Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2696▼ 543 respecto a la semana anterior
Críticas / altas1264▼ 228 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)262▼ 241 respecto a la semana anterior
195 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Pendiente de análisis | Alta (8.7) | 0.81% | — | Sharp Multifunction PrinterAIToshibatec Multifunction PrinterAI | 1/10/2026 | 6/10/2026 | Sharp (and Toshiba Tec rebranded) multifunction printers contain an unauthenticated local file inclusion vulnerability that allows remote attackers to read arbitrary files by manipulating the path parameter in the installed_emanual_down.html endpoint. Attackers can supply directory traversal sequences such as… | |
| Aplazada | Crítica (9.8) | 0.57% | 💥 PoC | Honeywell Pd45 Industrial PrinterAI | 24/9/2026 | 24/9/2026 | An unauthenticated Remote Code Execution via Arbitrary File Upload vulnerability in the web management interface in Honeywell PD45 Industrial Printer version F10.19.010040, allows upload of attacker controlled files without requiring authentication. An attacker could potentially exploit this vulnerability, leading to… | |
| Aplazada | Alta (8.8) | 0.44% | — | Honeywell Pd45 Industrial PrinterAI | 24/9/2026 | 24/9/2026 | An Authenticated Remote Code Execution via Arbitrary File Write in the Intermec Fingerprint Command Interface vulnerability in the web management interface in Honeywell PD45 Industrial Printer version F10.19.010040, allows an authenticated user with access to the admin or itadmin account to submit commands written in… | |
| Aplazada | Media (6.3) | 0.18% | — | Seiko Epson PrintersAISeiko Epson ScannersAI | 20/8/2026 | 28/8/2026 | Multiple SEIKO EPSON printers and scanners contain revoked root certificates. A man-in-the-middle attack may allow an attacker to obtain communication data transmitted by the product. As for the details of the affected products and versions, refer to the vendor's information. | |
| Aplazada | Media (6.9) | 0.38% | — | Ricoh PrintersAIRicoh Multifunction PrintersAI | 23/7/2026 | 23/7/2026 | Printers and Multifunction Printers (MFPs) provided by Ricoh Company, Ltd. do not implement restrictions on SSH port forwarding, allowing to connect to arbitrary destinations. When SSH is enabled on an affected product, SSH port forwarding may be leveraged to connect to other node on the LAN. | |
| Aplazada | Alta (8.5) | 0.18% | — | Ricoh Printer DriversAIKonicaminolta Printer DriversAI | 15/6/2026 | 24/7/2026 | Multiple printer drivers provided by Ricoh Company, Ltd. and KONICA MINOLTA JAPAN, INC. contain a privilege escalation vulnerability. If this vulnerability is exploited, an attacker who can log in to a computer running an affected printer driver could elevate privileges by using a specially crafted driver. | |
| Pendiente de análisis | Media (5.1) | 0.16% | — | Canon Pixus Ix6800 Series Cups Printer DriverAICanon Pixma Mg2500 Series Cups Printer DriverAI | 29/5/2026 | 21/7/2026 | Improper handling of symbolic links in the installer of CUPS Printer Driver for macOS(*) may allow a local attacker with login privileges to exploit a specially crafted symbolic link during installation to modify permissions of directories for which they would not normally have authorization. *:Canon PIXUS iX6800… | |
| Aplazada | Alta (7.8) | 0.13% | — | Epson Printer Driver InstallerAI | 19/2/2026 | 17/6/2026 | The com.epson.InstallNavi.helper tool, deployed with the EPSON printer driver installer, contains a local privilege escalation vulnerability due to multiple flaws in its implementation. It fails to properly authenticate clients over the XPC protocol and does not correctly enforce macOS’s authorization model, exposing… | |
| Aplazada | Alta (8.7) | 0.81% | — | AMR Printer ManagementAI | 18/2/2026 | 17/6/2026 | Path traversal vulnerability in the AMR Printer Management 1.01 Beta web service, which allows remote attackers to read arbitrary files from the underlying Windows system by using specially crafted path traversal sequences in requests directed to the web management service. The service is accessible without… | |
| Modificada | Baja (2.1) | 0.45% | — | Harry0703 Moneyprinterturbo | 11/10/2025 | 17/6/2026 | A weakness has been identified in harry0703 MoneyPrinterTurbo up to 1.2.6. The impacted element is the function upload_music of the file app/controllers/v1/music.py of the component API Endpoint. Executing a manipulation of the argument File can lead to path traversal. The attack may be performed from remote. The… | |
| Aplazada | Media (6.9) | 0.38% | — | Canon Generic Plus Pcl6 Printer DriverAICanon Generic Plus UFR II Printer DriverAICanon Generic Plus Lips4 Printer DriverAICanon Generic Plus Lipslx Printer DriverAI+9 | 29/9/2025 | 17/6/2026 | Unallocated memory access vulnerability in print processing of Generic Plus PCL6 Printer Driver / Generic Plus UFR II Printer Driver / Generic Plus LIPS4 Printer Driver / Generic Plus LIPSLX Printer Driver / Generic Plus PS Printer Driver / UFRII LT Printer Driver / CARPS2 Printer Driver / Generic FAX Driver / LIPS4… | |
