Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2687▼ 562 respecto a la semana anterior
Críticas / altas1259▼ 239 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)265▼ 239 respecto a la semana anterior
108 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (8.8) | 3.9% | — | Barcodewiz Barcode Activex Control | 9/1/2018 | 17/6/2026 | Multiple buffer overflows in BarCodeWiz BarCode before 6.7 ActiveX control (BarcodeWiz.DLL) allow remote attackers to execute arbitrary code via a long argument to the (1) BottomText or (2) TopText property. | |
| Modificada | Media (6.8) | 2.3% | — | Freebit Elphonebtnv6 Activex Control | 7/9/2015 | 17/6/2026 | Buffer overflow in the ExecCall method in c2lv6.ocx in the FreeBit ELPhoneBtnV6 ActiveX control allows remote attackers to execute arbitrary code via a crafted HTML document, related to the discontinued "Click to Live" service. | |
| Modificada | Alta (7.5) | 1.4% | — | Easewe Software Easewe FTP OCX Activex Control | 1/1/2015 | 16/6/2026 | The EaseWeFtp.FtpLibrary ActiveX control in EaseWeFtp.ocx in Easewe FTP OCX 4.5.0.9 does not restrict access to certain methods, which allows remote attackers to execute arbitrary files via a pathname in the first argument to the (1) Execute or (2) Run method, (3) write to arbitrary files via a pathname in the… | |
| Modificada | Alta (9.3) | 3.6% | — | Myheritage Sequeryobject Activex Control | 6/6/2014 | 16/6/2026 | Multiple array index errors in the MyHeritage SEQueryObject ActiveX control (SearchEngineQuery.dll) 1.0.2.0 allow remote attackers to execute arbitrary code via the (1) seTokensArray, or (2) seTokensValuesArray parameter to the AddTokens method; (3) seLastNameTokensArray parameter to the AddLastNameTokens method; (4)… | |
| Modificada | Alta (9.3) | 11% | 💥 Exploit | Daum Communications Daumgame Activex Control | 30/1/2014 | 17/6/2026 | Buffer overflow in the IconCreate method in an ActiveX control in the DaumGame ActiveX plugin 1.1.0.4 and 1.1.0.5 allows remote attackers to execute arbitrary code via a long string, as exploited in the wild in January 2014. | |
| Modificada | Alta (8.1) | 7.4% | 💥 Exploit | Mw6tech Aztec Activex ControlMw6tech Datamatrix Activex ControlMw6tech Maxicode Activex Control | 21/1/2014 | 16/6/2026 | MW6 Aztec, DataMatrix, and MaxiCode ActiveX controls before version 4.0 vulnerable to arbitrary code via a crafted HTML document. Latest versions (4.0) of MW6 Aztec, DataMatrix, and MaxiCode ActiveX controls have resolved the issue | |
| Modificada | Alta (8.8) | 4.1% | 💥 Exploit | Axis Media Control Activex Control | 4/10/2013 | 16/6/2026 | The AXIS Media Control (AMC) ActiveX control (AxisMediaControlEmb.dll) 6.2.10.11 for AXIS network cameras allows remote attackers to create or overwrite arbitrary files via a file path to the (1) StartRecord, (2) SaveCurrentImage, or (3) StartRecordMedia methods. | |
| Modificada | Media (4.3) | 2.1% | — | HP PKI Activex Control | 12/1/2013 | 16/6/2026 | The KillProcess method in the HP PKI ActiveX control (HPPKI.ocx) before 1.2.0.1 allows remote attackers to cause a denial of service (kill process) via the partial or full name of a process. | |
| Modificada | Alta (9.3) | 12% | 💥 Exploit | Dlink Camera Stream Client Activex ControlDlink Dcs-5605 PTZ IP Network Camera | 6/10/2012 | 16/6/2026 | Stack-based buffer overflow in the SelectDirectory method in DcsCliCtrl.dll in Camera Stream Client ActiveX Control, as used in D-Link DCS-5605 PTZ IP Network Camera, allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a long string argument. | |
| Modificada | Alta (9.3) | 9.8% | 💥 Exploit | Oracle Hyperion Strategic FinanceTidestone Formula ONE Activex Control | 15/9/2012 | 16/6/2026 | Heap-based buffer overflow in the SetDevNames method of the Tidestone Formula One ActiveX control (TTF16.ocx) 6.3.5 Build 1 in Oracle Hyperion Strategic Finance 12.x and possibly earlier allows remote attackers to execute arbitrary code via a long string to the DriverName parameter. | |
| Modificada | Alta (10) | 71% | 💥 Exploit | Trendnet Securview Wireless Internet Camera Activex ControlTrendnet Securview Wireless Internet Camera | 6/9/2012 | 16/6/2026 | Stack-based buffer overflow in the UltraMJCam ActiveX Control in TRENDnet SecurView TV-IP121WN Wireless Internet Camera allows remote attackers to execute arbitrary code via a long string to the OpenFileDlg method. | |
| Modificada | Alta (9.3) | 36% | 💥 Exploit | Cisco Linksys Playerpt Activex Control | 19/7/2012 | 16/6/2026 | Stack-based buffer overflow in the SetSource method in the Cisco Linksys PlayerPT ActiveX control 1.0.0.15 in PlayerPT.ocx on the Cisco WVC200 Wireless-G PTZ Internet video camera allows remote attackers to execute arbitrary code via a long URL in the first argument (aka the sURL argument). | |
