Vulnerability Database

385,424

Total vulnerabilities in the database

CVE-2019-18914 — hp / futuresmart_3

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

A potential security vulnerability has been identified for certain HP printers and MFPs that would allow redirection page Cross-Site Scripting in a client’s browser by clicking on a third-party malicious link.

  • Published: Nov 9, 2021
  • Updated: Sep 15, 2026
  • CVE: CVE-2019-18914
  • Severity: Medium
  • Exploit:
  • CISA KEV:

CVSS v3:

  • Severity: Medium
  • Score: 6.1
  • AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

CVSS v2:

  • Severity: Medium
  • Score: 4.3
  • AV:N/AC:M/Au:N/C:N/I:P/A:N
Software Affected versions
hp / futuresmart_3 < 2309025_582081
hp / futuresmart_3 < 2309025_582098
hp / futuresmart_4 < 2410028_055010
hp / futuresmart_3 < 2309025_582089
hp / futuresmart_4 < 2410028_055028
hp / futuresmart_3 < 2309025_582096
hp / futuresmart_4 < 2410028_055035
hp / futuresmart_4 < 2410028_055034
hp / futuresmart_3 < 2309025_582102
hp / futuresmart_4 < 2410028_055015
hp / futuresmart_3 < 2309025_582099
hp / futuresmart_4 < 2410028_055019
hp / futuresmart_4 < 2410028_055002
hp / futuresmart_3 < 2309025_582093
hp / futuresmart_4 < 2410028_055018
hp / futuresmart_3 < 2309025_582101
hp / futuresmart_4 < 2410028_055020
hp / futuresmart_4 < 2410028_055026
hp / futuresmart_4 < 2410028_055041
hp / futuresmart_3 < 2309025_582084
hp / futuresmart_4 < 2410028_055006
hp / futuresmart_4 < 2410028_055016
hp / futuresmart_4 < 2410028_055008
hp / futuresmart_4 < 2410028_055011
hp / futuresmart_3 < 2309025_582108
hp / futuresmart_3 < 2309025_582106
hp / futuresmart_4 < 2410028_055031
hp / futuresmart_3 < 2309025_582097
hp / futuresmart_4 < 2410028_055022
hp / futuresmart_3 < 2309025_582113
hp / futuresmart_3 < 2309025_582105
hp / futuresmart_4 < 2410028_055038
hp / futuresmart_3 < 2309025_582104
hp / futuresmart_3 < 2309025_582082
hp / futuresmart_4 < 2410028_055029
hp / futuresmart_3 < 2309025_582112
hp / futuresmart_4 < 2410028_055023
hp / futuresmart_3 < 2309025_582088
hp / futuresmart_3 < 2309025_582091
hp / futuresmart_4 < 2410028_055040
hp / futuresmart_4 < 2410028_055003
hp / futuresmart_3 < 2309025_582085
hp / futuresmart_4 < 2410028_055039
hp / futuresmart_4 < 2410028_055009
hp / futuresmart_3 < 2309025_582110
hp / futuresmart_4 < 2410028_055037
hp / futuresmart_3 < 2309025_582086
hp / futuresmart_4 < 2410028_055012
hp / futuresmart_4 < 2410028_055004
hp / futuresmart_4 < 2410028_055025
hp / futuresmart_3 < 2309025_582103
hp / futuresmart_4 < 2410028_055024
hp / futuresmart_4 < 2410028_055021
hp / futuresmart_4 < 2410028_055007
hp / futuresmart_4 < 2410028_055005
hp / futuresmart_3 < 2309025_582083
hp / futuresmart_4 < 2410028_055013
hp / futuresmart_3 < 2309025_582114
hp / futuresmart_4 < 2410028_055032
hp / futuresmart_4 < 2410028_055030
hp / futuresmart_4 < 2410028_055027
hp / futuresmart_3 < 2309025_582092
hp / futuresmart_4 < 2410028_055033
hp / futuresmart_4 < 2410028_055017
hp / futuresmart_4 < 2410028_055014
hp / futuresmart_3 < 2309025_582087
hp / futuresmart_4 < 2410028_055036

Frequently Asked Questions

A security vulnerability is a weakness in software, hardware, or configuration that can be exploited to compromise confidentiality, integrity, or availability. Many vulnerabilities are tracked as CVEs (Common Vulnerabilities and Exposures), which provide a standardized identifier so teams can coordinate patching, mitigation, and risk assessment across tools and vendors.

CVSS (Common Vulnerability Scoring System) estimates technical severity, but it doesn't automatically equal business risk. Prioritize using context like internet exposure, affected asset criticality, known exploitation (proof-of-concept or in-the-wild), and whether compensating controls exist. A "Medium" CVSS on an exposed, production system can be more urgent than a "Critical" on an isolated, non-production host.

A vulnerability is the underlying weakness. An exploit is the method or code used to take advantage of it. A zero-day is a vulnerability that is unknown to the vendor or has no publicly available fix when attackers begin using it. In practice, risk increases sharply when exploitation becomes reliable or widespread.

Recurring findings usually come from incomplete Asset Discovery, inconsistent patch management, inherited images, and configuration drift. In modern environments, you also need to watch the software supply chain: dependencies, containers, build pipelines, and third-party services can reintroduce the same weakness even after you patch a single host. Unknown or unmanaged assets (often called Shadow IT) are a common reason the same issues resurface.

Use a simple, repeatable triage model: focus first on externally exposed assets, high-value systems (identity, VPN, email, production), vulnerabilities with known exploits, and issues that enable remote code execution or privilege escalation. Then enforce patch SLAs and track progress using consistent metrics so remediation is steady, not reactive.

SynScan combines attack surface monitoring and continuous security auditing to keep your inventory current, flag high-impact vulnerabilities early, and help you turn raw findings into a practical remediation plan.