Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2687▼ 562 respecto a la semana anterior
Críticas / altas1259▼ 239 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)265▼ 239 respecto a la semana anterior
–

108 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (8.8)3.9%—Barcodewiz Barcode Activex Control9/1/201817/6/2026
Multiple buffer overflows in BarCodeWiz BarCode before 6.7 ActiveX control (BarcodeWiz.DLL) allow remote attackers to execute arbitrary code via a long argument to the (1) BottomText or (2) TopText property.
ModificadaMedia (6.8)2.3%—Freebit Elphonebtnv6 Activex Control7/9/201517/6/2026
Buffer overflow in the ExecCall method in c2lv6.ocx in the FreeBit ELPhoneBtnV6 ActiveX control allows remote attackers to execute arbitrary code via a crafted HTML document, related to the discontinued "Click to Live" service.
ModificadaAlta (7.5)1.4%—Easewe Software Easewe FTP OCX Activex Control1/1/201516/6/2026
The EaseWeFtp.FtpLibrary ActiveX control in EaseWeFtp.ocx in Easewe FTP OCX 4.5.0.9 does not restrict access to certain methods, which allows remote attackers to execute arbitrary files via a pathname in the first argument to the (1) Execute or (2) Run method, (3) write to arbitrary files via a pathname in the…
ModificadaAlta (9.3)3.6%—Myheritage Sequeryobject Activex Control6/6/201416/6/2026
Multiple array index errors in the MyHeritage SEQueryObject ActiveX control (SearchEngineQuery.dll) 1.0.2.0 allow remote attackers to execute arbitrary code via the (1) seTokensArray, or (2) seTokensValuesArray parameter to the AddTokens method; (3) seLastNameTokensArray parameter to the AddLastNameTokens method; (4)…
ModificadaAlta (9.3)11%💥 ExploitDaum Communications Daumgame Activex Control30/1/201417/6/2026
Buffer overflow in the IconCreate method in an ActiveX control in the DaumGame ActiveX plugin 1.1.0.4 and 1.1.0.5 allows remote attackers to execute arbitrary code via a long string, as exploited in the wild in January 2014.
ModificadaAlta (8.1)7.4%💥 ExploitMw6tech Aztec Activex ControlMw6tech Datamatrix Activex ControlMw6tech Maxicode Activex Control21/1/201416/6/2026
MW6 Aztec, DataMatrix, and MaxiCode ActiveX controls before version 4.0 vulnerable to arbitrary code via a crafted HTML document. Latest versions (4.0) of MW6 Aztec, DataMatrix, and MaxiCode ActiveX controls have resolved the issue
ModificadaAlta (8.8)4.1%💥 ExploitAxis Media Control Activex Control4/10/201316/6/2026
The AXIS Media Control (AMC) ActiveX control (AxisMediaControlEmb.dll) 6.2.10.11 for AXIS network cameras allows remote attackers to create or overwrite arbitrary files via a file path to the (1) StartRecord, (2) SaveCurrentImage, or (3) StartRecordMedia methods.
ModificadaMedia (4.3)2.1%—HP PKI Activex Control12/1/201316/6/2026
The KillProcess method in the HP PKI ActiveX control (HPPKI.ocx) before 1.2.0.1 allows remote attackers to cause a denial of service (kill process) via the partial or full name of a process.
ModificadaAlta (9.3)12%💥 ExploitDlink Camera Stream Client Activex ControlDlink Dcs-5605 PTZ IP Network Camera6/10/201216/6/2026
Stack-based buffer overflow in the SelectDirectory method in DcsCliCtrl.dll in Camera Stream Client ActiveX Control, as used in D-Link DCS-5605 PTZ IP Network Camera, allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a long string argument.
ModificadaAlta (9.3)9.8%💥 ExploitOracle Hyperion Strategic FinanceTidestone Formula ONE Activex Control15/9/201216/6/2026
Heap-based buffer overflow in the SetDevNames method of the Tidestone Formula One ActiveX control (TTF16.ocx) 6.3.5 Build 1 in Oracle Hyperion Strategic Finance 12.x and possibly earlier allows remote attackers to execute arbitrary code via a long string to the DriverName parameter.
ModificadaAlta (10)71%💥 ExploitTrendnet Securview Wireless Internet Camera Activex ControlTrendnet Securview Wireless Internet Camera6/9/201216/6/2026
Stack-based buffer overflow in the UltraMJCam ActiveX Control in TRENDnet SecurView TV-IP121WN Wireless Internet Camera allows remote attackers to execute arbitrary code via a long string to the OpenFileDlg method.
ModificadaAlta (9.3)36%💥 ExploitCisco Linksys Playerpt Activex Control19/7/201216/6/2026
Stack-based buffer overflow in the SetSource method in the Cisco Linksys PlayerPT ActiveX control 1.0.0.15 in PlayerPT.ocx on the Cisco WVC200 Wireless-G PTZ Internet video camera allows remote attackers to execute arbitrary code via a long URL in the first argument (aka the sURL argument).
