Vulnerability index

Browse CVEs

105 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Freeflow Core HIGH 7.5
CVE-2026-2252

An XML External Entity (XXE) vulnerability allows malicious user to perform Server-Side Request Forgery (SSRF) via crafted XML input containing malic…

Fix: 8.1.0+
Fix from $1,950 2026-02-27
Freeflow Core CRITICAL 9.8
CVE-2026-2251

Improper limitation of a pathname to a restricted directory (Path Traversal) vulnerability in Xerox FreeFlow Core allows unauthorized path traversal …

Fix: 8.1.0+
Fix from $2,300 2026-02-27
Centreware Web MEDIUM 5.4
CVE-2026-1769

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Xerox CentreWare on Windows allows Store…

Fix: after 7.0.6
Fix from $1,600 2026-02-06
Freeflow Core CRITICAL 9.8
CVE-2025-8356EPSS 15%

In Xerox FreeFlow Core version 8.0.4, an attacker can exploit a Path Traversal vulnerability to access unauthorized files on the server. This can lea…

Mitigation only
Fix from $2,300 2025-08-08
Freeflow Core HIGH 7.5
CVE-2025-8355EPSS 7%

In Xerox FreeFlow Core version 8.0.4, improper handling of XML input allows injection of external entities. An attacker can craft malicious XML conta…

Mitigation only
Fix from $1,950 2025-08-08
Workplace Suite MEDIUM 6.5
CVE-2024-55931

Xerox Workplace Suite stores tokens in session storage, which may expose them to potential access if a user's session is compromised.  The patch for…

Fix: 5.6.701.9+
Fix from $1,600 2025-01-27
Workplace Suite CRITICAL 9.8
CVE-2024-55930

Xerox Workplace Suite has weak default folder permissions that allow unauthorized users to access, modify, or delete files

Fix: 5.6.701.9+
Fix from $2,300 2025-01-23
Workplace Suite HIGH 7.5
CVE-2024-55928

Xerox Workplace Suite exposes sensitive secrets in clear text, both locally and remotely. This vulnerability allows attackers to intercept or access …

Fix: 5.6.701.9+
Fix from $1,950 2025-01-23
Workplace Suite MEDIUM 5.3
CVE-2024-55929

A mail spoofing vulnerability in Xerox Workplace Suite allows attackers to forge email headers, making it appear as though messages are sent from tru…

Fix: 5.6.701.9+
Fix from $1,600 2025-01-23
Workplace Suite CRITICAL 9.8
CVE-2024-55926

A vulnerability found in Xerox Workplace Suite allows arbitrary file read, upload, and deletion on the server through crafted header manipulation. By…

Fix: 5.6.701.9+
Fix from $2,300 2025-01-23
Workplace Suite HIGH 7.5
CVE-2024-55927

A vulnerability in Xerox Workplace Suite arises from flawed token generation and the use of hard-coded keys. These weaknesses allow attackers to pred…

Fix: 5.6.701.9+
Fix from $1,950 2025-01-23
Workplace Suite HIGH 7.5
CVE-2024-55925

In Xerox Workplace Suite, an API restricted to specific hosts can be bypassed by manipulating the Host header. If the server improperly validates or …

Fix: 5.6.701.9+
Fix from $1,950 2025-01-23
Freeflow Core CRITICAL 9.8
CVE-2024-47556

Pre-Auth RCE via Path Traversal

Fix: 7.0.11+
Fix from $2,300 2024-10-07
Freeflow Core CRITICAL 9.8
CVE-2024-47557

Pre-Auth RCE via Path Traversal

Fix: 7.0.11+
Fix from $2,300 2024-10-07
Freeflow Core HIGH 8.8
CVE-2024-47558

Authenticated RCE via Path Traversal

Mitigation only
Fix from $1,950 2024-10-07
Freeflow Core HIGH 8.8
CVE-2024-47559

Authenticated RCE via Path Traversal

Mitigation only
Fix from $1,950 2024-10-07
Primelink C9065 Firmware MEDIUM 5.9
CVE-2023-46327

Multiple MFPs (multifunction printers) provided by FUJIFILM Business Innovation Corp. and Xerox Corporation provide a facility to export the contents…

Fix: 68.81.41 / 85.40.31+
Fix from $1,600 2023-11-02
Workcentre 3550 Firmware MEDIUM 6.5
CVE-2022-45897

