Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

Lexmark

857 known vulnerabilities

23
CRITICAL
18
HIGH
14
MEDIUM

Top Products

cx310 firmware 17 cx310 17 cs41x firmware 14 cs41x 14 ms310 firmware 14 ms310 14 ms312 firmware 14 ms312 14 cs31x firmware 13 cs31x 13
55 CVEs · Page 1/2
7.5
CVE-2023-40239

Certain Lexmark devices (such as CS310) before 2023-08-25 allow XXE attacks, leading to information disclosure. The fixe

9.8
CVE-2023-26070

Certain Lexmark devices through 2023-02-19 mishandle Input Validation (issue 4 of 4).

9.8
CVE-2023-26069

Certain Lexmark devices through 2023-02-19 mishandle Input Validation (issue 3 of 4).

9.8
CVE-2023-26068

Certain Lexmark devices through 2023-02-19 mishandle Input Validation (issue 2 of 4).

8.1
CVE-2023-26067

Certain Lexmark devices through 2023-02-19 mishandle Input Validation (issue 1 of 4).

9.8
CVE-2023-26066

Certain Lexmark devices through 2023-02-19 have Improper Validation of an Array Index.

9.8
CVE-2023-26065

Certain Lexmark devices through 2023-02-19 have an Integer Overflow.

9.8
CVE-2023-26064

Certain Lexmark devices through 2023-02-19 have an Out-of-bounds Write.

9.8
CVE-2023-26063

Certain Lexmark devices through 2023-02-19 access a Resource By Using an Incompatible Type.

9.8
CVE-2023-23560

In certain Lexmark products through 2023-01-12, SSRF can occur because of a lack of input validation.

7.5
CVE-2023-22960

Lexmark products through 2023-01-10 have Improper Control of Interaction Frequency.

8.1
CVE-2022-29850

Various Lexmark products through 2022-04-27 allow an attacker who has already compromised an affected Lexmark device to

7.5
CVE-2022-24935

Lexmark products through 2022-02-10 have Incorrect Access Control.

8.8
CVE-2021-44737

PJL directory traversal vulnerability in Lexmark devices through 2021-12-07 that can be leveraged to overwrite internal

9.8
CVE-2021-44736

The initial admin account setup wizard on Lexmark devices allow unauthenticated access to the “out of service erase” fea

9.8
CVE-2021-44735

Embedded web server command injection vulnerability in Lexmark devices through 2021-12-07.

9.8
CVE-2021-44734

Embedded web server input sanitization vulnerability in Lexmark devices through 2021-12-07, which can which can lead to

9.8
CVE-2021-44738

Buffer overflow vulnerability has been identified in Lexmark devices through 2021-12-07 in postscript interpreter.

7.8
CVE-2021-35449

The Lexmark Universal Print Driver version 2.15.1.0 and below, G2 driver 2.7.1.0 and below, G3 driver 3.2.0.0 and below,

7.8
CVE-2021-35469

The Lexmark Printer Software G2, G3 and G4 Installation Packages have a local escalation of privilege vulnerability due

5.4
CVE-2020-10094

A cross-site scripting (XSS) vulnerability in Lexmark CS31x before LW74.VYL.P273; CS41x before LW74.VY2.P273; CS51x befo

5.4
CVE-2020-10093

A cross-site scripting (XSS) vulnerability in Lexmark Pro910 series inkjet and other discontinued products.

7.5
CVE-2018-18894

Certain older Lexmark devices (C, M, X, and 6500e before 2018-12-18) contain a directory traversal vulnerability in the

8.8
CVE-2016-1487

Lexmark Markvision Enterprise before 2.3.0 misuses the Apache Commons Collections Library, leading to remote code execut

5.3
CVE-2011-4538

Lexmark X, W, T, E, and C devices before 2012-02-09 allow attackers to obtain sensitive information by reading passwords

7.5
CVE-2011-3269

Lexmark X, W, T, E, C, 6500e, and 25xxN devices before 2011-11-15 allow attackers to obtain sensitive information via a

