Lexmark International Inc.
Self-Reporting Analysis
Of all the CVEs published by Lexmark International Inc. as a CNA, 9.5% affect products that Lexmark International Inc. develops as a vendor.
Of all the CVEs published that affect products developed by Lexmark International Inc., 2.9% are self-published by Lexmark International Inc. as a CNA.
Trends Over Time
The number and severity of CVEs published by Lexmark International Inc. over time
Top CVEs
All CVEs published by Lexmark International Inc. as a CNA, regardless of affected vendor or product.
21 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2025-65078CRITICAL An untrusted search path vulnerability has been identified in the Embedded Solutions Framework in various Lexmark devices. This vulnerability can be leveraged by an attacker to exe | Feb 3, 2026 | 9.3 | 30 | NO | NO |
CVE-2025-65077HIGH A relative path traversal vulnerability has been identified in the Embedded Solutions Framework in various Lexmark devices. This vulnerability can be leveraged by an attacker to ex | Feb 3, 2026 | 8.8 | 28 | NO | NO |
CVE-2025-1127CRITICAL The vulnerability can be leveraged by an attacker to execute arbitrary code as an unprivileged user and/or modify the contents of any data on the filesystem. | Feb 13, 2025 | 9.1 | 28 | NO | NO |
CVE-2025-1126CRITICAL A Reliance on Untrusted Inputs in a Security Decision vulnerability has been identified in the Lexmark Print Management Client. | Feb 11, 2025 | 9.3 | 28 | NO | NO |
CVE-2023-50735CRITICAL A heap corruption vulnerability has been identified in PostScript interpreter in various Lexmark devices. The vulnerability can be leveraged by an attacker to execute arbitrary cod | Feb 28, 2024 | 9.0 | 28 | NO | NO |
CVE-2025-4044HIGH Improper Restriction of XML External Entity Reference in various Lexmark printer drivers for Windows allows attacker to disclose sensitive information to an arbitrary URL. | Aug 19, 2025 | 8.2 | 26 | NO | NO |
CVE-2023-50739HIGH A buffer overflow vulnerability has been identified in the Internet Printing Protocol (IPP) in various Lexmark devices. The vulnerability can be leveraged by an attacker to execute | Jan 18, 2025 | 8.8 | 26 | NO | NO |
CVE-2023-50737CRITICAL The SE menu contains information used by Lexmark to diagnose device errors. A vulnerability in one of the SE menu routines can be leveraged by an attacker to execute arbitrary code | Feb 28, 2024 | 9.1 | 25 | NO | NO |
CVE-2023-50734CRITICAL A buffer overflow vulnerability has been identified in PostScript interpreter in various Lexmark devices. The vulnerability can be leveraged by an attacker to execute arbitrary cod | Feb 28, 2024 | 9.0 | 25 | NO | NO |
CVE-2025-4046HIGH A missing authorization vulnerability in Lexmark Cloud Services badge management allows attacker to reassign badges within their organization | Aug 19, 2025 | 8.5 | 24 | NO | NO |
CVE Severity & Scoring
Exploit Exposure
Signals from CVEs in this cna scope (21 CVEs).
Social Chatter
An overview of all social media posts that mention a CVE ID published by Lexmark International Inc. as a CNA.
Media Mentions
Media articles that mention a CVE ID published by Lexmark International Inc. as a CNA — matched by CVE ID, not by organization name.