Skip to content
Signals
NVD · CVE-2026-64604 · In the Linux kernel, the following vulnerability has been resolved: KVM: VMX: Grab vmcs12 on CR8 interception update iff vCPU is in guest mode When updating CR8NVD · CVE-2026-64603 · In the Linux kernel, the following vulnerability has been resolved: platform/x86: intel-hid: Protect ACPI notify handler against recursion Since commit e2ffcda1NVD · CVE-2026-64602 · In the Linux kernel, the following vulnerability has been resolved: iio: adc: spear: Initialize completion before requesting IRQ In the report from Jaeyoung ChuNVD · CVE-2026-64601 · In the Linux kernel, the following vulnerability has been resolved: ALSA: us144mkii: capture_urb_complete: redundant usb_anchor_urb corrupts anchor list on eachCISA KEV · CVE-2026-63077 · 9.8 · JetBrains TeamCity Deserialization of Untrusted Data Vulnerability · Added 2026-08-05 · Due 2026-08-08CISA KEV · CVE-2026-18556 · 7.4 · N-able N-central Authentication Bypass Using an Alternate Path or Channel Vulnerability · Added 2026-08-04 · Due 2026-08-07NVD · CVE-2026-64604 · In the Linux kernel, the following vulnerability has been resolved: KVM: VMX: Grab vmcs12 on CR8 interception update iff vCPU is in guest mode When updating CR8NVD · CVE-2026-64603 · In the Linux kernel, the following vulnerability has been resolved: platform/x86: intel-hid: Protect ACPI notify handler against recursion Since commit e2ffcda1NVD · CVE-2026-64602 · In the Linux kernel, the following vulnerability has been resolved: iio: adc: spear: Initialize completion before requesting IRQ In the report from Jaeyoung ChuNVD · CVE-2026-64601 · In the Linux kernel, the following vulnerability has been resolved: ALSA: us144mkii: capture_urb_complete: redundant usb_anchor_urb corrupts anchor list on eachCISA KEV · CVE-2026-63077 · 9.8 · JetBrains TeamCity Deserialization of Untrusted Data Vulnerability · Added 2026-08-05 · Due 2026-08-08CISA KEV · CVE-2026-18556 · 7.4 · N-able N-central Authentication Bypass Using an Alternate Path or Channel Vulnerability · Added 2026-08-04 · Due 2026-08-07

Vendors · ricoh

ricoh

· 4 Critical

Total CVEs

43

Critical

4

Products

384

Search All CVEs →

43

Products (384)

