Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2687▼ 562 respecto a la semana anterior
Críticas / altas1259▼ 239 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)265▼ 239 respecto a la semana anterior
–

147 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (7.2)1.2%—Axis OS16/10/202317/6/2026
GoSecure on behalf of Genetec Inc. has found a flaw that allows for a remote code execution during the installation of ACAP applications on the Axis device. The application handling service in AXIS OS was vulnerable to command injection allowing an attacker to run arbitrary code. Axis has released patched AXIS OS…
ModificadaCrítica (9.8)3.3%—Apache Axis5/9/202317/6/2026
** UNSUPPORTED WHEN ASSIGNED ** When integrating Apache Axis 1.x in an application, it may not have been obvious that looking up a service through "ServiceFactory.getService" allows potentially dangerous lookup mechanisms such as LDAP. When passing untrusted input to this API method, this could expose the application…
ModificadaAlta (8.8)0.59%—Axis License Plate Verifier3/8/202317/6/2026
User provided input is not sanitized on the AXIS License Plate Verifier specific “search.cgi” allowing for SQL injections.
ModificadaAlta (8.8)0.83%—Axis License Plate Verifier3/8/202317/6/2026
User provided input is not sanitized in the “Settings > Access Control” configuration interface allowing for arbitrary code execution.
ModificadaAlta (8.8)0.83%—Axis License Plate Verifier3/8/202317/6/2026
User provided input is not sanitized on the AXIS License Plate Verifier specific “api.cgi” allowing for arbitrary code execution.
ModificadaCrítica (9.8)0.63%—Axis License Plate Verifier3/8/202317/6/2026
Due to insufficient file permissions, unprivileged users could gain access to unencrypted administrator credentials allowing the configuration of the application.
ModificadaCrítica (9.8)0.63%—Axis License Plate Verifier3/8/202317/6/2026
Due to insufficient file permissions, unprivileged users could gain access to unencrypted user credentials that are used in the integration interface towards 3rd party systems.
ModificadaAlta (8.8)0.67%—Axis License Plate Verifier3/8/202317/6/2026
A broken access control was found allowing for privileged escalation of the operator account to gain administrator privileges.
ModificadaAlta (8.8)0.31%—Axis A1001 Firmware25/7/202317/6/2026
Ariel Harush and Roy Hodir from OTORIO have found a flaw in the AXIS A1001 when communicating over OSDP. A heap-based buffer overflow was found in the pacsiod process which is handling the OSDP communication allowing to write outside of the allocated buffer. By appending invalid data to an OSDP message it was possible…
ModificadaMedia (6.5)0.30%—Axis A1001 FirmwareAxis A1210 (-b) FirmwareAxis A1601 FirmwareAxis A1610 (-b) Firmware+125/7/202317/6/2026
Knud from Fraktal.fi has found a flaw in some Axis Network Door Controllers and Axis Network Intercoms when communicating over OSDP, highlighting that the OSDP message parser crashes the pacsiod process, causing a temporary unavailability of the door-controlling functionalities meaning that doors cannot be opened or…
ModificadaMedia (5.3)0.28%—Axis OS8/5/202317/6/2026
AXIS OS 11.0.X - 11.3.x use a static RSA key in legacy LUA-components to protect Axis-specific source code. The static RSA key is not used in any other secure communication nor can it be used to compromise the device or any customer data.
ModificadaMedia (6.1)0.47%—Axis 207w Firmware21/2/202317/6/2026
A Vulnerability was discovered in Axis 207W network camera. There is a reflected XSS vulnerability in the web administration portal, which allows an attacker to execute arbitrary JavaScript via URL.
ModificadaCrítica (9.8)1.6%—Axis P1204 FirmwareAxis P3225 FirmwareAxis P3367 FirmwareAxis M3045 Firmware+215/6/202217/6/2026
A vulnerability, was found in legacy Axis devices such as P3225 and M3005. This affects an unknown part of the component CGI Script. The manipulation leads to improper privilege management. It is possible to initiate the attack remotely.
