Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2556▼ 314 respecto a la semana anterior
Críticas / altas1340▲ 78 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 7 respecto a la semana anterior
Sin puntuar (sin CVSS)62▼ 466 respecto a la semana anterior
159 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.8) | 8.3% | — | Foxitsoftware PDF Activex | 7/1/2021 | 17/6/2026 | Foxit PDF ActiveX before 5.5.1 allows remote code execution via command injection because of the lack of a security permission control. | |
| Modificada | Alta (7.2) | 1.1% | — | Cymiinstaller322 Activex Project Cymiinstaller322 Activex | 30/6/2020 | 17/6/2026 | CyMiInstaller322 ActiveX which runs MIPLATFORM downloads files required to run applications. A vulnerability in downloading files by CyMiInstaller322 ActiveX caused by an attacker to download randomly generated DLL files and MIPLATFORM to load those DLLs due to insufficient verification. | |
| Modificada | Alta (7.2) | 0.65% | — | Inogard Activex | 29/4/2020 | 17/6/2026 | AxECM.cab(ActiveX Control) in Inogard Ebiz4u contains a vulnerability that could allow remote files to be downloaded and executed by setting arguments to the activeX method. Download of Code Without Integrity Check vulnerability in ActiveX control of Inogard Co,,LTD Ebiz4u ActiveX of Inogard Co,,LTD(AxECM.cab) allows… | |
| Modificada | Alta (7.5) | 6.6% | — | Dart Powertcp Webserver FOR Activex | 23/1/2020 | 16/6/2026 | NULL Pointer Dereference in PowerTCP WebServer for ActiveX 1.9.2 and earlier allows remote attackers to cause a denial of service (application crash) via a crafted HTTP request. | |
| Modificada | Alta (8.8) | 1.0% | — | Yes24 Viewer Activex | 15/8/2019 | 17/6/2026 | Yes24ViewerX ActiveX Control 1.0.327.50126 and earlier versions contains a vulnerability that could allow remote attackers to download and execute arbitrary files by setting the arguments to the ActiveX method. This can be leveraged for code execution. | |
| Modificada | Alta (7.8) | 2.1% | — | Foxitsoftware Foxit PDF SDK Activex | 17/6/2019 | 17/6/2026 | A command injection can occur for specially crafted PDF files in Foxit Reader SDK (ActiveX) 5.4.0.1031 when parsing a launch action. An attacker can leverage this to gain remote code execution. | |
| Modificada | Alta (7.8) | 2.3% | — | Foxitsoftware Foxit PDF SDK Activex | 17/6/2019 | 17/6/2026 | A File Write can occur for specially crafted PDF files in Foxit Reader SDK (ActiveX) Professional 5.4.0.1031 when the JavaScript API Doc.exportAsFDF is used. An attacker can leverage this to gain remote code execution. | |
| Modificada | Alta (7.8) | 2.2% | — | Foxitsoftware Foxit PDF SDK Activex | 17/6/2019 | 17/6/2026 | In Foxit Reader SDK (ActiveX) Professional 5.4.0.1031, an uninitialized object in IReader_ContentProvider::GetDocEventHandler occurs when embedding the control into Office documents. By opening a specially crafted document, an attacker can trigger an out of bounds write condition, possibly leveraging this to gain… | |
| Modificada | Alta (7.8) | 4.9% | — | Foxitsoftware Foxit PDF SDK Activex | 17/6/2019 | 17/6/2026 | A stack-based buffer overflow can occur for specially crafted PDF files in Foxit Reader SDK (ActiveX) 5.4.0.1031 when parsing the URI string. An attacker can leverage this to gain remote code execution. | |
| Modificada | Alta (7.8) | 2.2% | — | Foxitsoftware Foxit PDF SDK Activex | 17/6/2019 | 17/6/2026 | A File Write can occur for specially crafted PDF files in Foxit Reader SDK (ActiveX) Professional 5.4.0.1031 when the JavaScript API Doc.createDataObject is used. An attacker can leverage this to gain remote code execution. | |
| Modificada | Alta (7.8) | 2.6% | — | Foxitsoftware Foxit PDF SDK Activex | 17/6/2019 | 17/6/2026 | A command injection can occur for specially crafted PDF files in Foxit Reader SDK (ActiveX) Professional 5.4.0.1031 when the JavaScript API app.launchURL is used. An attacker can leverage this to gain remote code execution. | |
| Modificada | Alta (7.8) | 2.4% | — | Foxitsoftware Foxit PDF SDK Activex | 17/6/2019 | 17/6/2026 | A use after free in the TextBox field Validate action in IReader_ContentProvider can occur for specially crafted PDF files in Foxit Reader SDK (ActiveX) Professional 5.4.0.1031. An attacker can leverage this to gain remote code execution. Relative to CVE-2018-19452, this has a different free location and requires… | |
