Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2703▼ 615 respecto a la semana anterior
Críticas / altas1293▼ 208 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)291▼ 219 respecto a la semana anterior
–

159 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (7.5)16%💥 ExploitGateway Cweblaunchctl Activex ControlGateway Weblaunch10/1/200816/6/2026
Multiple stack-based buffer overflows in the WebLaunch.WeblaunchCtl.1 (aka CWebLaunchCtl) ActiveX control in weblaunch.ocx 1.0.0.1 in Gateway Weblaunch allow remote attackers to execute arbitrary code via a long string in the (1) second or (2) fourth argument to the DoWebLaunch method. NOTE: some of these details are…
ModificadaMedia (6.8)3.7%💥 ExploitRavware Flic Activex Control21/12/200716/6/2026
Buffer overflow in RavWare Software MAS Flic ActiveX Control (masflc.ocx) 1.0.0.1 allows remote attackers to execute arbitrary code via a long FileName property.
ModificadaAlta (9.3)38%💥 ExploitIntuit BookkeepingIntuit ProseriesIntuit QuickbooksIntuit Quicken+415/12/200716/6/2026
Multiple stack-based buffer overflows in the awApi4.AnswerWorks.1 ActiveX control in awApi4.dll 4.0.0.42, as used by Vantage Linguistics AnswerWorks, and Intuit Clearly Bookkeeping, ProSeries, QuickBooks, Quicken, QuickTax, and TurboTax, allow remote attackers to execute arbitrary code via long arguments to the (1)…
ModificadaMedia (4.3)2.2%💥 ExploitWebex Communications Webex Gpccontainer Activex Control15/11/200716/6/2026
Unspecified vulnerability in the GpcContainer.GpcContainer.1 ActiveX control in WebEx allows remote attackers to cause a denial of service (memory access violation and crash) via (1) an invalid argument to the InitParam method or (2) an unspecified vector involving the SetParam method.
ModificadaAlta (9.3)3.7%💥 ExploitEdraw Flowchart Activex5/11/200716/6/2026
Absolute path traversal vulnerability in the EDraw Flowchart ActiveX control in EDImage.ocx 2.0.2005.1104 allows remote attackers to create or overwrite arbitrary files with arbitrary contents via a full pathname in the second argument to the HttpDownloadFile method, a different product than CVE-2007-4420.
ModificadaAlta (7.5)4.7%—Automated Solutions Modbus Slave Activex Control19/9/200716/6/2026
Unspecified vulnerability in the Modbus/TCP Diagnostic function in MiniHMI.exe for the Automated Solutions Modbus Slave ActiveX Control before 1.5 allows remote attackers to corrupt the heap and possibly execute arbitrary code via malformed Modbus requests to TCP port 502.
ModificadaAlta (10)10%💥 ExploitMW6 Technologies Qrcode Activex19/9/200716/6/2026
Multiple absolute path traversal vulnerabilities in the MW6QRCode.QRCode.1 ActiveX control in MW6QRCode.dll in MW6 Technologies QRCode ActiveX 3.0.0.1 and earlier allow remote attackers to create or overwrite arbitrary files via a full pathname in the argument to the (1) SaveAsBMP or (2) SaveAsWMF method. NOTE: some…
ModificadaAlta (9.3)6.7%—Photochannel PNI Digital Media Upload Plugin Activex Control18/9/200716/6/2026
Multiple stack-based buffer overflows in the PhotoChannel Networks PNI Digital Media Photo Upload Plugin ActiveX control before 2.0.0.10, as used by multiple retailers, allow remote attackers to execute arbitrary code via unspecified vectors.
ModificadaAlta (9.3)7.0%💥 ExploitClever Components Internet Activex Suite30/7/200716/6/2026
Absolute path traversal vulnerability in the clInetSuiteX6.clWebDav ActiveX control in CLINETSUITEX6.OCX in Clever Internet ActiveX Suite 6.2 allows remote attackers to create or overwrite arbitrary files via a full pathname in the second argument to the GetToFile method. NOTE: some of these details are obtained from…
ModificadaMedia (6.8)4.6%💥 ExploitHP Photo Digital Imaging Activex Control10/7/200716/6/2026
Absolute path traversal vulnerability in a certain ActiveX control in hpqvwocx.dll 2.1.0.556 in Hewlett-Packard (HP) Digital Imaging allows remote attackers to create or overwrite arbitrary files via the second argument to the SaveToFile method.
ModificadaMedia (6.4)2.9%💥 ExploitChilkat Software Chilkat ZIP Activex Control10/7/200716/6/2026
Absolute path traversal vulnerability in the Chilkat Software Chilkat Zip ActiveX control in ChilkatZip2.dll 12.4.2.0 allows remote attackers to create or overwrite arbitrary files via a full pathname in the argument to the (1) SaveLastError method and probably the (2) WriteExe method.