On Xerox WorkCentre 3550 25.003.03.000 devices, an authenticated attacker can view the SMB server settings and can obtain the stored cleartext creden…

Mitigation only
Fix from $1,600 2023-01-31
Colorqube 8580 Firmware HIGH 7.5
CVE-2022-26572

Xerox ColorQube 8580 was discovered to contain an access control issue which allows attackers to print, view the status, and obtain sensitive informa…

Mitigation only
Fix from $1,950 2022-04-04
Phaser 4622 Firmware CRITICAL 9.8
CVE-2021-37354

Xerox Phaser 4622 v35.013.01.000 was discovered to contain a buffer overflow in the function sub_3226AC via the TIMEZONE variable. This vulnerability…

No fix yet
Fix from $2,300 2022-02-15
Xmpie Ustore HIGH 7.5
CVE-2022-23320

XMPie uStore 12.3.7244.0 allows for administrators to generate reports based on raw SQL queries. Since the application ships with default administrat…

No fix yet
Fix from $1,950 2022-02-07
Versalink Firmware HIGH 7.5
CVE-2022-23968

Xerox VersaLink devices on specific versions of firmware before 2022-01-26 allow remote attackers to brick the device via a crafted TIFF file in an u…

Fix: after 50.61
Fix from $1,950 2022-01-26
Altalink B8045 Firmware CRITICAL 9.8
CVE-2019-10881

Xerox AltaLink B8045/B8055/B8065/B8075/B8090, AltaLink C8030/C8035/C8045/C8055/C8070 with software releases before 103.xxx.030.32000 includes two acc…

Fix: 103.001.010.14010 / 103.002.010.14010+
Fix from $2,300 2021-04-13
Phaser 6510 Firmware CRITICAL 9.8
CVE-2021-28671

Xerox Phaser 6510 before 64.65.51 and 64.59.11 (Bridge), WorkCentre 6515 before 65.65.51 and 65.59.11 (Bridge), VersaLink B400 before 37.65.51 and 37…

Fix: 32.59.01 / 32.65.51+
Fix from $2,300 2021-03-29
Phaser 6510 Firmware CRITICAL 9.8
CVE-2021-28672

Xerox Phaser 6510 before 64.65.51 and 64.59.11 (Bridge), WorkCentre 6515 before 65.65.51 and 65.59.11 (Bridge), VersaLink B400 before 37.65.51 and 37…

Fix: 32.59.01 / 32.65.51+
Fix from $2,300 2021-03-29
Altalink B8045 Firmware CRITICAL 9.8
CVE-2021-28668

Xerox AltaLink B80xx before 103.008.020.23120, C8030/C8035 before 103.001.020.23120, C8045/C8055 before 103.002.020.23120 and C8070 before 103.003.02…

Fix: 103.001.020.23120 / 103.002.020.23120+
Fix from $2,300 2021-03-29
Phaser 6510 Firmware CRITICAL 9.8
CVE-2021-28673

Xerox Phaser 6510 before 64.61.23 and 64.59.11 (Bridge), WorkCentre 6515 before 65.61.23 and 65.59.11 (Bridge), VersaLink B400 before 37.61.23 and 37…

Fix: 32.59.01 / 32.61.23+
Fix from $2,300 2021-03-29
Altalink B8045 Firmware HIGH 7.5
CVE-2021-28669

Xerox AltaLink B80xx before 103.008.020.23120, C8030/C8035 before 103.001.020.23120, C8045/C8055 before 103.002.020.23120 and C8070 before 103.003.02…

Fix: 103.001.020.23120 / 103.002.020.23120+
Fix from $1,950 2021-03-29
Altalink B8045 Firmware CRITICAL 9.1
CVE-2021-28670

Xerox AltaLink B8045/B8090 before 103.008.030.32000, C8030/C8035 before 103.001.030.32000, C8045/C8055 before 103.002.030.32000 and C8070 before 103.…

Fix: 103.001.020.23120 / 103.002.020.23120+
Fix from $2,300 2021-03-29
Altalink B8045 Firmware HIGH 7.5
CVE-2019-18630

On Xerox AltaLink B8045/B8055/B8065/B8075/B8090 and C8030/C8035/C8045/C8055/C8070 multifunction printers with software releases before 101.00x.099.28…

Fix: 103.001.010.14010 / 103.002.010.14010+
Fix from $1,950 2021-03-04