Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2738▼ 488 respecto a la semana anterior
Críticas / altas1301▼ 189 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)229▼ 273 respecto a la semana anterior
24 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (4.3) | 0.14% | — | Dmitry V Barcode Scanner With Inventory AND Order ManagerAI | 29/4/2026 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Dmitry V. (CEO of "UKR Solution") Barcode Scanner with Inventory & Order Manager barcode-scanner-lite-pos-to-manage-products-inventory-and-orders allows Cross Site Request Forgery.This issue affects Barcode Scanner with Inventory & Order Manager: from n/a through <=… | |
| Aplazada | Media (5.5) | 0.47% | — | Dmitryglhf Mcp-url-downloaderAI | 27/4/2026 | 17/6/2026 | A vulnerability has been found in dmitryglhf mcp-url-downloader up to 4b8cf2de55f6e8864a77d108e8a94a5b8e4394c6. Affected by this issue is the function _validate_url_safe of the file src/mcp_url_downloader/server.py. Such manipulation of the argument url leads to server-side request forgery. The attack can be executed… | |
| Aplazada | Alta (7.2) | 0.51% | — | Dmitry V Barcode Scanner Lite POS TO Manage Products Inventory AND OrdersAI | 6/11/2025 | 7/10/2026 | Path Traversal: '.../...//' vulnerability in Dmitry V. (CEO of "UKR Solution") Barcode Scanner with Inventory & Order Manager barcode-scanner-lite-pos-to-manage-products-inventory-and-orders allows Path Traversal.This issue affects Barcode Scanner with Inventory & Order Manager: from n/a through <= 1.10.4. | |
| Aplazada | Media (4.3) | 0.15% | — | Dmitry V UPC EAN Gtin Code GeneratorAI | 22/10/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Dmitry V. (CEO of "UKR Solution") UPC/EAN/GTIN Code Generator upc-ean-barcode-generator allows Cross Site Request Forgery.This issue affects UPC/EAN/GTIN Code Generator: from n/a through <= 2.0.2. | |
| Aplazada | Alta (7.1) | 0.17% | — | Dmitry V Barcode Scanner With Inventory AND Order ManagerAI | 31/8/2025 | 26/9/2026 | Missing Authorization vulnerability in Dmitry V. (CEO of "UKR Solution") Barcode Scanner with Inventory & Order Manager barcode-scanner-lite-pos-to-manage-products-inventory-and-orders.This issue affects Barcode Scanner with Inventory & Order Manager: from n/a through <= 1.5.3. | |
| Aplazada | Alta (7.7) | 0.38% | — | Dmitry V UPC EAN Gtin Code GeneratorAI | 28/8/2025 | 25/9/2026 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Dmitry V. (CEO of "UKR Solution") UPC/EAN/GTIN Code Generator upc-ean-barcode-generator allows Path Traversal.This issue affects UPC/EAN/GTIN Code Generator: from n/a through <= 2.0.2. | |
| Aplazada | Media (4.9) | 0.40% | — | Dmitry V Barcode Scanner With Inventory AND Order ManagerAI | 14/8/2025 | 17/6/2026 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Dmitry V. (CEO of "UKR Solution") Barcode Scanner with Inventory & Order Manager barcode-scanner-lite-pos-to-manage-products-inventory-and-orders allows Path Traversal.This issue affects Barcode Scanner with Inventory &… | |
| Aplazada | Alta (7.5) | 0.38% | — | Dmitry V Barcode Generator FOR WoocommerceAI | 15/4/2025 | 17/6/2026 | Missing Authorization vulnerability in Dmitry V. (CEO of "UKR Solution") Barcode Generator for WooCommerce embedding-barcodes-into-product-pages-and-orders allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Barcode Generator for WooCommerce: from n/a through <= 2.0.4. | |
| Aplazada | Media (5.4) | 0.27% | — | Dmitry V Barcode Generator FOR WoocommerceAI | 1/4/2025 | 17/6/2026 | Missing Authorization vulnerability in Dmitry V. (CEO of "UKR Solution") Barcode Generator for WooCommerce embedding-barcodes-into-product-pages-and-orders allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Barcode Generator for WooCommerce: from n/a through <= 2.0.4. | |
| Aplazada | Media (5.4) | 0.27% | — | Dmitry V UPC EAN Gtin Code GeneratorAI | 1/4/2025 | 17/6/2026 | Missing Authorization vulnerability in Dmitry V. (CEO of "UKR Solution") UPC/EAN/GTIN Code Generator upc-ean-barcode-generator allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects UPC/EAN/GTIN Code Generator: from n/a through <= 2.0.2. | |
| Aplazada | Media (6.5) | 0.35% | — | Dmitry V Barcode Generator FOR WoocommerceAI | 31/1/2025 | 17/6/2026 | Insertion of Sensitive Information Into Sent Data vulnerability in Dmitry V. (CEO of "UKR Solution") Barcode Generator for WooCommerce embedding-barcodes-into-product-pages-and-orders allows Retrieve Embedded Sensitive Data.This issue affects Barcode Generator for WooCommerce: from n/a through <= 2.0.2. | |