sp c252dn13 CVEssp c250sf13 CVEssp c250dn firmware13 CVEssp c250sf firmware13 CVEssp c252dn firmware13 CVEssp c252sf firmware13 CVEssp c252sf13 CVEssp c250dn13 CVEssp 212sfnw firmware5 CVEssp 212sfw5 CVEssp 212sfw firmware5 CVEssp 212snw5 CVEssp 212snw firmware5 CVEssp 212suw5 CVEssp 212suw firmware5 CVEssp 212w5 CVEssp 212w firmware5 CVEssp 213nw5 CVEssp 213nw firmware5 CVEssp 213sfnw5 CVEssp 213sfnw firmware5 CVEssp 213sfw5 CVEssp 213sfw firmware5 CVEssp 213snw5 CVEssp 213snw firmware5 CVEssp 213suw5 CVEssp 213suw firmware5 CVEssp 213w5 CVEssp 213w firmware5 CVEssp 220nw5 CVEssp 220nw firmware5 CVEssp 220sfnw5 CVEssp 220sfnw firmware5 CVEssp 220snw5 CVEssp 220snw firmware5 CVEssp c261sfnw5 CVEssp c261sfnw firmware5 CVEssp c262dnw5 CVEssp c262dnw firmware5 CVEssp c262sfnw5 CVEssp c262sfnw firmware5 CVEsd7500 firmware5 CVEsd84005 CVEssp 330dn firmware5 CVEssp 330sfn5 CVEssp 330sfn firmware5 CVEssp 330sn5 CVEssp 330sn firmware5 CVEssp 3710dn5 CVEssp 3710dn firmware5 CVEssp 3710sf5 CVEssp 3710sf firmware5 CVEsd6500 firmware5 CVEssp 212nw5 CVEssp 212nw firmware5 CVEsm 27005 CVEsm 2700 firmware5 CVEsm 27015 CVEssp 212sfnw5 CVEsm 2701 firmware5 CVEsd65105 CVEsd6510 firmware5 CVEsd75005 CVEssp c260dnw5 CVEssp c260dnw firmware5 CVEssp c260sfnw5 CVEssp c260sfnw firmware5 CVEssp c261dnw5 CVEssp c261dnw firmware5 CVEssp 221nw5 CVEssp 221nw firmware5 CVEssp 221s5 CVEssp 221s firmware5 CVEssp 221sf5 CVEssp 221sf firmware5 CVEssp 221sfnw5 CVEssp 221sfnw firmware5 CVEssp 221snw5 CVEssp 221snw firmware5 CVEsd55005 CVEsd5500 firmware5 CVEssp 277sfnwx5 CVEssp 277sfnwx firmware5 CVEssp 277snwx5 CVEssp 277snwx firmware5 CVEsd8400 firmware5 CVEsd55105 CVEsd5510 firmware5 CVEsd55205 CVEsd22005 CVEsd2200 firmware5 CVEsd5520 firmware5 CVEsd65005 CVEssp 330dn5 CVEssp 221 firmware4 CVEssp 213nw \(taiwan\)4 CVEssp 212sfnw \(china\) firmware4 CVEsmp 20144 CVEsmp 2014 firmware4 CVEsmp 2014ad4 CVEsmp 2014ad firmware4 CVEsmp 2014d4 CVEssp277nwx4 CVEssp277nwx firmware4 CVEsmp 2014d firmware4 CVEssp 2214 CVEssp 213snw \(taiwan\) firmware4 CVEssp 213snw \(taiwan\)4 CVEssp 213sfnw \(taiwan\) firmware4 CVEssp 212sfnw \(china\)4 CVEssp 213sfnw \(taiwan\)4 CVEssp 213nw \(taiwan\) firmware4 CVEsp c300w firmware3 CVEsp c301w3 CVEsp c301w firmware3 CVEsm c250fwb firmware3 CVEsm c250fw3 CVEsm c250fw firmware3 CVEsm c250fwb3 CVEsp c300w3 CVEsmp c307 firmware2 CVEsmp c20032 CVEsmp c4504ex2 CVEsmp c4504ex firmware2 CVEsmp 305\+2 CVEsmp 305\+ firmware2 CVEsmp c60032 CVEsmp c6003 firmware2 CVEsmp c3072 CVEsmp c3003 smart operation panel firmware1 CVEsmp c30041 CVEsmp c3004 firmware1 CVEsmp c3004ex1 CVEsmp c3004ex