Vulnerability index

Browse CVEs

33 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Freeflow Core CRITICAL 9.8
CVE-2025-8356EPSS 15%

In Xerox FreeFlow Core version 8.0.4, an attacker can exploit a Path Traversal vulnerability to access unauthorized files on the server. This can lea…

Mitigation only
Fix from $2,300 2025-08-08
Freeflow Core HIGH 7.5
CVE-2025-8355EPSS 7%

In Xerox FreeFlow Core version 8.0.4, improper handling of XML input allows injection of external entities. An attacker can craft malicious XML conta…

Mitigation only
Fix from $1,950 2025-08-08
Freeflow Core HIGH 8.8
CVE-2024-47558

Authenticated RCE via Path Traversal

Mitigation only
Fix from $1,950 2024-10-07
Freeflow Core HIGH 8.8
CVE-2024-47559

Authenticated RCE via Path Traversal

Mitigation only
Fix from $1,950 2024-10-07
Workcentre 3550 Firmware MEDIUM 6.5
CVE-2022-45897

On Xerox WorkCentre 3550 25.003.03.000 devices, an authenticated attacker can view the SMB server settings and can obtain the stored cleartext creden…

Mitigation only
Fix from $1,600 2023-01-31
Colorqube 8580 Firmware HIGH 7.5
CVE-2022-26572

Xerox ColorQube 8580 was discovered to contain an access control issue which allows attackers to print, view the status, and obtain sensitive informa…

Mitigation only
Fix from $1,950 2022-04-04
Phaser 4622 Firmware CRITICAL 9.8
CVE-2021-37354

Xerox Phaser 4622 v35.013.01.000 was discovered to contain a buffer overflow in the function sub_3226AC via the TIMEZONE variable. This vulnerability…

No fix yet
Fix from $2,300 2022-02-15
Xmpie Ustore HIGH 7.5
CVE-2022-23320

XMPie uStore 12.3.7244.0 allows for administrators to generate reports based on raw SQL queries. Since the application ships with default administrat…

No fix yet
Fix from $1,950 2022-02-07
Phaser 3320 Firmware CRITICAL 9.8
CVE-2019-13171

Some Xerox printers (such as the Phaser 3320 V53.006.16.000) were affected by one or more stack-based buffer overflow vulnerabilities in the Google C…

Mitigation only
Fix from $2,300 2020-03-13
Phaser 3320 Firmware CRITICAL 9.8
CVE-2019-13172

Some Xerox printers (such as the Phaser 3320 V53.006.16.000) were affected by a buffer overflow vulnerability in the Authentication Cookie of the web…

Mitigation only
Fix from $2,300 2020-03-13
Phaser 3320 Firmware CRITICAL 9.8
CVE-2019-13165

Some Xerox printers (such as the Phaser 3320 V53.006.16.000) were affected by a buffer overflow vulnerability in the request parser of the IPP servic…

Mitigation only
Fix from $2,300 2020-03-13
Phaser 3320 Firmware CRITICAL 9.8
CVE-2019-13168

Some Xerox printers (such as the Phaser 3320 V53.006.16.000) were affected by a buffer overflow vulnerability in the attributes parser of the IPP ser…

Mitigation only
Fix from $2,300 2020-03-13
Phaser 3320 Firmware CRITICAL 9.8
CVE-2019-13169

Some Xerox printers (such as the Phaser 3320 V53.006.16.000) were affected by a buffer overflow vulnerability in the Content-Type HTTP Header of the …

Mitigation only
Fix from $2,300 2020-03-13
Phaser 3320 Firmware HIGH 7.5
CVE-2019-13166

Some Xerox printers (such as the Phaser 3320 V53.006.16.000) did not implement account lockout. Local account credentials may be extracted from the d…

Mitigation only
Fix from $1,950 2020-03-13
Phaser 3320 Firmware MEDIUM 6.5
CVE-2019-13170

Some Xerox printers (such as the Phaser 3320 V53.006.16.000) did not implement any mechanism to avoid CSRF attacks. Successful exploitation of this v…

Mitigation only
Fix from $1,600 2020-03-13
Phaser 3320 Firmware MEDIUM 6.1
CVE-2019-13167

Multiple Stored XSS vulnerabilities were found in the Xerox Web Application, used by the Phaser 3320 V53.006.16.000 and other printers. Successful ex…

Mitigation only
Fix from $1,600 2020-03-13
Colorqube 9201 Firmware CRITICAL 9.8
CVE-2013-6362

Xerox ColorCube and WorkCenter devices in 2013 had hardcoded FTP and shell user accounts.

