |
| Analizada | Alta (7) | 1.0% | — | HP Linux Imaging AND Printing | 16/9/2026 | 21/9/2026 | HP has identified and remediated multiple externally reported vulnerabilities within HPLIP. The findings affect several software components that could potentially enable remote code execution, privilege escalation, denial of service, information disclosure, or unauthorized file modification under certain conditions. | |
| Aplazada | Media (6.2) | 0.22% | — | Kozea WeasyprintAI | 14/9/2026 | 23/9/2026 | WeasyPrint helps web developers to create PDF documents. Prior to 70.0, server-side applications that configure a restrictive url_fetcher and pass attacker-influenced values to HTML.write_pdf() can have the restriction bypassed through the xmp_metadata or stylesheets options. In weasyprint/pdf/init.py, xmp_metadata… | |
| Pendiente de análisis | Alta (8.5) | 2.3% | — | Amazon Codecatalyst-blueprintsAI | 3/9/2026 | 8/9/2026 | Improper neutralization of special elements used in an OS command (CWE-78) in the blueprint resynthesis framework in Amazon Web Services codecatalyst-blueprints before 0.3.156 might allow a user with permission to commit to a repository in the project to execute arbitrary commands in the blueprint resynthesis… | |
| Aplazada | Media (6.5) | 0.37% | — | WOO Barcode Labels Print Barcode LabelsAI | 31/8/2026 | 1/9/2026 | Subscriber Sensitive Data Exposure in Print Barcode Labels for your WooCommerce products/orders <= 4.0.0 versions. | |
| Aplazada | Alta (8.6) | 0.53% | — | Mapfish PrintAI | 28/8/2026 | 9/9/2026 | mapfish-print is a component of MapFish for printing templated cartographic maps. Prior to 3.28.30, 3.30.32, 3.31.24, 3.33.16, and 4.0.5, MapFish Print accepts an attacker-controlled GML layer url in requests to the /api/print3/print endpoint and fetches XML parsed by… | |
| Aplazada | Alta (8.2) | 0.41% | — | RansomlookAIKozea WeasyprintAI | 24/8/2026 | 26/8/2026 | RansomLook contains insufficient resource validation in the analysis PDF generation functionality. Analysis documents are converted from Markdown to HTML and passed to WeasyPrint for PDF rendering. Prior to the fix, WeasyPrint used its default URL fetcher, allowing resource references contained in an analysis to be… | |
| Pendiente de análisis | Alta (7) | 0.32% | — | OctoprintAI | 21/8/2026 | 30/9/2026 | OctoPrint provides a web interface for controlling consumer 3D printers. Prior to 1.11.8 and 2.0.0rc3, OctoPrint's custom Tornado upload handler and Flask with Werkzeug parse request parameters differently, allowing an attacker with FILE_UPLOAD permission to inject reserved internal upload fields through query… |