Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3020▼ 63 respecto a la semana anterior
Críticas / altas1413▲ 57 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▼ 128 respecto a la semana anterior
55 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (8.8) | 0.51% | — | Ukrsolution Print Labels With Barcodes | 2/5/2024 | 17/6/2026 | The Print Labels with Barcodes. Create price tags, product labels, order labels for WooCommerce plugin for WordPress is vulnerable to unauthorized access of data, modification of data, and loss of data due to an improper capability check on 42 separate AJAX functions in all versions up to, and including, 3.4.6. This… | |
| Aplazada | Alta (7.1) | 0.38% | — | Dmitry V Barcode Scanner With Inventory AND Order ManagerAI | 19/3/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Dmitry V. (CEO of "UKR Solution") Barcode Scanner with Inventory & Order Manager barcode-scanner-lite-pos-to-manage-products-inventory-and-orders.This issue affects Barcode Scanner with Inventory & Order Manager: from… | |
| Analizada | Alta (8.8) | 0.50% | — | Ethercreation Generate Barcode ON Invoice / Delivery Slip | 23/2/2024 | 17/6/2026 | In the module "Generate barcode on invoice / delivery slip" (ecgeneratebarcode) from Ether Creation <= 1.2.0 for PrestaShop, a guest can perform SQL injection. | |
| Modificada | Crítica (9.8) | 0.63% | — | Ukrsolution Barcode Scanner AND Inventory Manager | 24/1/2024 | 17/6/2026 | Unrestricted Upload of File with Dangerous Type vulnerability in UkrSolution Barcode Scanner and Inventory manager.This issue affects Barcode Scanner and Inventory manager: from n/a through 1.5.1. | |
| Modificada | Crítica (9.8) | 0.55% | — | Ukrsolution Barcode Scanner AND Inventory Manager | 8/1/2024 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in UkrSolution Simple Inventory Management – just scan barcode to manage products and orders. For WooCommerce.This issue affects Simple Inventory Management – just scan barcode to manage products and orders. For… | |
| Modificada | Alta (8.8) | 0.26% | — | Woocommerce Order Barcodes | 17/7/2023 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in WooCommerce WooCommerce Order Barcodes plugin <= 1.6.4 versions. | |
| Modificada | Alta (7.5) | 53% | — | Glpi-project Barcode | 24/11/2021 | 17/6/2026 | Barcode is a GLPI plugin for printing barcodes and QR codes. GLPI instances version 2.x prior to version 2.6.1 with the barcode plugin installed are vulnerable to a path traversal vulnerability. This issue was patched in version 2.6.1. As a workaround, delete the `front/send.php` file. | |
| Modificada | Media (6.5) | 0.92% | — | Zint Barcode Generator | 17/8/2021 | 17/6/2026 | Zint Barcode Generator before 2.10.0 has a one-byte buffer over-read, related to is_last_single_ascii in code1.c, and rs_encode_uint in reedsol.c. | |
| Modificada | Alta (7.5) | 2.4% | — | Zint Barcode Generator | 26/2/2021 | 17/6/2026 | ean_leading_zeroes in backend/upcean.c in Zint Barcode Generator 2.9.1 has a stack-based buffer overflow that is reachable from the C API through an application that includes the Zint Barcode Generator library code. | |
| Modificada | Media (6.1) | 1.1% | — | Egavilanmedia Barcodes Generator | 15/12/2020 | 17/6/2026 | EGavilan Barcodes generator 1.0 is affected by: Cross Site Scripting (XSS) via the index.php. An Attacker is able to inject the XSS payload in the web application each time a user visits the website. | |
| Modificada | Alta (8.8) | 3.9% | — | Barcodewiz Barcode Activex Control | 9/1/2018 | 17/6/2026 | Multiple buffer overflows in BarCodeWiz BarCode before 6.7 ActiveX control (BarcodeWiz.DLL) allow remote attackers to execute arbitrary code via a long argument to the (1) BottomText or (2) TopText property. | |
| Modificada | Media (5.4) | 0.27% | — | Barcode Scanner Project Barcode Scanner | 2/10/2014 | 17/6/2026 | The barcode scanner (aka tw.com.books.android.plus) application 2.3.0 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate. | |
| Modificada | Alta (9.3) | 6.9% | — | Barcodewiz Barcode Activex Control | 5/8/2010 | 16/6/2026 | Buffer overflow in BarCodeWiz BarCode 3.29 ActiveX control (BarcodeWiz.dll) allows remote attackers to execute arbitrary code via a long argument to the LoadProperties method. | |
