Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2768▼ 554 respecto a la semana anterior
Críticas / altas1325▼ 178 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)268▼ 242 respecto a la semana anterior
159 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (5.1) | 1.3% | — | Imbccontents Activex Control | 6/7/2006 | 16/6/2026 | The Execute function in iMBCContents ActiveX Control before 2.0.0.59 allows remote attackers to execute arbitrary files via the file URI handler. | |
| Modificada | Alta (9.3) | 11% | — | Gracenote Cddbcontrol Activex Control | 27/6/2006 | 16/6/2026 | Buffer overflow in GraceNote CDDBControl ActiveX Control, as used by multiple products that use Gracenote CDDB, allows remote attackers to execute arbitrary code via a long option string. | |
| Modificada | Media (5) | 14% | 💥 Exploit | TDC Cryptomathic Cenroll Activex Control | 9/5/2006 | 16/6/2026 | Stack-based buffer overflow in the createPKCS10 function in Cryptomathic Cenroll ActiveX Control 1.1.0.0 allows remote attackers to execute arbitrary code via vectors related to the TDC Digital signature. | |
| Modificada | Alta (7.5) | 7.1% | 💥 Exploit | Banktown Btcxctl20com Activex Control | 5/5/2006 | 16/6/2026 | Buffer overflow in BankTown Client Control (aka BtCxCtl20Com) 1.4.2.51817, and possibly 1.5.2.50209, allows remote attackers to execute arbitrary code via a long string in the first argument to SetBannerUrl. NOTE: portions of these details are obtained from third party information. | |
| Modificada | Media (5) | 12% | — | Microsoft LOG Sink Class Activex Control | 5/7/2005 | 16/6/2026 | The Microsoft Log Sink Class ActiveX control in pkmcore.dll is marked as "safe for scripting" for Internet Explorer, which allows remote attackers to create or append to arbitrary files. | |
| Modificada | Alta (10) | 8.2% | 💥 Exploit | Weonlydo Wodftpdlx Activex Component | 10/1/2005 | 16/6/2026 | Buffer overflow in the WodFtpDLX.ocx (WeOnlyDo!) ActiveX component before 2.3.2.97, as used by CoffeeCup Direct FTP 6.2.0.62 and CoffeeCup Free FTP 3.0.0.10, and possibly other applications, allows remote attackers to execute arbitrary code via a long filename. | |
| Modificada | Baja (2.6) | 8.3% | 💥 Exploit | Yahoo Audio Conferencing Activex Control | 31/12/2003 | 16/6/2026 | Buffer overflow in the Yahoo! Audio Conferencing (aka Voice Chat) ActiveX control before 1,0,0,45 allows remote attackers to cause a denial of service and possibly execute arbitrary code via a URL with a long hostname to Yahoo! Messenger or Yahoo! Chat. | |
| Modificada | Media (4.3) | 17% | — | Microsoft Tsac Activex Control | 31/12/2002 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in connect.asp in Microsoft Terminal Services Advanced Client (TSAC) ActiveX control allows remote attackers to inject arbitrary web script or HTML via unknown vectors. | |
| Modificada | Alta (7.5) | 17% | — | Microsoft Tsac Activex Control | 24/9/2002 | 16/6/2026 | Buffer overflow in Microsoft Terminal Services Advanced Client (TSAC) ActiveX control allows remote attackers to execute arbitrary code via a long server name field. |