| Aplazada | Media (5.9) | 0.36% | — | Canon Generic Plus Pcl6 Printer DriverAICanon Generic Plus UFR II Printer DriverAICanon Generic Plus Lips4 Printer DriverAICanon Generic Plus Lipslx Printer DriverAI+9 | 29/9/2025 | 17/6/2026 | Out-of-bounds write vulnerabilities in print processing of Generic Plus PCL6 Printer Driver / Generic Plus UFR II Printer Driver / Generic Plus LIPS4 Printer Driver / Generic Plus LIPSLX Printer Driver / Generic Plus PS Printer Driver / UFRII LT Printer Driver / CARPS2 Printer Driver / Generic FAX Driver / LIPS4… | |
| Aplazada | Media (5.9) | 0.31% | — | Canon Generic Plus Pcl6 Printer DriverAICanon Generic Plus UFR II Printer DriverAICanon Generic Plus Lips4 Printer DriverAICanon Generic Plus Lipslx Printer DriverAI+9 | 29/9/2025 | 17/6/2026 | Out-of-bounds read vulnerabilities in print processing of Generic Plus PCL6 Printer Driver / Generic Plus UFR II Printer Driver / Generic Plus LIPS4 Printer Driver / Generic Plus LIPSLX Printer Driver / Generic Plus PS Printer Driver / UFRII LT Printer Driver / CARPS2 Printer Driver / Generic FAX Driver / LIPS4… | |
| Analizada | Media (5.5) | 0.84% | — | Harry0703 Moneyprinterturbo | 15/9/2025 | 17/6/2026 | A vulnerability has been found in harry0703 MoneyPrinterTurbo up to 1.2.6. The impacted element is the function download_video/stream_video of the file app/controllers/v1/video.py of the component URL Handler. The manipulation of the argument file_path leads to path traversal. The attack can be initiated remotely. The… | |
| Analizada | Media (6.3) | 0.31% | — | Harry0703 Moneyprinterturbo | 15/9/2025 | 17/6/2026 | wangxutech MoneyPrinterTurbo 1.2.6 allows path traversal via /api/v1/download/ URIs such as /api/v1/download//etc/passwd. | |
| Aplazada | Media (5.3) | 0.20% | — | Lenovo PrintersAICupsAI | 11/9/2025 | 17/6/2026 | A missing authentication vulnerability was reported in some Lenovo printers that could allow a user to view limited device information or modify network settings via the CUPS service. | |
| Aplazada | Alta (8.2) | 0.15% | — | Lexmark Printer DriversAI | 19/8/2025 | 17/6/2026 | Improper Restriction of XML External Entity Reference in various Lexmark printer drivers for Windows allows attacker to disclose sensitive information to an arbitrary URL. | |
| Analizada | Media (6.9) | 0.68% | — | Harry0703 Moneyprinterturbo | 20/7/2025 | 17/6/2026 | A vulnerability was found in harry0703 MoneyPrinterTurbo up to 1.2.6 and classified as critical. Affected by this issue is the function verify_token of the file app/controllers/base.py of the component API Endpoint. The manipulation leads to missing authentication. The attack may be launched remotely. | |
| Analizada | Media (5.3) | 0.46% | — | Harry0703 Moneyprinterturbo | 20/7/2025 | 17/6/2026 | A vulnerability has been found in harry0703 MoneyPrinterTurbo up to 1.2.6 and classified as critical. Affected by this vulnerability is the function download_video/delete_video of the file app/controllers/v1/video.py. The manipulation leads to path traversal. The attack can be launched remotely. | |
| Analizada | Media (5.3) | 0.40% | — | Harry0703 Moneyprinterturbo | 20/7/2025 | 17/6/2026 | A vulnerability, which was classified as critical, was found in harry0703 MoneyPrinterTurbo up to 1.2.6. Affected is the function upload_bgm_file of the file app/controllers/v1/video.py of the component File Extension Handler. The manipulation of the argument File leads to unrestricted upload. It is possible to launch… | |
| Aplazada | Media (6.9) | 0.40% | — | M3M Printer Server WEBAI | 26/5/2025 | 17/6/2026 | User enumeration vulnerability in M3M Printer Server Web. This issue occurs during user authentication, where a difference in error messages could allow an attacker to determine whether a username is valid or not, allowing a brute force attack on valid usernames. | |
| Analizada | Alta (8) | 0.26% | — | Dynamixsoftware Printershare | 23/5/2025 | 17/6/2026 | A double-free condition occurs during the cleanup of temporary image files, which can be exploited to achieve memory corruption and potentially arbitrary code execution. | |
| Analizada | Crítica (9.8) | 0.69% | — | Dynamixsoftware Printershare | 23/5/2025 | 17/6/2026 | An Out of Bounds Write occurs when the native library attempts PDF rendering, which can be exploited to achieve memory corruption and potentially arbitrary code execution. | |
| Analizada | Crítica (9.1) | 0.30% | — | Dynamixsoftware Printershare | 23/5/2025 | 17/6/2026 | PrinterShare Android application allows the capture of Gmail authentication tokens that can be reused to access a user's Gmail account without proper authorization. | |
| Aplazada | Alta (8.4) | 0.21% | — | Seiko Epson Printer DriversAI | 28/4/2025 | 17/6/2026 | Multiple SEIKO EPSON printer drivers for Windows OS are configured with an improper access permission settings when installed or used in a language other than English. If a user is directed to place a crafted DLL file in a location of an attacker's choosing, the attacker may execute arbitrary code with SYSTEM… |