Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2975▼ 108 respecto a la semana anterior
Críticas / altas1449▲ 87 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
–

159 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (4.3)2.1%—HP PKI Activex Control12/1/201316/6/2026
The KillProcess method in the HP PKI ActiveX control (HPPKI.ocx) before 1.2.0.1 allows remote attackers to cause a denial of service (kill process) via the partial or full name of a process.
ModificadaAlta (9.3)12%💥 ExploitDlink Camera Stream Client Activex ControlDlink Dcs-5605 PTZ IP Network Camera6/10/201216/6/2026
Stack-based buffer overflow in the SelectDirectory method in DcsCliCtrl.dll in Camera Stream Client ActiveX Control, as used in D-Link DCS-5605 PTZ IP Network Camera, allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a long string argument.
ModificadaMedia (5)2.3%💥 ExploitDart Powertcp Activex4/10/201216/6/2026
Stack consumption vulnerability in dartwebserver.dll 1.9 and earlier, as used in Dart PowerTCP WebServer for ActiveX and other products, allows remote attackers to cause a denial of service (daemon crash) via a long request.
ModificadaAlta (9.3)36%💥 ExploitAsus Ipswcom Activex ComponentAsus Net4switch15/9/201216/6/2026
Buffer overflow in the CxDbgPrint function in the ipswcom.dll ActiveX component 1.0.0.1 for ASUS Net4Switch 1.0.0020 allows remote attackers to execute arbitrary code via a long parameter to the Alert method.
ModificadaAlta (9.3)9.8%💥 ExploitOracle Hyperion Strategic FinanceTidestone Formula ONE Activex Control15/9/201216/6/2026
Heap-based buffer overflow in the SetDevNames method of the Tidestone Formula One ActiveX control (TTF16.ocx) 6.3.5 Build 1 in Oracle Hyperion Strategic Finance 12.x and possibly earlier allows remote attackers to execute arbitrary code via a long string to the DriverName parameter.
ModificadaAlta (10)71%💥 ExploitTrendnet Securview Wireless Internet Camera Activex ControlTrendnet Securview Wireless Internet Camera6/9/201216/6/2026
Stack-based buffer overflow in the UltraMJCam ActiveX Control in TRENDnet SecurView TV-IP121WN Wireless Internet Camera allows remote attackers to execute arbitrary code via a long string to the OpenFileDlg method.
ModificadaAlta (9.3)36%💥 ExploitCisco Linksys Playerpt Activex Control19/7/201216/6/2026
Stack-based buffer overflow in the SetSource method in the Cisco Linksys PlayerPT ActiveX control 1.0.0.15 in PlayerPT.ocx on the Cisco WVC200 Wireless-G PTZ Internet video camera allows remote attackers to execute arbitrary code via a long URL in the first argument (aka the sURL argument).
ModificadaAlta (9.3)5.1%—Luratech Lurawave JP2 Activex Control2/2/201216/6/2026
Stack-based buffer overflow in jp2_x.dll in LuraWave JP2 ActiveX Control 2.1.5.5 and other versions before 2.1.5.11 allows remote attackers to execute arbitrary code via a JPEG2000 (JP2) file with a crafted Quantization Default (QCD) marker segment.
ModificadaAlta (9.3)39%💥 ExploitNtrglobal NTR Activex Control15/1/201216/6/2026
The StopModule method in the NTR ActiveX control before 2.0.4.8 allows remote attackers to execute arbitrary code via a crafted lModule parameter that triggers use of an arbitrary memory address as a function pointer.
ModificadaAlta (9.3)42%💥 ExploitNtrglobal NTR Activex Control15/1/201216/6/2026
Multiple stack-based buffer overflows in the NTR ActiveX control before 2.0.4.8 allow remote attackers to execute arbitrary code via (1) a long bstrUrl parameter to the StartModule method, (2) a long bstrParams parameter to the Check method, a long bstrUrl parameter to the (3) Download or (4) DownloadModule method…
ModificadaAlta (9.3)2.9%—Sunplus-tech DVR Remote Activex Control26/11/201116/6/2026
DVRemoteAx.ax 2.1.0.39 in the DVR Remote ActiveX control allows remote attackers to execute arbitrary code via a crafted DVRobot.dll file in a manifest directory on a web server.
ModificadaAlta (9.3)1.9%—Uusee Uuplayer Activex ControlUusee9/8/201116/6/2026
The Play method in the UUPlayer ActiveX control 6.0.0.1 in UUSee 2010 6.11.0609.2 allows remote attackers to execute arbitrary programs via a UNC share pathname in the MPlayerPath parameter.
ModificadaAlta (9.3)4.2%—Uusee Uuplayer Activex ControlUusee9/8/201116/6/2026
Heap-based buffer overflow in the SendLogAction method in the UUPlayer ActiveX control 6.0.0.1 in UUSee 2010 6.11.0609.2 might allow remote attackers to execute arbitrary code via a long argument.
