Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2980▼ 83 respecto a la semana anterior
Críticas / altas1452▲ 101 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)353▼ 157 respecto a la semana anterior
–

159 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (9.3)4.5%—Invensys Wonderware Archestra Configuration Access Component Activex ControlInvensys Wonderware Application Server5/8/201016/6/2026
Stack-based buffer overflow in the IConfigurationAccess interface in the Invensys Wonderware Archestra ConfigurationAccessComponent ActiveX control in Wonderware Application Server (WAS) before 3.1 SP2 P01, as used in the Wonderware Archestra Integrated Development Environment (IDE) and the InFusion Integrated…
ModificadaAlta (9.3)6.9%💥 ExploitBarcodewiz Barcode Activex Control5/8/201016/6/2026
Buffer overflow in BarCodeWiz BarCode 3.29 ActiveX control (BarcodeWiz.dll) allows remote attackers to execute arbitrary code via a long argument to the LoadProperties method.
ModificadaAlta (9.3)9.4%💥 ExploitTopazsystems Sigplus PRO Activex Control5/8/201016/6/2026
Stack-based buffer overflow in SigPlus Pro 3.74 ActiveX control allows remote attackers to execute arbitrary code via a long eighth argument (HexString) to the LCDWriteString method.
ModificadaAlta (10)3.2%—Gigabyte Dldrv2 Activex Control2/8/201016/6/2026
Array index error in the SetDLInfo method in the GIGABYTE Dldrv2 ActiveX control 1.4.206.11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via the item argument.
ModificadaAlta (10)1.8%—Gigabyte Dldrv2 Activex Control2/8/201016/6/2026
The GIGABYTE Dldrv2 ActiveX control 1.4.206.11 allows remote attackers to (1) download arbitrary programs onto a client system, and execute these programs, via vectors involving the dl method; and (2) download arbitrary programs onto a client system via vectors involving the SetDLInfo method in conjunction with the…
ModificadaAlta (10)4.6%—Creative Autoupdate Engine Activex ControlCreative Autoupdate15/6/201016/6/2026
Stack-based buffer overflow in Creative Software AutoUpdate Engine ActiveX Control 2.0.12.0, as used in Creative Software AutoUpdate 1.40.01, allows remote attackers to execute arbitrary code via vectors related to the BrowseFolder method.
ModificadaAlta (9.3)30%💥 ExploitViscomsoft Movie Player PRO SDK Activex18/1/201016/6/2026
Stack-based buffer overflow in the MOVIEPLAYER.MoviePlayerCtrl.1 ActiveX control in MoviePlayer.ocx 6.8.0.0 in Viscom Software Movie Player Pro SDK ActiveX 6.8 allows remote attackers to execute arbitrary code via a long strFontName parameter to the DrawText method.
ModificadaAlta (8.8)5.1%💥 ExploitSoftcab Sound Converter Activex29/12/200916/6/2026
Insecure method vulnerability in SoftCab Sound Converter ActiveX control (sndConverter.ocx) 1.2 allows remote attackers to create or overwrite arbitrary files via the SaveFormat method. NOTE: some of these details are obtained from third party information.
ModificadaAlta (9.3)31%💥 ExploitCA Etrust Pestpatrole Ppctl.dll Activex8/12/200916/6/2026
Stack-based buffer overflow in the PestPatrol ActiveX control (ppctl.dll) 5.6.7.9 in CA eTrust PestPatrol allows remote attackers to execute arbitrary code via a long argument to the Initialize method.
ModificadaAlta (9.3)4.8%—Larts Uploader Activex Control3/12/200916/6/2026
Multiple stack-based buffer overflows in the Lateral Arts Photobox uploader ActiveX control 1.x before 1.3, and 2.2.0.6, allow remote attackers to execute arbitrary code via a long URL string for the (1) LogURL, (2) ConnectURL, (3) SkinURL, (4) AlbumCreateURL, (5) ErrorURL, or (6) httpsinglehost property value.
ModificadaAlta (8.8)8.9%💥 ExploitAOL Superbuddy Activex Control9/10/200916/6/2026
Use-after-free vulnerability in the Sb.SuperBuddy.1 ActiveX control (sb.dll) in America Online (AOL) 9.5.0.1 allows remote attackers to trigger memory corruption or possibly execute arbitrary code via a malformed argument to the SetSuperBuddy method.
ModificadaAlta (9.3)4.8%💥 ExploitChilkatsoft Chilkat Imap Activex Control21/8/200916/6/2026
Insecure method vulnerability in ChilkatMail_v7_9.dll in the Chilkat Software IMAP ActiveX control (ChilkatMail2.ChilkatMailMan2.1) allows remote attackers to execute arbitrary programs via the LoadXmlEmail method.
