CVE-2023-35175Critical· 9.8▾ MidnightCertain HP LaserJet Pro print products are potentially vulnerable to Potential Remote Code Execution and/or Elevation of Privilege via Server-Side Request Forgery (SSRF) using the Web Service Eventing model.
▾ Midnight zone — Critical, or high with PoC / in-the-wild
impact 53.9 · likelihood 0.3 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Jul 4.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
Last analysed / modified upstream
1.8%
Certain HP LaserJet Pro print products are potentially vulnerable to Potential Remote Code Execution and/or Elevation of Privilege via Server-Side Request Forgery (SSRF) using the Web Service Eventing model.
w1a75a_firmware < 002_2322cw1a76a_firmware < 002_2322cw1a77a_firmware < 002_2322cw1a78a_firmware < 002_2322cw1a79a_firmware < 002_2322cw1a80a_firmware < 002_2322cw1a81a_firmware < 002_2322cw1a82a_firmware < 002_2322claserjet_pro_m453-m454_w1y40a_firmware < 002_2322claserjet_pro_m453-m454_w1y41a_firmware < 002_2322claserjet_pro_m453-m454_w1y43a_firmware < 002_2322claserjet_pro_m453-m454_w1y44a_firmware < 002_2322claserjet_pro_m453-m454_w1y45a_firmware < 002_2322claserjet_pro_m453-m454_w1y46a_firmware < 002_2322claserjet_pro_m453-m454_w1y47a_firmware < 002_2322claserjet_pro_m304-m305_w1a46a_firmware < 002_2322claserjet_pro_m304-m305_w1a47a_firmware < 002_2322claserjet_pro_m304-m305_w1a48a_firmware < 002_2322claserjet_pro_m304-m305_w1a66a_firmware < 002_2322claserjet_pro_m404-m405_93m22a_firmware < 002_2322claserjet_pro_m404-m405_w1a51a_firmware < 002_2322claserjet_pro_m404-m405_w1a52a_firmware < 002_2322claserjet_pro_m404-m405_w1a53a_firmware < 002_2322claserjet_pro_m404-m405_w1a56a_firmware < 002_2322claserjet_pro_m404-m405_w1a57a_firmware < 002_2322claserjet_pro_m404-m405_w1a58a_firmware < 002_2322claserjet_pro_m404-m405_w1a59a_firmware < 002_2322claserjet_pro_m404-m405_w1a60a_firmware < 002_2322claserjet_pro_m404-m405_w1a63a_firmware < 002_2322claserjet_pro_mfp_m428-m429_f_w1a29a_firmware < 002_2322claserjet_pro_mfp_m428-m429_f_w1a30a_firmware < 002_2322claserjet_pro_mfp_m428-m429_f_w1a32a_firmware < 002_2322claserjet_pro_mfp_m428-m429_f_w1a34a_firmware < 002_2322claserjet_pro_mfp_m428-m429_f_w1a35a_firmware < 002_2322claserjet_pro_mfp_m428-m429_f_w1a38a_firmware < 002_2322claserjet_pro_mfp_m428-m429_w1a28a_firmware < 002_2322claserjet_pro_mfp_m428-m429_w1a31a_firmware < 002_2322claserjet_pro_mfp_m428-m429_w1a33a_firmware < 002_2322cUpgrade past the affected range:
w1a75a_firmware 002_2322cw1a76a_firmware 002_2322cw1a77a_firmware 002_2322cw1a78a_firmware 002_2322cw1a79a_firmware 002_2322cw1a80a_firmware 002_2322cw1a81a_firmware 002_2322cw1a82a_firmware 002_2322claserjet_pro_m453-m454_w1y40a_firmware 002_2322claserjet_pro_m453-m454_w1y41a_firmware 002_2322claserjet_pro_m453-m454_w1y43a_firmware 002_2322claserjet_pro_m453-m454_w1y44a_firmware 002_2322claserjet_pro_m453-m454_w1y45a_firmware 002_2322claserjet_pro_m453-m454_w1y46a_firmware 002_2322claserjet_pro_m453-m454_w1y47a_firmware 002_2322claserjet_pro_m304-m305_w1a46a_firmware 002_2322claserjet_pro_m304-m305_w1a47a_firmware 002_2322claserjet_pro_m304-m305_w1a48a_firmware 002_2322claserjet_pro_m304-m305_w1a66a_firmware 002_2322claserjet_pro_m404-m405_93m22a_firmware 002_2322claserjet_pro_m404-m405_w1a51a_firmware 002_2322claserjet_pro_m404-m405_w1a52a_firmware 002_2322claserjet_pro_m404-m405_w1a53a_firmware 002_2322claserjet_pro_m404-m405_w1a56a_firmware 002_2322claserjet_pro_m404-m405_w1a57a_firmware 002_2322claserjet_pro_m404-m405_w1a58a_firmware 002_2322claserjet_pro_m404-m405_w1a59a_firmware 002_2322claserjet_pro_m404-m405_w1a60a_firmware 002_2322claserjet_pro_m404-m405_w1a63a_firmware 002_2322claserjet_pro_mfp_m428-m429_f_w1a29a_firmware 002_2322claserjet_pro_mfp_m428-m429_f_w1a30a_firmware 002_2322claserjet_pro_mfp_m428-m429_f_w1a32a_firmware 002_2322claserjet_pro_mfp_m428-m429_f_w1a34a_firmware 002_2322claserjet_pro_mfp_m428-m429_f_w1a35a_firmware 002_2322claserjet_pro_mfp_m428-m429_f_w1a38a_firmware 002_2322claserjet_pro_mfp_m428-m429_w1a28a_firmware 002_2322claserjet_pro_mfp_m428-m429_w1a31a_firmware 002_2322claserjet_pro_mfp_m428-m429_w1a33a_firmware 002_2322cConnected by shared product, vendor, weakness, or advisory.
CVE-2025-68616High· 7.5WeasyPrint helps web developers to create PDF documents
CVE-2023-35178High· 8.8Certain HP LaserJet Pro print products are potentially vulnerable to Buffer Overflow when performing a GET request to scan jobs.
CVE-2023-35177High· 8.8Certain HP LaserJet Pro print products are potentially vulnerable to a stack-based buffer overflow related to the compact font format parser.
CVE-2023-35176High· 8.8Certain HP LaserJet Pro print products are potentially vulnerable to Buffer Overflow and/or Denial of Service when using the backup & restore feature through the embedded web service on the device.
CVE-2026-12992High· 7.4A flaw was found in Apicurio Registry
CVE-2021-21985Critical· 9.8The vSphere Client (HTML5) contains a remote code execution vulnerability due to lack of input validation in the Virtual SAN Health Check plug-in which is enabled by default in vCenter Server