ModificadaAlta (9.3)5.4%—Provideo Alarm Activex ControlProvideo Gmax Activex ControlProvideo Paxplayer Activex Control5/8/201116/6/2026
Multiple buffer overflows in the Provideo ActiveX controls allow remote attackers to execute arbitrary code via crafted input fields, as demonstrated by (1) a long strIp argument to the voice method in 2way.dll in the alarm 1.0.3.1 ActiveX control, (2) a network response to AXPlayer.ocx in the GMAXPlayer 2.0.8.2…
ModificadaAlta (9.3)4.5%—Honeywell Scanserver Activex Control22/3/201116/6/2026
Use-after-free vulnerability in the addOSPLext method in the Honeywell ScanServer ActiveX control 780.0.20.5 allows remote attackers to execute arbitrary code via a crafted HTML document.
ModificadaMedia (5)1.2%—Dellsystemlite.scanner Activex Control21/2/201116/6/2026
The Dell DellSystemLite.Scanner ActiveX control in DellSystemLite.ocx 1.0.0.0 does not properly restrict the values of the WMIAttributesOfInterest property, which allows remote attackers to execute arbitrary WMI Query Language (WQL) statements via a crafted value, as demonstrated by a value that triggers disclosure of…
ModificadaMedia (5)1.6%—Dellsystemlite.scanner Activex Control21/2/201116/6/2026
Directory traversal vulnerability in the GetData method in the Dell DellSystemLite.Scanner ActiveX control in DellSystemLite.ocx 1.0.0.0 allows remote attackers to read arbitrary files via directory traversal sequences in the fileID parameter.
ModificadaAlta (10)56%💥 ExploitMoxa Activex SDK18/2/201116/6/2026
Stack-based buffer overflow in a certain ActiveX control in MediaDBPlayback.DLL 2.2.0.5 in the Moxa ActiveX SDK allows remote attackers to execute arbitrary code via a long PlayFileName property value.
ModificadaAlta (9.3)5.5%—Topazsystems Sigplus PRO Activex Control7/2/201116/6/2026
Multiple heap-based buffer overflows in Topaz Systems SigPlus Pro ActiveX Control 3.95, and possibly other versions before 4.29, allow remote attackers to execute arbitrary code via a long (1) KeyString property, (2) NewPath parameter to the SetLocalIniFilePath method, or (3) NewPortPath parameter to the…
ModificadaAlta (9.3)4.8%—Topazsystems Sigplus PRO Activex Control7/2/201116/6/2026
Topaz Systems SigPlus Pro ActiveX Control 3.95, and possibly other versions before 4.29, allows remote attackers to execute arbitrary code by calling the exposed unsafe (1) SetLogFilePath and (2) SigMessage methods to create arbitrary files with arbitrary content.
ModificadaMedia (6.8)1.0%—Redhat Spice-activexRedhat Enterprise Virtualization Manager8/12/201016/6/2026
Race condition in the SPICE (aka spice-activex) plug-in for Internet Explorer in Red Hat Enterprise Virtualization (RHEV) Manager before 2.2.4 allows local users to create a certain named pipe, and consequently gain privileges, via vectors involving knowledge of the name of this named pipe, in conjunction with use of…
ModificadaAlta (9.3)4.8%—Sonicwall Ssl-vpn End-point Interrogator/installer Activex Control3/11/201016/6/2026
Stack-based buffer overflow in SonicWALL SSL-VPN End-Point Interrogator/Installer ActiveX control (Aventail.EPInstaller) before 10.5.2 and 10.0.5 hotfix 3 allows remote attackers to execute arbitrary code via long (1) CabURL and (2) Location arguments to the Install3rdPartyComponent method.
ModificadaAlta (10)4.9%—Realpage Module Activex Control26/10/201016/6/2026
Multiple buffer overflows in the RealPage Module Upload ActiveX control in Realpage.dll 1.0.0.9 in RealPage Module ActiveX Controls allow remote attackers to execute arbitrary code via a long (1) DestURL or (2) SourceFile property value.
ModificadaMedia (5)1.4%—Realpage Module Activex Controls26/10/201016/6/2026
The Upload method in the RealPage Module Upload ActiveX control in Realpage.dll 1.0.0.9 in RealPage Module ActiveX Controls does not properly restrict certain property values, which allows remote attackers to read arbitrary files via a filename in the SourceFile property in conjunction with an http URL in the DestURL…
ModificadaAlta (9.3)3.9%—Oracle Siebel Option Pack IE Activex Control17/8/201016/6/2026
The Oracle Siebel Option Pack for IE ActiveX control does not properly initialize memory that is used by the NewBusObj method, which allows remote attackers to execute arbitrary code via a crafted HTML document.
Orbitaley — Vulnerabilidades