| Modificada | Alta (7.8) | 5.7% | — | Precisionid Data Matrix Barcode Activex Control | 1/4/2009 | 16/6/2026 | Multiple insecure method vulnerabilities in PRECIS~2.DLL in the PrecisionID Datamatrix ActiveX control (DMATRIXLib.Datamatrix) allow remote attackers to overwrite arbitrary files via the (1) SaveBarCode and (2) SaveEnhWMF methods. | |
| Modificada | Alta (7.5) | 2.4% | — | Barcodephp Barcodegen 1D | 28/1/2009 | 16/6/2026 | Directory traversal vulnerability in image.php in Barcode Generator 1D (barcodegen) 2.0.0 and earlier allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the code parameter. | |
| Modificada | Alta (9.3) | 5.6% | — | MW6 Technologies Barcode Activex | 27/1/2009 | 16/6/2026 | Heap-based buffer overflow in MW6 Technologies Barcode ActiveX control (Barcode.MW6Barcode.1, Barcode.dll) 3.0.0.1 allows remote attackers to execute arbitrary code via a long Supplement property. | |
| Modificada | Alta (9) | 7.1% | — | MW6 Technologies 1D Barcode Decoder Activex | 4/11/2008 | 16/6/2026 | Multiple insecure method vulnerabilities in MW6 Technologies 1D Barcode ActiveX control (BARCODELib.MW6Barcode, Barcode.dll) 3.0.0.1 allow remote attackers to overwrite arbitrary files via a full pathname argument to the (1) SaveAsBMP and (2) SaveAsWMF methods. | |
| Modificada | Alta (9.3) | 10% | — | Black ICE Barcode SDK | 13/6/2008 | 16/6/2026 | Stack-based buffer overflow in the BITIFF.BITiffCtrl.1 ActiveX control in BITiff.ocx 10.9.3.0 in Black Ice Barcode SDK 5.01 allows remote attackers to execute arbitrary code via a long first argument to the SetByteOrder method. | |
| Modificada | Alta (9.3) | 35% | — | Black ICE Barcode SDK | 12/6/2008 | 16/6/2026 | The BIDIB.BIDIBCtrl.1 ActiveX control in BIDIB.ocx 10.9.3.0 in Black Ice Barcode SDK 5.01 allows remote attackers to force the download and storage of arbitrary files by specifying the origin URL in the first argument to the DownloadImageFileURL method, and the local filename in the second argument. NOTE: some of… | |
| Modificada | Alta (9.3) | 8.7% | — | Blackice Black ICE Barcode SDK | 12/6/2008 | 16/6/2026 | The BIDIB.BIDIBCtrl.1 ActiveX control in BIDIB.ocx 10.9.3.0 in Black Ice Barcode SDK 5.01 allows remote attackers to execute arbitrary code via long strings in the two arguments to the DownloadImageFileURL method, which trigger memory corruption. NOTE: some of these details are obtained from third party information. | |
| Modificada | Alta (9.3) | 6.0% | — | Idautomation Aztec BarcodeIdautomation Datamatrix BarcodeIdautomation Linear BarcodeIdautomation Pdf417 Barcode | 18/5/2008 | 16/6/2026 | IDAutomation allows remote attackers to overwrite arbitrary files via the argument to the (1) SaveBarCode and (2) SaveEnhWMF methods in (a) the IDAuto.BarCode.1 ActiveX control in IDAutomationLinear6.dll (aka IDAutomation Linear BarCode) 1.6.0.6, (b) the IDAuto.Datamatrix.1 ActiveX control in IDAutomationDMATRIX6.DLL… | |
| Modificada | Alta (7.5) | 1.4% | — | Nonnoi Solutions ASP Barcode | 10/7/2007 | 16/6/2026 | The Nonnoi ASP/Barcode ActiveX control (nonnoi_ASPBarcode.dll) allows remote attackers to overwrite arbitrary files via an argument to the SaveBarcode function. | |
| Modificada | Alta (9.3) | 35% | — | RKD Software Barcode Activex | 27/6/2007 | 16/6/2026 | Stack-based buffer overflow in the BeginPrint method in a certain ActiveX control in RKD Software (barcodetools.com) BarCodeAx.dll 4.9 allows remote attackers to execute arbitrary code via a long argument. | |
| Modificada | Media (5) | 6.0% | — | Tec-it Tbarcode OCX | 15/6/2007 | 16/6/2026 | The TEC-IT TBarCode OCX ActiveX control (TBarCode7.ocx) 7.0.2.3524 allows remote attackers to overwrite arbitrary files via the SaveImage method. | |
| Modificada | Alta (10) | 4.4% | — | Precisionid Barcode | 17/5/2007 | 16/6/2026 | The PrecisionID Barcode 1.9 ActiveX control in PrecisionID_Barcode.dll, when Internet Explorer 6 is used, allows remote attackers to overwrite arbitrary files via a full pathname to the SaveToFile function, a different vulnerability than CVE-2007-2744. |