firmware1 CVEsmp c3061 CVEsmp c306 firmware1 CVEsmp c35031 CVEsmp c3503 firmware1 CVEsmp c3503 smart operation panel1 CVEsmp c3503 smart operation panel firmware1 CVEsmp c35041 CVEsmp c3504 firmware1 CVEsmp c3504ex1 CVEsmp c3504ex firmware1 CVEsmp c4061 CVEsmp c406 firmware1 CVEsmp c406z1 CVEsmp c406zspf firmware1 CVEsmp c4071 CVEsmp c407 firmware1 CVEsmp c45031 CVEsmp c4503 firmware1 CVEsmp c4503 smart operation panel1 CVEsmp c4503 smart operation panel firmware1 CVEsmp c45041 CVEsmp c4504 firmware1 CVEsmp c55031 CVEsmp c5503 firmware1 CVEsmp c5503 smart operation panel1 CVEsmp c5503 smart operation panel firmware1 CVEsmp c55041 CVEsmp c5504 firmware1 CVEsmp c5504ex1 CVEsmp c5504ex firmware1 CVEsmp c6003 smart operation panel1 CVEsmp c6003 smart operation panel firmware1 CVEsmp c60041 CVEsmp c6004 firmware1 CVEsmp c6004ex1 CVEsmp c6004ex firmware1 CVEsmp c65031 CVEsmp c6503 firmware1 CVEsmyprint1 CVEsp 3101 CVEsp 310 firmware1 CVEsp 3111 CVEsp 311 firmware1 CVEspc fax generic driver1 CVEspcl6 \(pcl xl\) driver1 CVEspcl6 driver for universal print1 CVEspostscript3 driver1 CVEsprinter driver packager nx1 CVEspro c5300s1 CVEspro c5300s firmware1 CVEspro c5310s1 CVEspro c5310s firmware1 CVEsps driver for universal print1 CVEsrpcs driver1 CVEsrpcs raster driver1 CVEssp 2101 CVEssp 210 \(china\)1 CVEssp 210 \(china\) firmware1 CVEssp 210 firmware1 CVEssp 210 q \(china\)1 CVEssp 210 q \(china\) firmware1 CVEssp 210e \(china\)1 CVEssp 210e \(china\) firmware1 CVEssp 210sf1 CVEssp 210sf \(china\)1 CVEssp 210sf \(china\) firmware1 CVEssp 210sf firmware1 CVEssp 210sf q \(china\)1 CVEssp 210sf q \(china\) firmware1 CVEssp 210su1 CVEssp 210su \(china\) firmware1 CVEssp 210su firmware1 CVEssp 210su q \(china\)1 CVEssp 210su q \(china\) firmware1 CVEssp 2111 CVEssp 211 firmware1 CVEssp 211sf1 CVEssp 211sf firmware1 CVEssp 211su1 CVEssp 211su firmware1 CVEssp 277nwx1 CVEssp 277nwx firmware1 CVEssp 310dnw1 CVEssp 310dnw firmware1 CVEssp 310sfnw1 CVEssp 310sfnw firmware1 CVEssp 311dnw1 CVEssp 311dnw firmware1 CVEssp 311sfnw1 CVEssp 311sfnw firmware1 CVEssp 312dnw1 CVEssp 312dnw firmware1 CVEssp 312sfnw1 CVEssp 312sfnw firmware1 CVEssp 320dn1 CVEssp 320dn firmware1 CVEssp 320sfn1 CVEssp 320sfn firmware1 CVEssp 320sn1 CVEssp 320sn firmware1 CVEssp 325dnw1 CVEssp 325dnw firmware1 CVEssp 325sfnw1 CVEssp 325sfnw firmware1 CVEssp 325snw1 CVEssp 325snw firmware1 CVEssp 377dnwx1 CVEssp 377dnwx firmware1 CVEssp 377sfnwx1 CVEssp 377sfnwx firmware1 CVEssp 377snwx1 CVEssp 377snwx firmware1 CVEssp 4510dn1 CVEssp 4510dn firmware1 CVEssp 4510sf1 CVEssp 4510sf firmware1 CVEssp 4520dn1 CVEssp 4520dn