Vulnerabilidades en PaperCut
35 resultadosAnálisis Vexday
PaperCut apresenta um portfólio moderado de 27 vulnerabilidades com 3 atualmente sob ataque ativo, indicando risco operacional imediato. Apesar de apenas 1 crítica, a recentidade é preocupante: 4 CVEs nos últimos 90 dias e a dominância de CWE-76 (injeção) sugerem padrão de defeitos exploráveis em lógica de aplicação. Organizações usuárias devem priorizar patches recentes e monitorar os 3 CVEs em exploração ativa.
CVE-2023-27350CRITICALThis vulnerability allows remote attackers to bypass authentication on affected installations of PaperCut NG 22.0.5 (Build 63914). AuthenticEPSS 100.0%KEVCVE-2023-3486HIGHPaperCut NG Unauthenticated File UploadEPSS 79.2%CVE-2023-27351HIGHThis vulnerability allows remote attackers to bypass authentication on affected installations of PaperCut NG 22.0.5 (Build 63914). AuthenticEPSS 78.1%KEVCVE-2024-1222HIGHIncorrect authorization controls in PaperCut NG/MF APIsEPSS 64.0%CVE-2024-1883MEDIUMReflected XSS in PaperCut NG/MFEPSS 61.5%CVE-2023-39469HIGHPaperCut NG External User Lookup Code Injection Remote Code Execution VulnerabilityEPSS 61.4%CVE-2024-1884MEDIUMServer Side Request Forgery in PaperCut NG/MFEPSS 37.9%CVE-2023-2533HIGHPaperCut MF/NG 22.0.10 (Build 65996 2023-03-27) - Remote code execution via CSRFEPSS 29.2%KEVCVE-2026-81578HIGHPaperCut MF/NG: Authentication BypassEPSS 4.5%KEVCVE-2023-4568MEDIUMPaperCut NG Unauthenticated XMLRPCEPSS 3.9%CVE-2026-82078CRITICALPaperCut MF/NG: Unsafe Dynamic Class Loading in Database ConnectorEPSS 3.8%KEVCVE-2023-39470HIGHPaperCut NG print.script.sandboxed Exposed Dangerous Function Remote Code Execution VulnerabilityEPSS 1.8%CVE-2024-1882HIGHServer-side resource injection in PaperCut NG/MFEPSS 1.4%CVE-2024-1654HIGHUnauthorized write operations in PaperCut NG/MFEPSS 1.3%CVE-2026-82077HIGHPaperCut NG/MF: Remote Code Execution via Scan2FaxEPSS 0.7%CVE-2026-8793MEDIUMPaperCut NG/MF: Insufficient brute-force protectionEPSS 0.7%CVE-2026-8794MEDIUMPaperCut NG/MF: User enumeration via timing attackEPSS 0.7%CVE-2026-6418MEDIUMPaperCut NG/MF: Path Traversal in Shared Account SynchronizationEPSS 0.6%CVE-2024-1221LOWImproper access controls on APIs on Linux and macOS in PaperCut NG/MFEPSS 0.5%CVE-2024-1223MEDIUMImproper authorization controls in PaperCut NG/MFEPSS 0.4%