| Aplazada | Crítica (9.1) | 0.48% | — | Dmitry V Barcode Scanner With Inventory AND Order ManagerAI | 21/1/2025 | 17/6/2026 | Unrestricted Upload of File with Dangerous Type vulnerability in Dmitry V. (CEO of "UKR Solution") Barcode Scanner with Inventory & Order Manager barcode-scanner-lite-pos-to-manage-products-inventory-and-orders allows Upload a Web Shell to a Web Server.This issue affects Barcode Scanner with Inventory & Order Manager:… | |
| Aplazada | Alta (7.1) | 0.44% | — | Dmitry V Barcode Scanner With Inventory AND Order ManagerAI | 13/12/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Dmitry V. (CEO of "UKR Solution") Barcode Scanner with Inventory & Order Manager barcode-scanner-lite-pos-to-manage-products-inventory-and-orders allows Reflected XSS.This issue affects Barcode Scanner with Inventory… | |
| Aplazada | Media (4.3) | 0.25% | — | Dmitry V Barcode Scanner With Inventory AND Order ManagerAI | 14/5/2024 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Dmitry V. (CEO of "UKR Solution") Barcode Scanner with Inventory & Order Manager barcode-scanner-lite-pos-to-manage-products-inventory-and-orders.This issue affects Barcode Scanner with Inventory & Order Manager: from n/a through <= 1.5.4. | |
| Aplazada | Media (5.3) | 0.58% | — | Dmitry V Barcode Scanner With Inventory AND Order ManagerAI | 14/5/2024 | 17/6/2026 | Insertion of Sensitive Information Into Sent Data vulnerability in Dmitry V. (CEO of "UKR Solution") Barcode Scanner with Inventory & Order Manager barcode-scanner-lite-pos-to-manage-products-inventory-and-orders.This issue affects Barcode Scanner with Inventory & Order Manager: from n/a through <= 1.5.4. | |
| Aplazada | Alta (8.4) | 0.23% | — | Deepmagic DmitryAI | 30/4/2024 | 17/6/2026 | DMitry (Deepmagic Information Gathering Tool) 1.3a has a format-string vulnerability, with a threat model similar to CVE-2017-7938. | |
| Aplazada | Alta (7.1) | 0.38% | — | Dmitry V Barcode Scanner With Inventory AND Order ManagerAI | 19/3/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Dmitry V. (CEO of "UKR Solution") Barcode Scanner with Inventory & Order Manager barcode-scanner-lite-pos-to-manage-products-inventory-and-orders.This issue affects Barcode Scanner with Inventory & Order Manager: from… | |
| Modificada | Crítica (9.8) | 2.6% | — | Dmitry Project Dmitry | 19/6/2020 | 17/6/2026 | A stack-based buffer overflow in DMitry (Deepmagic Information Gathering Tool) 1.3a might allow remote WHOIS servers to execute arbitrary code via a long line in a response that is mishandled by nic_format_buff. | |
| Modificada | Media (6.6) | 5.0% | 💥 Exploit | Mor-pah.net Dmitry Deepmagic Information Gathering Tool | 20/4/2017 | 17/6/2026 | Stack-based buffer overflow in DMitry (Deepmagic Information Gathering Tool) version 1.3a (Unix) allows attackers to cause a denial of service (application crash) or possibly have unspecified other impact via a long argument. An example threat model is automated execution of DMitry with hostname strings found in local… | |
| Modificada | Baja (2.1) | 0.94% | — | Dmitry Loac Taxotouch | 20/9/2012 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in the Taxotouch module for Drupal allows remote authenticated users with certain permissions to inject arbitrary web script or HTML via unspecified vectors. | |
| Modificada | Media (6.8) | 2.3% | — | Dmitry Baryshev Ksquirrel-libs | 26/2/2009 | 16/6/2026 | Multiple stack-based buffer overflows in the mt_codec::getHdrHead function in kernel/kls_hdr/fmt_codec_hdr.cpp in ksquirrel-libs 0.8.0 allow context-dependent attackers to execute arbitrary code via a crafted Radiance RGBE image (aka .hdr file). | |
| Modificada | Alta (7.5) | 1.5% | — | Dmitry Sheiko Business Card WEB Builder | 8/11/2006 | 16/6/2026 | Multiple PHP remote file inclusion vulnerabilities in Dmitry Sheiko Business Card Web Builder (BCWB) 2.5 allow remote attackers to execute arbitrary PHP code via a URL in the root_path_admin parameter to (1) /include/startup.inc.php, (2) dcontent/default.css.php, or (3) system/default.css.php, different vectors than… | |
| Modificada | Media (5.1) | 2.4% | 💥 Exploit | Dmitry Sheiko Sapid Gallery | 10/8/2006 | 16/6/2026 | Multiple PHP remote file inclusion vulnerabilities in Dmitry Sheiko SAPID Gallery 1.0 and earlier allow remote attackers to execute arbitrary PHP code via a URL in the (1) root_path parameter to (a) usr/extensions/get_calendar.inc.php or the (2) GLOBALS[root_path] parameter to (b) usr/extensions/get_tree.inc.php. | |
| Modificada | Media (5.1) | 3.8% | 💥 Exploit | Dmitry Sheiko Sapid Shop | 10/8/2006 | 16/6/2026 | PHP remote file inclusion vulnerability in usr/extensions/get_tree.inc.php in Dmitry Sheiko SAPID Shop 1.2 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the GLOBALS[root_path] parameter. |