firmware1 CVEssr10 ftp server1 CVEsstreamline nx client tool1 CVEsaficio mp 301spf1 CVEsstreamline nx pc client1 CVEsaficio mp 301spf firmware1 CVEsaficio sp 3500sf1 CVEsaficio sp 3500sf firmware1 CVEsaficio sp 4210n1 CVEsaficio sp 4210n firmware1 CVEsdevice software manager1 CVEsdl-101 CVEsdl-1 sr101 CVEsfusionpro vdp1 CVEsgeneric pcl5 driver1 CVEsim 25001 CVEsim 2500 firmware1 CVEsim 27021 CVEsim 2702 firmware1 CVEsim 30001 CVEsim 3000 firmware1 CVEsim 3501 CVEsim 35001 CVEsim 3500 firmware1 CVEsim 350 firmware1 CVEsim 350f1 CVEsim 350f firmware1 CVEsim 40001 CVEsim 4000 firmware1 CVEsim 430f1 CVEsim 430f firmware1 CVEsim 430fb1 CVEsim 430fb firmware1 CVEsim 50001 CVEsim 5000 firmware1 CVEsim 550f1 CVEsim 550f firmware1 CVEsim 60001 CVEsim 6000 firmware1 CVEsim 600f1 CVEsim 600f firmware1 CVEsim 600srf1 CVEsim 600srf firmware1 CVEsim 70001 CVEsim 7000 firmware1 CVEsim 80001 CVEsim 8000 firmware1 CVEsim 90001 CVEsim 9000 firmware1 CVEsim c20001 CVEsim c2000 firmware1 CVEsim c25001 CVEsim c2500 firmware1 CVEsim c3001 CVEsim c30001 CVEsim c3000 firmware1 CVEsim c300 firmware1 CVEsim c300f1 CVEsim c300f firmware1 CVEsim c35001 CVEsim c3500 firmware1 CVEsim c400f1 CVEsim c400f firmware1 CVEsim c400srf1 CVEsim c400srf firmware1 CVEsim c45001 CVEsim c4500 firmware1 CVEsim c530f1 CVEsim c530f firmware1 CVEsim c530fb1 CVEsim c530fb firmware1 CVEsim c55001 CVEsim c5500 firmware1 CVEsim c60001 CVEsim c6000 firmware1 CVEsim c65001 CVEsim c6500 firmware1 CVEsim c80001 CVEsim c8000 firmware1 CVEsim cw22001 CVEsim cw2200 firmware1 CVEsim cw22011 CVEsim cw2201 firmware1 CVEslimedio1 CVEsm 3201 CVEsm 320 firmware1 CVEsm 320f1 CVEsm 320f firmware1 CVEsm 320fb1 CVEsm 320fb firmware1 CVEsm c20001 CVEsm c2000 firmware1 CVEsm c20011 CVEsm c2001 firmware1 CVEsmp 2001sp1 CVEsmp 2001sp firmware1 CVEsmp 25551 CVEsmp 2555 firmware1 CVEsmp 30551 CVEsmp 3055 firmware1 CVEsmp 35551 CVEsmp 3555 firmware1 CVEsmp 402spf1 CVEsmp 402spf firmware1 CVEsmp 40551 CVEsmp 4055 firmware1 CVEsmp 5011 CVEsmp 501 firmware1 CVEsmp 50551 CVEsmp 5055 firmware1 CVEsmp 60551 CVEsmp 6055 firmware1 CVEsmp c1803 jpn1 CVEsmp c1803 jpn firmware1 CVEsmp c2003 firmware1 CVEsmp c2003 smart operation panel1 CVEsmp c2003 smart operation panel firmware1 CVEsmp c2003sp firmware1 CVEsmp c20041 CVEsmp c2004 firmware1 CVEsmp c2004ex1 CVEsmp c2004ex firmware1 CVEsmp c25031 CVEsmp c2503 firmware1 CVEsmp c2503 smart operation panel1 CVEsmp c2503 smart operation panel firmware1 CVEsmp c25041 CVEsmp c2504 firmware1 CVEsmp c2504ex1 CVEsmp c2504ex firmware1 CVEsmp c30031 CVEsmp c3003 firmware1 CVEsmp c3003 smart operation panel1 CVEs