| Modificada | Alta (7.8) | 2.9% | — | Foxitsoftware Foxit PDF SDK Activex | 7/6/2019 | 17/6/2026 | A use after free in the TextBox field Mouse Enter action in IReader_ContentProvider can occur for specially crafted PDF files in Foxit Reader SDK (ActiveX) Professional 5.4.0.1031. An attacker can leverage this to gain remote code execution. Relative to CVE-2018-19444, this has a different free location and requires… | |
| Modificada | Alta (7.8) | 2.7% | — | Foxitsoftware Foxit PDF SDK Activex | 7/6/2019 | 17/6/2026 | A command injection can occur for specially crafted PDF files in Foxit Reader SDK (ActiveX) Professional 5.4.0.1031 when using the Open File action on a Field. An attacker can leverage this to gain remote code execution. | |
| Modificada | Alta (8.8) | 3.9% | — | Barcodewiz Barcode Activex Control | 9/1/2018 | 17/6/2026 | Multiple buffer overflows in BarCodeWiz BarCode before 6.7 ActiveX control (BarcodeWiz.DLL) allow remote attackers to execute arbitrary code via a long argument to the (1) BottomText or (2) TopText property. | |
| Modificada | Media (6.8) | 2.3% | — | Freebit Elphonebtnv6 Activex Control | 7/9/2015 | 17/6/2026 | Buffer overflow in the ExecCall method in c2lv6.ocx in the FreeBit ELPhoneBtnV6 ActiveX control allows remote attackers to execute arbitrary code via a crafted HTML document, related to the discontinued "Click to Live" service. | |
| Modificada | Alta (7.5) | 6.4% | — | Panasonic Security API Activex SDK | 6/7/2015 | 17/6/2026 | Stack-based buffer overflow in the Ipropsapi.ipropsapiCtrl.1 ActiveX control in ipropsapivideo in Panasonic Security API (PS-API) ActiveX SDK before 8.10.18 allows remote attackers to execute arbitrary code via a long string to the MulticastAddr method. | |
| Modificada | Media (6.8) | 5.6% | — | Panasonic Security API Activex SDK | 6/7/2015 | 17/6/2026 | Multiple stack-based buffer overflows in Ipropsapi in Panasonic Security API (PS-API) ActiveX SDK before 8.10.18 allow remote attackers to execute arbitrary code via a long string in the (1) FilePassword property or to the (2) GetStringInfo method. | |
| Modificada | Alta (7.5) | 2.4% | — | Moxa Vport Activex SDK Plus | 26/5/2015 | 17/6/2026 | Multiple stack-based buffer overflows in Moxa VPort ActiveX SDK Plus before 2.8 allow remote attackers to insert assembly-code lines via vectors involving a regkey (1) set or (2) get command. | |
| Modificada | Alta (7.5) | 1.4% | — | Easewe Software Easewe FTP OCX Activex Control | 1/1/2015 | 16/6/2026 | The EaseWeFtp.FtpLibrary ActiveX control in EaseWeFtp.ocx in Easewe FTP OCX 4.5.0.9 does not restrict access to certain methods, which allows remote attackers to execute arbitrary files via a pathname in the first argument to the (1) Execute or (2) Run method, (3) write to arbitrary files via a pathname in the… | |
| Modificada | Media (6.8) | 3.7% | — | Foxitsoftware Foxit PDF SDK Activex | 17/10/2014 | 17/6/2026 | Buffer overflow in the SetLogFile method in Foxit.FoxitPDFSDKProCtrl.5 in Foxit PDF SDK ActiveX 2.3 through 5.0.1820 before 5.0.2.924 allows remote attackers to execute arbitrary code via a long string, related to global variables. | |
| Modificada | Alta (9.3) | 3.6% | — | Myheritage Sequeryobject Activex Control | 6/6/2014 | 16/6/2026 | Multiple array index errors in the MyHeritage SEQueryObject ActiveX control (SearchEngineQuery.dll) 1.0.2.0 allow remote attackers to execute arbitrary code via the (1) seTokensArray, or (2) seTokensValuesArray parameter to the AddTokens method; (3) seLastNameTokensArray parameter to the AddLastNameTokens method; (4)… | |
| Modificada | Alta (9.3) | 11% | — | Daum Communications Daumgame Activex Control | 30/1/2014 | 17/6/2026 | Buffer overflow in the IconCreate method in an ActiveX control in the DaumGame ActiveX plugin 1.1.0.4 and 1.1.0.5 allows remote attackers to execute arbitrary code via a long string, as exploited in the wild in January 2014. | |
| Modificada | Alta (8.1) | 7.4% | — | Mw6tech Aztec Activex ControlMw6tech Datamatrix Activex ControlMw6tech Maxicode Activex Control | 21/1/2014 | 16/6/2026 | MW6 Aztec, DataMatrix, and MaxiCode ActiveX controls before version 4.0 vulnerable to arbitrary code via a crafted HTML document. Latest versions (4.0) of MW6 Aztec, DataMatrix, and MaxiCode ActiveX controls have resolved the issue | |
| Modificada | Alta (8.8) | 4.1% | — | Axis Media Control Activex Control | 4/10/2013 | 16/6/2026 | The AXIS Media Control (AMC) ActiveX control (AxisMediaControlEmb.dll) 6.2.10.11 for AXIS network cameras allows remote attackers to create or overwrite arbitrary files via a file path to the (1) StartRecord, (2) SaveCurrentImage, or (3) StartRecordMedia methods. |