ModificadaAlta (7.6)14%💥 ExploitAMX Netlinx VNC Activex Control3/7/200716/6/2026
Multiple buffer overflows in the AMX NetLinx VNC (AmxVnc) ActiveX control in AmxVnc.dll 1.0.13.0 allow remote attackers to execute arbitrary code via long (1) Host, (2) Password, or (3) LogFile property values.
ModificadaMedia (6.4)8.8%💥 ExploitHP Photo Digital Imaging Activex Control29/6/200716/6/2026
Absolute path traversal in a certain ActiveX control in hpqxml.dll 2.0.0.133 in Hewlett-Packard (HP) Photo Digital Imaging allows remote attackers to create or overwrite arbitrary files via the argument to the saveXMLAsFile method.
ModificadaMedia (6.4)2.9%💥 ExploitCiviltech Avax Vector Activex27/6/200716/6/2026
A certain ActiveX control in Avaxswf.dll 1.0.0.1 in Civitech Avax Vector 1.3 allows remote attackers to create or overwrite arbitrary files via a full pathname in the argument to the WriteMovie method.
ModificadaAlta (9.3)35%💥 ExploitRKD Software Barcode Activex27/6/200716/6/2026
Stack-based buffer overflow in the BeginPrint method in a certain ActiveX control in RKD Software (barcodetools.com) BarCodeAx.dll 4.9 allows remote attackers to execute arbitrary code via a long argument.
ModificadaAlta (7.8)42%💥 ExploitMicrosoft OfficeMicrosoft Office Msodatasourcecontrol Activex19/6/200716/6/2026
Buffer overflow in the Microsoft Office MSODataSourceControl ActiveX object allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a long argument to the DeleteRecordSourceIfUnused method.
ModificadaAlta (9.3)6.5%—Zoomify Viewer Activex Control11/6/200716/6/2026
Multiple stack-based buffer overflows in the Zoomify Viewer ActiveX control in ZActiveX.dll might allow remote attackers to execute arbitrary code via unspecified vectors.
ModificadaAlta (10)44%💥 ExploitMicrosoft Internet ExplorerProvideo Camimage Activex Control7/6/200716/6/2026
Buffer overflow in the Provideo Camimage ActiveX control in ISSCamControl.dll 1.0.1.5, when Internet Explorer 6 is used on Windows 2000 SP4, allows remote attackers to execute arbitrary code via a long URL property value.
ModificadaMedia (6.8)3.4%—Media Technology Group Cdpass Activex Control1/6/200716/6/2026
Multiple stack-based buffer overflows in the Media Technology Group CDPass ActiveX control in CDPass.dll allow remote attackers to execute arbitrary code via unspecified vectors, possibly involving the GetTOC2 method.
ModificadaAlta (9.3)5.2%—BT Business Connect Webhelper Activex Control1/6/200716/6/2026
Multiple buffer overflows in the British Telecommunications Business Connect webhelper ActiveX control before 1.0.0.7 in btbconnectwebcontrol.dll allow remote attackers to execute arbitrary code via unspecified vectors.
ModificadaAlta (10)4.7%💥 ExploitH+H Vcdapilibapi Activex ControlH+H Virtual CD24/5/200716/6/2026
The VCDAPILibApi ActiveX control in vc9api.DLL 9.0.0.57 in Virtual CD 9.0.0.2 allows remote attackers to execute arbitrary commands via a command line in the first argument to the VCDLaunchAndWait function.
ModificadaAlta (10)4.6%—SKY Software Shcombobox Activex ControlSKY Software Shell Megapack Activex24/5/200716/6/2026
Stack-based buffer overflow in the SetPath function in the shComboBox ActiveX control (shcmb80.ocx) in Sky Software Shell MegaPack ActiveX 8.0 allows remote attackers to execute arbitrary code via a long argument. NOTE: the provenance of this information is unknown; the details are obtained solely from third party…
ModificadaAlta (9.3)6.4%💥 ExploitLead Technologies Leadtools Isis Activex Control22/5/200716/6/2026
Heap-based buffer overflow in LEAD Technologies LEADTOOLS ISIS ActiveX Control (ltisi14E.ocx) 14.5.0.44 and earlier allows remote attackers to execute arbitrary code via a long DriverName property.
ModificadaAlta (7.5)5.5%💥 ExploitPegasus Imagn Activex Control22/5/200716/6/2026
Multiple stack-based buffer overflows in the Pegasus ImagN' ActiveX control (IMW32O40.OCX) 4.00.041 allow remote attackers to execute arbitrary code via (1) a long FileName parameter, or unspecified vectors involving the (2) BeginReport, (3) CreatePictureExA, (4) DefineImage, (5) DefineImageEx, (6) DefineImageFox, (7)…
ModificadaAlta (9.4)4.6%💥 ExploitMorovia Barcode Activex Control13/5/200716/6/2026
A certain ActiveX control in Morovia Barcode ActiveX Professional 3.3.1304 allows remote attackers to overwrite arbitrary files by calling the Save method with an arbitrary filename.