ModificadaAlta (7.8)0.38%—Axis IP Utility14/2/202217/6/2026
AXIS IP Utility before 4.18.0 allows for remote code execution and local privilege escalation by the means of DLL hijacking. IPUtility.exe would attempt to load DLLs from its current working directory which could allow for remote code execution if a compromised DLL would be placed in the same folder.
ModificadaAlta (8.8)0.95%—Axis OSAxis OS 2016Axis OS 2018Axis OS 20205/10/202117/6/2026
A user controlled parameter related to SMTP test functionality is not correctly validated making it possible to add the Carriage Return and Line Feed (CRLF) control characters and include arbitrary SMTP headers in the generated test email.
ModificadaAlta (7.5)0.89%—Axis OSAxis OS 2016Axis OS 2018Axis OS 20205/10/202117/6/2026
A user controlled parameter related to SMTP test functionality is not correctly validated making it possible to bypass blocked network recipients.
ModificadaMedia (6.8)0.80%—Axis OSAxis OS 2016Axis OS 2018Axis OS 20205/10/202117/6/2026
User controlled parameters related to SMTP notifications are not correctly validated. This can lead to a buffer overflow resulting in crashes and data leakage.
ModificadaMedia (5.3)0.40%—Axis Device Manager25/8/202117/6/2026
A user with permission to log on to the machine hosting the AXIS Device Manager client could under certain conditions extract a memory dump from the built-in Windows Task Manager application. The memory dump may potentially contain credentials of connected Axis devices.
ModificadaAlta (8.8)2.9%—Jenkins Yaml Axis16/4/202017/6/2026
Jenkins Yaml Axis Plugin 0.2.0 and earlier does not configure its YAML parser to prevent the instantiation of arbitrary types, resulting in a remote code execution vulnerability.
ModificadaAlta (7.5)92%💥 ExploitApache AxisOracle Agile Engineering Data ManagementOracle Agile Product Lifecycle ManagementOracle Application Testing Suite+331/5/201917/6/2026
A Server Side Request Forgery (SSRF) vulnerability affected the Apache Axis 1.4 distribution that was last released in 2006. Security and bug commits commits continue in the projects Axis 1.x Subversion repository, legacy users are encouraged to build from source. The successor to Axis 1.x is Axis2, the latest version…
ModificadaMedia (6.1)11%💥 PoCApache AxisOracle Agile Engineering Data ManagementOracle Agile Product Lifecycle ManagementOracle Application Testing Suite+342/8/201817/6/2026
Apache Axis 1.x up to and including 1.4 is vulnerable to a cross-site scripting (XSS) attack in the default servlet/services.
ModificadaAlta (7.5)1.5%—Axis A1001 FirmwareAxis A8004-v FirmwareAxis A8105-e FirmwareAxis A9161 Firmware+38626/6/201817/6/2026
An issue was discovered in the httpd process in multiple models of Axis IP Cameras. There is Memory Corruption.
ModificadaAlta (7.5)1.5%—Axis A1001 FirmwareAxis A8004-v FirmwareAxis A8105-e FirmwareAxis A9161 Firmware+38626/6/201817/6/2026
An issue was discovered in multiple models of Axis IP Cameras. There is an Incorrect Size Calculation.
ModificadaCrítica (9.8)80%💥 ExploitAxis A1001 FirmwareAxis A8004-v FirmwareAxis A8105-e FirmwareAxis A9161 Firmware+38626/6/201817/6/2026
An issue was discovered in multiple models of Axis IP Cameras. There is an Exposed Insecure Interface.
ModificadaCrítica (9.8)87%💥 ExploitAxis A1001 FirmwareAxis A8004-v FirmwareAxis A8105-e FirmwareAxis A9161 Firmware+38626/6/201817/6/2026
An issue was discovered in multiple models of Axis IP Cameras. There is a bypass of access control.