VYPR

Vendor CVEs

Ricoh

All CVEs

61 total · sorted by risk
  • CVE-2026-21409MedJan 9, 2026
    risk 0.38cvss 5.9epss 0.00

    Improper authorization vulnerability exists in RICOH Streamline NX 3.5.1 to 24R3. If a man-in-the-middle attack is conducted on the communication between the affected product and its user, and some crafted request is processed by the product, the user's registration information…

  • CVE-2018-16187MedJan 9, 2019
    risk 0.38cvss 5.9epss 0.01

    The RICOH Interactive Whiteboard D2200 V1.3 to V2.2, D5500 V1.3 to V2.2, D5510 V1.3 to V2.2, the display versions with RICOH Interactive Whiteboard Controller Type1 V1.3 to V2.2 attached (D5520, D6500, D6510, D7500, D8400), and the display versions with RICOH Interactive…

  • CVE-2026-41226MedApr 30, 2026
    risk 0.31cvss 4.7epss 0.00

    Open redirect vulnerability exists in Multiple laser printers and MFPs which implement Ricoh Web Image Monitor. When accessing a specially crafted URL, the user may be redirected to an arbitrary website. As a result, the user may become a victim of a phishing attack.

  • CVE-2022-37406MedDec 7, 2022
    risk 0.31cvss 4.8epss 0.01

    Cross-site scripting vulnerability in Aficio SP 4210N firmware versions prior to Web Support 1.05 allows a remote authenticated attacker with an administrative privilege to inject an arbitrary script.

  • CVE-2024-37387MedJun 19, 2024
    risk 0.26cvss 4.0epss 0.00

    Use of potentially dangerous function issue exists in Ricoh Streamline NX PC Client. If this vulnerability is exploited, files in the PC where the product is installed may be altered.

  • CVE-2025-58422LowSep 8, 2025
    risk 0.20cvss 3.1epss 0.00

    RICOH Streamline NX versions 3.5.1 to 24R3 are vulnerable to tampering with operation history. If an attacker can perform a man-in-the-middle attack, they may alter the values of HTTP requests, which could result in tampering with the operation history of the product’s…

  • CVE-2025-48825LowJun 13, 2025
    risk 0.16cvss 2.5epss 0.00

    RICOH Streamline NX V3 PC Client versions 3.5.0 to 3.7.0 contains an issue with use of less trusted source, which may allow an attacker who can conduct a man-in-the-middle attack to eavesdrop upgrade requests and execute a malicious DLL with custom code.

  • CVE-2012-5002Sep 19, 2012
    risk 0.05cvss epss 0.31

    Stack-based buffer overflow in SR10 FTP server (SR10.exe) 1.1.0.6 in Ricoh DC Software DL-10 4.5.0.1, when the Log file name option is enabled, allows remote attackers to execute arbitrary code via a long USER FTP command.

  • CVE-2015-6750Aug 31, 2015
    risk 0.04cvss epss 0.08

    Buffer overflow in Ricoh DL FTP Server 1.1.0.6 and earlier allows remote attackers to execute arbitrary code via a long USER command.

  • CVE-2026-63226MedJul 23, 2026
    risk 0.00cvss 5.8epss 0.00

    Printers and Multifunction Printers (MFPs) provided by Ricoh Company, Ltd. do not implement restrictions on SSH port forwarding, allowing to connect to arbitrary destinations. When SSH is enabled on an affected product, SSH port forwarding may be leveraged to connect to other…

  • CVE-2026-56809MedJun 30, 2026
    risk 0.00cvss 6.1epss 0.00

    Multiple laser printers and MFPs (multifunction printers) which implement Ricoh Web Image Monitor contain a reflected cross-site scripting vulnerability. An arbitrary script may be executed on the web browser of the user who accesses a crafted URL.

Page 2 of 2