ModificadaMedia (4.3)1.9%💥 ExploitAvax-software Avax Vector Activex8/7/200916/6/2026
Buffer overflow in the Avax Vector ActiveX control in avPreview.ocx in AVAX-software Avax Vector ActiveX 1.3 allows remote attackers to cause a denial of service (application crash) via a long PrinterName property.
ModificadaAlta (9.3)4.1%—Ebay Enhanced Picture Uploader Activex Control9/6/200916/6/2026
eBay Enhanced Picture Uploader ActiveX control (EPUWALcontrol.dll) before 1.0.27 allows remote attackers to execute arbitrary commands via the PictureUrls property.
ModificadaAlta (9.3)5.6%—Dlink Mpeg4 Viewer Activex Control20/5/200916/6/2026
Multiple heap-based buffer overflows in the D-Link MPEG4 Viewer ActiveX Control (csviewer.ocx) 2.11.918.2006 allow remote attackers to execute arbitrary code via a long argument to the (1) SetFilePath and (2) SetClientCookie methods. NOTE: the provenance of this information is unknown; the details are obtained solely…
ModificadaAlta (8.8)1.7%—Versalsoft Http File Upload Activex Control7/4/200916/6/2026
Insecure method vulnerability in the Versalsoft HTTP Image Uploader ActiveX control (UUploaderSvrD.dll 6.0.0.35) allows remote attackers to delete arbitrary files via the RemoveFileOrDir method.
ModificadaAlta (7.8)5.7%💥 ExploitPrecisionid Data Matrix Barcode Activex Control1/4/200916/6/2026
Multiple insecure method vulnerabilities in PRECIS~2.DLL in the PrecisionID Datamatrix ActiveX control (DMATRIXLib.Datamatrix) allow remote attackers to overwrite arbitrary files via the (1) SaveBarCode and (2) SaveEnhWMF methods.
ModificadaAlta (9.3)8.8%💥 ExploitGeovision Liveaudio Activex Control25/3/200916/6/2026
Use-after-free vulnerability in the LIVEAUDIO.LiveAudioCtrl.1 ActiveX control in LIVEAU~1.OCX 7.0 for GeoVision DVR systems allows remote attackers to execute arbitrary code by calling the GetAudioPlayingTime method with certain arguments.
ModificadaAlta (9.3)36%💥 ExploitIBM Access Support Activex Control25/3/200916/6/2026
Stack-based buffer overflow in the GetXMLValue method in the IBM Access Support ActiveX control in IbmEgath.dll, as distributed on IBM and Lenovo computers, allows remote attackers to execute arbitrary code via unspecified vectors.
ModificadaAlta (8.8)5.5%💥 ExploitGeovision Livex Activex Control10/3/200916/6/2026
Directory traversal vulnerability in the SnapShotToFile method in the GeoVision LiveX (aka LiveX_v8200) ActiveX control 8.1.2 and 8.2.0 in LIVEX_~1.OCX allows remote attackers to create or overwrite arbitrary files via a .. (dot dot) in the argument, possibly involving the PlayX and SnapShotX methods.
ModificadaAlta (9.3)5.5%💥 ExploitSopcast Sopcore Activex Control4/3/200916/6/2026
Insecure method vulnerability in the SopCast SopCore ActiveX control in sopocx.ocx 3.0.3.501 allows remote attackers to execute arbitrary programs via an executable file name in the argument to the SetExternalPlayer method.
ModificadaAlta (9.3)8.8%💥 ExploitEztools-software WEB ON Windows Activex2/2/200916/6/2026
Multiple insecure method vulnerabilities in the Web On Windows (WOW) ActiveX control in WOW ActiveX 2 allow remote attackers to (1) create and overwrite arbitrary files via the WriteIniFileString method, (2) execute arbitrary programs via the ShellExecute method, (3) read from the registry via unspecified vectors, and…
ModificadaAlta (9.3)5.6%💥 ExploitMW6 Technologies Barcode Activex27/1/200916/6/2026
Heap-based buffer overflow in MW6 Technologies Barcode ActiveX control (Barcode.MW6Barcode.1, Barcode.dll) 3.0.0.1 allows remote attackers to execute arbitrary code via a long Supplement property.
ModificadaAlta (9.3)16%—SapguiSimba Technologies Mdrmsap Activex Control10/11/200816/6/2026
Unspecified vulnerability in the Simba MDrmSap ActiveX control in mdrmsap.dll in SAP SAPgui allows remote attackers to execute arbitrary code via unknown vectors involving instantiation by Internet Explorer.
ModificadaAlta (9.3)41%💥 ExploitChilkat Software Chilkat Crypt Activex Control10/11/200816/6/2026
Insecure method vulnerability in the ChilkatCrypt2.ChilkatCrypt2.1 ActiveX control (ChilkatCrypt2.dll 4.3.2.1) in Chilkat Crypt ActiveX Component allows remote attackers to create and overwrite arbitrary files via the WriteFile method. NOTE: this could be leveraged for code execution by creating executable files in…
Orbitaley — Vulnerabilidades