No fix yet
Fix from $2,300 2020-02-13
Altalink C8035 Firmware HIGH 8.8
CVE-2019-19832

Xerox AltaLink C8035 printers allow CSRF. A request to add users is made in the Device User Database form field to the xerox.set URI. (The frmUserNam…

No fix yet
Fix from $1,950 2019-12-18
Atlalink Firmware CRITICAL 9.8
CVE-2019-17184

Xerox AtlaLink B8045/B8055/B8065/B8075/B8090 C8030/C8035/C8045/C8055/C8070 printers with software before 101.00x.089.22600 allow an attacker to gain …

No fix yet
Fix from $2,300 2019-10-04
Colorqube 8580 Firmware MEDIUM 6.1
CVE-2018-15530

Cross-site scripting (XSS) in the web interface of the Xerox ColorQube 8580 allows remote persistent injection of custom HTML / JavaScript code.

No fix yet
Fix from $1,600 2019-05-13
Docushare MEDIUM 6.5
CVE-2014-3138

SQL injection vulnerability in Xerox DocuShare before 6.53 Patch 6 Hotfix 2, 6.6.1 Update 1 before Hotfix 24, and 6.6.1 Update 2 before Hotfix 3 allo…

No fix yet
Fix from $1,600 2014-05-02
Fiery Webtools HIGH 7.5
CVE-2009-3913

SQL injection vulnerability in summary.php in Xerox Fiery Webtools allows remote attackers to execute arbitrary SQL commands via the select parameter.

Mitigation only
Fix from $1,950 2009-11-09
Phaser HIGH 7.8
CVE-2008-3571EPSS 36%

The Xerox Phaser 8400 allows remote attackers to cause a denial of service (reboot) via an empty UDP packet to port 1900.

No fix yet
Fix from $1,950 2008-08-10
Workcentre 232 HIGH 7.8
CVE-2006-6430

Web services in Xerox WorkCentre and WorkCentre Pro before 12.060.17.000, 13.x before 13.060.17.000, and 14.x before 14.060.17.000 do not require HTT…

Mitigation only
Fix from $1,950 2006-12-10
Workcentre 232 HIGH 7.8
CVE-2006-6439

Xerox WorkCentre and WorkCentre Pro before 12.050.03.000, 13.x before 13.050.03.000, and 14.x before 14.050.03.000 allows remote attackers to downloa…

Mitigation only
Fix from $1,950 2006-12-10
Workcentre 232 HIGH 7.5
CVE-2006-6434

Unspecified vulnerability in the Web User Interface in Xerox WorkCentre and WorkCentre Pro before 12.050.03.000, 13.x before 13.050.03.000, and 14.x …

Mitigation only
Fix from $1,950 2006-12-10
Workcentre 232 HIGH 7.5
CVE-2006-6440

Multiple unspecified vulnerabilities in Xerox WorkCentre and WorkCentre Pro before 12.050.03.000, 13.x before 13.050.03.000, and 14.x before 14.050.0…

Mitigation only
Fix from $1,950 2006-12-10
Workcentre 232 MEDIUM 6.8
CVE-2006-6436

Cross-site scripting (XSS) vulnerability in the Network controller in Xerox WorkCentre and WorkCentre Pro before 12.050.03.000, 13.x before 13.050.03…

Mitigation only
Fix from $1,600 2006-12-10
Docutech 6110 HIGH 7.5
CVE-2002-1833

The default configurations for DocuTech 6110 and DocuTech 6115 have a default administrative password of (1) "service!" on Solaris 8.0 or (2) "admini…

Mitigation only
Fix from $1,950 2002-12-31
Docutech 6110 HIGH 7.5
CVE-2002-1835

The default configuration of Xerox DocuTech 6110 and DocuTech 6115 running Solaris 8.0 has a large number of unnecessary services enabled such as RPC…

Mitigation only
Fix from $1,950 2002-12-31