Recent Vulnerabilities

View all 43
CVE-2023-30759HIGH 7.8

The driver installation package created by Printer Driver Packager NX v1.0.02 to v1.1.25 fails to detect its modification and may spawn an unexpected process with the administrative privilege. If a non-administrative user modifies the driver installation package and runs it on the target PC, an arbitrary program may be executed with the administrative privilege.

CVE-2022-43969CRITICAL 9.1

Ricoh mp_c4504ex devices with firmware 1.06 mishandle credentials.

CVE-2022-37406MEDIUM 4.8

Cross-site scripting vulnerability in Aficio SP 4210N firmware versions prior to Web Support 1.05 allows a remote authenticated attacker with an administrative privilege to inject an arbitrary script.

CVE-2022-36403HIGH 7.8

Untrusted search path vulnerability in the installer of Device Software Manager prior to Ver.2.20.3.0 allows an attacker to gain privileges via a Trojan horse DLL in an unspecified directory.

CVE-2021-33945CRITICAL 9.8

RICOH Printer series SP products 320DN, SP 325DNw, SP 320SN, SP 320SFN, SP 325SNw, SP 325SFNw, SP 330SN, Aficio SP 3500SF, SP 221S, SP 220SNw, SP 221SNw, SP 221SF, SP 220SFNw, SP 221SFNw v1.06 were discovered to contain a stack buffer overflow in the file /etc/wpa_supplicant.conf. This vulnerability allows attackers to cause a Denial of Service (DoS) via crafted overflow data.

CVE-2019-20001HIGH 7.8

An issue was discovered in RICOH Streamline NX Client Tool and RICOH Streamline NX PC Client that allows attackers to escalate local privileges.

CVE-2019-14310CRITICAL 9.8

Ricoh SP C250DN 1.05 devices allow denial of service (issue 2 of 3). Unauthenticated crafted packets to the IPP service will cause a vulnerable device to crash. A memory corruption has been identified in the way of how the embedded device parsed the IPP packets

CVE-2019-14309HIGH 7.5

Ricoh SP C250DN 1.05 devices have a fixed password. FTP service credential were found to be hardcoded within the printer firmware. This would allow to an attacker to access and read information stored on the shared FTP folders.

CVE-2019-14303HIGH 7.5

Ricoh SP C250DN 1.05 devices allow denial of service (issue 1 of 3). Some Ricoh printers were affected by a wrong LPD service implementation that lead to a denial of service vulnerability.

CVE-2019-14299CRITICAL 9.8

Ricoh SP C250DN 1.05 devices have an Authentication Method Vulnerable to Brute Force Attacks. Some Ricoh printers did not implement account lockout. Therefore, it was possible to obtain the local account credentials by brute force.

CVE-2019-19363HIGH 7.8

An issue was discovered in Ricoh (including Savin and Lanier) Windows printer drivers prior to 2020 that allows attackers local privilege escalation. Affected drivers and versions are: PCL6 Driver for Universal Print - Version 4.0 or later PS Driver for Universal Print - Version 4.0 or later PC FAX Generic Driver - All versions Generic PCL5 Driver - All versions RPCS Driver - All versions PostScript3 Driver - All versions PCL6 (PCL XL) Driver - All versions RPCS Raster Driver - All version

CVE-2019-14306HIGH 7.5

Ricoh SP C250DN 1.06 devices have Incorrect Access Control (issue 2 of 2).

CVE-2019-14304HIGH 8.8

Ricoh SP C250DN 1.06 devices allow CSRF.

CVE-2019-14302MEDIUM 6.8

On Ricoh SP C250DN 1.06 devices, a debug port can be used.

CVE-2019-14301HIGH 7.5

Ricoh SP C250DN 1.06 devices have Incorrect Access Control (issue 1 of 2).

CVE-2019-7751HIGH 7.5

A directory traversal and local file inclusion vulnerability in FPProducerInternetServer.exe in Ricoh MarcomCentral, formerly PTI Marketing, FusionPro VDP before 10.0 allows a remote attacker to list or enumerate sensitive contents of files. Furthermore, this could allow for privilege escalation by dumping the local machine's SAM and SYSTEM database files, and possibly remote code execution.

CVE-2019-6021MEDIUM 6.1

Open redirect vulnerability in Library Information Management System LIMEDIO all versions allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a specially crafted URL.

CVE-2019-18203MEDIUM 6.1

On the RICOH MP 501 printer, HTML Injection and Stored XSS vulnerabilities have been discovered in the area of adding addresses via the entryNameIn and KeyDisplay parameter to /web/entry/en/address/adrsSetUserWizard.cgi.

CVE-2019-14307

Several Ricoh printers have multiple buffer overflows parsing HTTP parameter settings for SNMP, which allow an attacker to cause a denial of service or code execution via crafted requests to the web server. Affected firmware versions depend on the printer models. One affected configuration is cpe:2.3:o:ricoh:sp_c250dn_firmware:-:*:*:*:*:*:*:* up to (including) 1.06 running on cpe:2.3:o:ricoh:sp_c250dn:-:*:*:*:*:*:*:*, cpe:2.3:o:ricoh:sp_c252dn:-:*:*:*:*:*:*:*. Another affected configuration is cpe:2.3:o:ricoh:sp_c250sf_firmware:-:*:*:*:*:*:*:* up to (including) 1.12 running on cpe:2.3:o:ricoh:sp_c250sf:-:*:*:*:*:*:*:*, cpe:2.3:o:ricoh:sp_c252sf:-:*:*:*:*:*:*:*.