9.8
CVE-2016-6918

Lexmark Markvision Enterprise (MVE) before 2.4.1 allows remote attackers to execute arbitrary commands by uploading file

5.4
CVE-2019-19773

Various Lexmark products have stored XSS in the embedded web server used in older generation Lexmark devices. Affected p

5.4
CVE-2019-19772

Various Lexmark products have reflected XSS in the embedded web server used in older generation Lexmark devices. Affecte

5.4
CVE-2019-18791

Lexmark printer MS812 and multiple older generation Lexmark devices have a stored XSS vulnerability in the embedded web

7.5
CVE-2014-8742

Directory traversal vulnerability in the ReportDownloadServlet servlet in Lexmark MarkVision Enterprise before 2.1 allow

9.8
CVE-2014-8741

Directory traversal vulnerability in the GfdFileUploadServerlet servlet in Lexmark MarkVision Enterprise before 2.1 allo

7.5
CVE-2019-16758

In Lexmark Services Monitor 2.27.4.0.39 (running on TCP port 2070), a remote attacker can use a directory traversal tech

9.8
CVE-2019-9933

Various Lexmark products have a Buffer Overflow (issue 3 of 3).

9.8
CVE-2019-9932

Various Lexmark products have a Buffer Overflow (issue 2 of 3).

7.5
CVE-2019-9931

Various Lexmark printers contain a denial of service vulnerability in the SNMP service that can be exploited to crash th

9.8
CVE-2019-9930

Various Lexmark products have an Integer Overflow.

5.3
CVE-2019-10059

The legacy finger service (TCP port 79) is enabled by default on various older Lexmark devices.

6.5
CVE-2019-10057

Various Lexmark products have CSRF.

5.3
CVE-2019-9935

Various Lexmark products have Incorrect Access Control (issue 2 of 2).

5.3
CVE-2019-9934

Various Lexmark products have Incorrect Access Control (issue 1 of 2).

9.1
CVE-2019-10058

Various Lexmark products have Incorrect Access Control.

9.8
CVE-2018-15519

Various Lexmark devices have a Buffer Overflow (issue 1 of 2).

9.8
CVE-2018-15520

Various Lexmark devices have a Buffer Overflow (issue 2 of 2).

4.9
CVE-2018-17944

On certain Lexmark devices that communicate with an LDAP or SMTP server, a malicious administrator can discover LDAP or

5.3
CVE-2019-6489

Certain Lexmark CX, MX, X, XC, XM, XS, and 6500e devices before 2019-02-11 allow remote attackers to erase stored shortc

9.8
CVE-2017-13771

Lexmark Scan To Network (SNF) 3.2.9 and earlier stores network configuration credentials in plaintext and transmits them

7.5
CVE-2017-2822

An exploitable code execution vulnerability exists in the image rendering functionality of Lexmark Perceptive Document F

8.8
CVE-2017-2821

An exploitable use-after-free exists in the PDF parsing functionality of Lexmark Perspective Document Filters 11.3.0.240

4.3
CVE-2017-2806

An exploitable arbitrary read exists in the XLS parsing of the Lexmark Perspective Document Filters conversion functiona

Frequently Asked Questions

How many CVEs affect Lexmark?

Lexmark has 857 CVE records in our database, including 366 critical and 223 high severity vulnerabilities.

What are the most severe Lexmark vulnerabilities?

Lexmark has 366 critical severity (CVSS 9.0+) and 223 high severity (CVSS 7.0-8.9) vulnerabilities. Review the list above sorted by publication date to find the most recent high-severity issues.

How can I scan for Lexmark vulnerabilities?

CyberStrike's AI-powered security agents automatically detect vulnerabilities in Lexmark products across your infrastructure. The platform provides continuous pentesting, DAST scanning, and real-time vulnerability monitoring with actionable remediation guidance.

Detect Lexmark Vulnerabilities

CyberStrike scans your infrastructure for Lexmark vulnerabilities and provides real-time remediation guidance.

Get Started