ModificadaAlta (9.3)5.1%—Luratech Lurawave JP2 Activex Control2/2/201216/6/2026
Stack-based buffer overflow in jp2_x.dll in LuraWave JP2 ActiveX Control 2.1.5.5 and other versions before 2.1.5.11 allows remote attackers to execute arbitrary code via a JPEG2000 (JP2) file with a crafted Quantization Default (QCD) marker segment.
ModificadaAlta (9.3)39%💥 ExploitNtrglobal NTR Activex Control15/1/201216/6/2026
The StopModule method in the NTR ActiveX control before 2.0.4.8 allows remote attackers to execute arbitrary code via a crafted lModule parameter that triggers use of an arbitrary memory address as a function pointer.
ModificadaAlta (9.3)42%💥 ExploitNtrglobal NTR Activex Control15/1/201216/6/2026
Multiple stack-based buffer overflows in the NTR ActiveX control before 2.0.4.8 allow remote attackers to execute arbitrary code via (1) a long bstrUrl parameter to the StartModule method, (2) a long bstrParams parameter to the Check method, a long bstrUrl parameter to the (3) Download or (4) DownloadModule method…
ModificadaAlta (9.3)2.9%—Sunplus-tech DVR Remote Activex Control26/11/201116/6/2026
DVRemoteAx.ax 2.1.0.39 in the DVR Remote ActiveX control allows remote attackers to execute arbitrary code via a crafted DVRobot.dll file in a manifest directory on a web server.
ModificadaAlta (9.3)1.9%—Uusee Uuplayer Activex ControlUusee9/8/201116/6/2026
The Play method in the UUPlayer ActiveX control 6.0.0.1 in UUSee 2010 6.11.0609.2 allows remote attackers to execute arbitrary programs via a UNC share pathname in the MPlayerPath parameter.
ModificadaAlta (9.3)4.2%—Uusee Uuplayer Activex ControlUusee9/8/201116/6/2026
Heap-based buffer overflow in the SendLogAction method in the UUPlayer ActiveX control 6.0.0.1 in UUSee 2010 6.11.0609.2 might allow remote attackers to execute arbitrary code via a long argument.
ModificadaAlta (9.3)5.4%—Provideo Alarm Activex ControlProvideo Gmax Activex ControlProvideo Paxplayer Activex Control5/8/201116/6/2026
Multiple buffer overflows in the Provideo ActiveX controls allow remote attackers to execute arbitrary code via crafted input fields, as demonstrated by (1) a long strIp argument to the voice method in 2way.dll in the alarm 1.0.3.1 ActiveX control, (2) a network response to AXPlayer.ocx in the GMAXPlayer 2.0.8.2…
ModificadaAlta (9.3)4.5%—Honeywell Scanserver Activex Control22/3/201116/6/2026
Use-after-free vulnerability in the addOSPLext method in the Honeywell ScanServer ActiveX control 780.0.20.5 allows remote attackers to execute arbitrary code via a crafted HTML document.
ModificadaMedia (5)1.2%—Dellsystemlite.scanner Activex Control21/2/201116/6/2026
The Dell DellSystemLite.Scanner ActiveX control in DellSystemLite.ocx 1.0.0.0 does not properly restrict the values of the WMIAttributesOfInterest property, which allows remote attackers to execute arbitrary WMI Query Language (WQL) statements via a crafted value, as demonstrated by a value that triggers disclosure of…
ModificadaMedia (5)1.6%—Dellsystemlite.scanner Activex Control21/2/201116/6/2026
Directory traversal vulnerability in the GetData method in the Dell DellSystemLite.Scanner ActiveX control in DellSystemLite.ocx 1.0.0.0 allows remote attackers to read arbitrary files via directory traversal sequences in the fileID parameter.
ModificadaAlta (9.3)5.5%—Topazsystems Sigplus PRO Activex Control7/2/201116/6/2026
Multiple heap-based buffer overflows in Topaz Systems SigPlus Pro ActiveX Control 3.95, and possibly other versions before 4.29, allow remote attackers to execute arbitrary code via a long (1) KeyString property, (2) NewPath parameter to the SetLocalIniFilePath method, or (3) NewPortPath parameter to the…
ModificadaAlta (9.3)4.8%—Topazsystems Sigplus PRO Activex Control7/2/201116/6/2026
Topaz Systems SigPlus Pro ActiveX Control 3.95, and possibly other versions before 4.29, allows remote attackers to execute arbitrary code by calling the exposed unsafe (1) SetLogFilePath and (2) SigMessage methods to create arbitrary files with arbitrary content.
ModificadaAlta (9.3)4.8%—Sonicwall Ssl-vpn End-point Interrogator/installer Activex Control3/11/201016/6/2026
Stack-based buffer overflow in SonicWALL SSL-VPN End-Point Interrogator/Installer ActiveX control (Aventail.EPInstaller) before 10.5.2 and 10.0.5 hotfix 3 allows remote attackers to execute arbitrary code via long (1) CabURL and (2) Location arguments to the Install3rdPartyComponent method.
Orbitaley — Vulnerabilidades