CVE-2019-14305

Several Ricoh printers have multiple buffer overflows parsing HTTP parameter settings for Wi-Fi, mDNS, POP3, SMTP, and notification alerts, which allow an attacker to cause a denial of service or code execution via crafted requests to the web server. Affected firmware versions depend on the printer models. One affected configuration is cpe:2.3:o:ricoh:sp_c250dn_firmware:-:*:*:*:*:*:*:* up to (including) 1.06 running on cpe:2.3:o:ricoh:sp_c250dn:-:*:*:*:*:*:*:*, cpe:2.3:o:ricoh:sp_c252dn:-:*:*:*:*:*:*:*. Another affected configuration is cpe:2.3:o:ricoh:sp_c250sf_firmware:-:*:*:*:*:*:*:* up to (including) 1.12 running on cpe:2.3:o:ricoh:sp_c250sf:-:*:*:*:*:*:*:*, cpe:2.3:o:ricoh:sp_c252sf:-:*:*:*:*:*:*:*.

CVE-2019-14300

Several Ricoh printers have multiple buffer overflows parsing HTTP cookie headers, which allow an attacker to cause a denial of service or code execution via crafted requests to the web server. Affected firmware versions depend on the printer models. One affected configuration is cpe:2.3:o:ricoh:sp_c250dn_firmware:-:*:*:*:*:*:*:* up to (including) 1.06 running on cpe:2.3:o:ricoh:sp_c250dn:-:*:*:*:*:*:*:*, cpe:2.3:o:ricoh:sp_c252dn:-:*:*:*:*:*:*:*. Another affected configuration is cpe:2.3:o:ricoh:sp_c250sf_firmware:-:*:*:*:*:*:*:* up to (including) 1.12 running on cpe:2.3:o:ricoh:sp_c250sf:-:*:*:*:*:*:*:*, cpe:2.3:o:ricoh:sp_c252sf:-:*:*:*:*:*:*:*.

CVE-2019-14308

Several Ricoh printers have multiple buffer overflows parsing LPD packets, which allow an attacker to cause a denial of service or code execution via crafted requests to the LPD service. Affected firmware versions depend on the printer models. One affected configuration is cpe:2.3:o:ricoh:sp_c250dn_firmware:-:*:*:*:*:*:*:* up to (including) 1.06 running on cpe:2.3:o:ricoh:sp_c250dn:-:*:*:*:*:*:*:*, cpe:2.3:o:ricoh:sp_c252dn:-:*:*:*:*:*:*:*. Another affected configuration is cpe:2.3:o:ricoh:sp_c250sf_firmware:-:*:*:*:*:*:*:* up to (including) 1.12 running on cpe:2.3:o:ricoh:sp_c250sf:-:*:*:*:*:*:*:*, cpe:2.3:o:ricoh:sp_c252sf:-:*:*:*:*:*:*:*.

CVE-2019-11845

An HTML Injection vulnerability has been discovered on the RICOH SP 4510DN via the /web/entry/en/address/adrsSetUserWizard.cgi entryNameIn parameter.

CVE-2019-11844

An HTML Injection vulnerability has been discovered on the RICOH SP 4520DN via the /web/entry/en/address/adrsSetUserWizard.cgi entryNameIn or entryDisplayNameIn parameter.

CVE-2018-16188

SQL injection vulnerability in the RICOH Interactive Whiteboard D2200 V1.3 to V2.2, D5500 V1.3 to V2.2, D5510 V1.3 to V2.2, the display versions with RICOH Interactive Whiteboard Controller Type1 V1.3 to V2.2 attached (D5520, D6500, D6510, D7500, D8400), and the display versions with RICOH Interactive Whiteboard Controller Type2 V3.0 to V3.1.10137.0 attached (D5520, D6510, D7500, D8400) allows remote attackers to execute arbitrary SQL commands via unspecified vectors.