| Modificada | Alta (9.3) | 5.1% | — | Luratech Lurawave JP2 Activex Control | 2/2/2012 | 16/6/2026 | Stack-based buffer overflow in jp2_x.dll in LuraWave JP2 ActiveX Control 2.1.5.5 and other versions before 2.1.5.11 allows remote attackers to execute arbitrary code via a JPEG2000 (JP2) file with a crafted Quantization Default (QCD) marker segment. | |
| Modificada | Alta (9.3) | 39% | 💥 Exploit | Ntrglobal NTR Activex Control | 15/1/2012 | 16/6/2026 | The StopModule method in the NTR ActiveX control before 2.0.4.8 allows remote attackers to execute arbitrary code via a crafted lModule parameter that triggers use of an arbitrary memory address as a function pointer. | |
| Modificada | Alta (9.3) | 42% | 💥 Exploit | Ntrglobal NTR Activex Control | 15/1/2012 | 16/6/2026 | Multiple stack-based buffer overflows in the NTR ActiveX control before 2.0.4.8 allow remote attackers to execute arbitrary code via (1) a long bstrUrl parameter to the StartModule method, (2) a long bstrParams parameter to the Check method, a long bstrUrl parameter to the (3) Download or (4) DownloadModule method… | |
| Modificada | Alta (9.3) | 2.9% | — | Sunplus-tech DVR Remote Activex Control | 26/11/2011 | 16/6/2026 | DVRemoteAx.ax 2.1.0.39 in the DVR Remote ActiveX control allows remote attackers to execute arbitrary code via a crafted DVRobot.dll file in a manifest directory on a web server. | |
| Modificada | Alta (9.3) | 1.9% | — | Uusee Uuplayer Activex ControlUusee | 9/8/2011 | 16/6/2026 | The Play method in the UUPlayer ActiveX control 6.0.0.1 in UUSee 2010 6.11.0609.2 allows remote attackers to execute arbitrary programs via a UNC share pathname in the MPlayerPath parameter. | |
| Modificada | Alta (9.3) | 4.2% | — | Uusee Uuplayer Activex ControlUusee | 9/8/2011 | 16/6/2026 | Heap-based buffer overflow in the SendLogAction method in the UUPlayer ActiveX control 6.0.0.1 in UUSee 2010 6.11.0609.2 might allow remote attackers to execute arbitrary code via a long argument. | |
| Modificada | Alta (9.3) | 5.4% | — | Provideo Alarm Activex ControlProvideo Gmax Activex ControlProvideo Paxplayer Activex Control | 5/8/2011 | 16/6/2026 | Multiple buffer overflows in the Provideo ActiveX controls allow remote attackers to execute arbitrary code via crafted input fields, as demonstrated by (1) a long strIp argument to the voice method in 2way.dll in the alarm 1.0.3.1 ActiveX control, (2) a network response to AXPlayer.ocx in the GMAXPlayer 2.0.8.2… | |
| Modificada | Alta (9.3) | 4.5% | — | Honeywell Scanserver Activex Control | 22/3/2011 | 16/6/2026 | Use-after-free vulnerability in the addOSPLext method in the Honeywell ScanServer ActiveX control 780.0.20.5 allows remote attackers to execute arbitrary code via a crafted HTML document. | |
| Modificada | Media (5) | 1.2% | — | Dellsystemlite.scanner Activex Control | 21/2/2011 | 16/6/2026 | The Dell DellSystemLite.Scanner ActiveX control in DellSystemLite.ocx 1.0.0.0 does not properly restrict the values of the WMIAttributesOfInterest property, which allows remote attackers to execute arbitrary WMI Query Language (WQL) statements via a crafted value, as demonstrated by a value that triggers disclosure of… | |
| Modificada | Media (5) | 1.6% | — | Dellsystemlite.scanner Activex Control | 21/2/2011 | 16/6/2026 | Directory traversal vulnerability in the GetData method in the Dell DellSystemLite.Scanner ActiveX control in DellSystemLite.ocx 1.0.0.0 allows remote attackers to read arbitrary files via directory traversal sequences in the fileID parameter. | |
| Modificada | Alta (9.3) | 5.5% | — | Topazsystems Sigplus PRO Activex Control | 7/2/2011 | 16/6/2026 | Multiple heap-based buffer overflows in Topaz Systems SigPlus Pro ActiveX Control 3.95, and possibly other versions before 4.29, allow remote attackers to execute arbitrary code via a long (1) KeyString property, (2) NewPath parameter to the SetLocalIniFilePath method, or (3) NewPortPath parameter to the… | |
| Modificada | Alta (9.3) | 4.8% | — | Topazsystems Sigplus PRO Activex Control | 7/2/2011 | 16/6/2026 | Topaz Systems SigPlus Pro ActiveX Control 3.95, and possibly other versions before 4.29, allows remote attackers to execute arbitrary code by calling the exposed unsafe (1) SetLogFilePath and (2) SigMessage methods to create arbitrary files with arbitrary content. | |
| Modificada | Alta (9.3) | 4.8% | — | Sonicwall Ssl-vpn End-point Interrogator/installer Activex Control | 3/11/2010 | 16/6/2026 | Stack-based buffer overflow in SonicWALL SSL-VPN End-Point Interrogator/Installer ActiveX control (Aventail.EPInstaller) before 10.5.2 and 10.0.5 hotfix 3 allows remote attackers to execute arbitrary code via long (1) CabURL and (2) Location arguments to the Install3rdPartyComponent method. |