Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2687▼ 562 respecto a la semana anterior
Críticas / altas1259▼ 239 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)265▼ 239 respecto a la semana anterior
147 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.2) | 1.2% | — | Axis OS | 16/10/2023 | 17/6/2026 | GoSecure on behalf of Genetec Inc. has found a flaw that allows for a remote code execution during the installation of ACAP applications on the Axis device. The application handling service in AXIS OS was vulnerable to command injection allowing an attacker to run arbitrary code. Axis has released patched AXIS OS… | |
| Modificada | Crítica (9.8) | 3.3% | — | Apache Axis | 5/9/2023 | 17/6/2026 | ** UNSUPPORTED WHEN ASSIGNED ** When integrating Apache Axis 1.x in an application, it may not have been obvious that looking up a service through "ServiceFactory.getService" allows potentially dangerous lookup mechanisms such as LDAP. When passing untrusted input to this API method, this could expose the application… | |
| Modificada | Alta (8.8) | 0.59% | — | Axis License Plate Verifier | 3/8/2023 | 17/6/2026 | User provided input is not sanitized on the AXIS License Plate Verifier specific “search.cgi” allowing for SQL injections. | |
| Modificada | Alta (8.8) | 0.83% | — | Axis License Plate Verifier | 3/8/2023 | 17/6/2026 | User provided input is not sanitized in the “Settings > Access Control” configuration interface allowing for arbitrary code execution. | |
| Modificada | Alta (8.8) | 0.83% | — | Axis License Plate Verifier | 3/8/2023 | 17/6/2026 | User provided input is not sanitized on the AXIS License Plate Verifier specific “api.cgi” allowing for arbitrary code execution. | |
| Modificada | Crítica (9.8) | 0.63% | — | Axis License Plate Verifier | 3/8/2023 | 17/6/2026 | Due to insufficient file permissions, unprivileged users could gain access to unencrypted administrator credentials allowing the configuration of the application. | |
| Modificada | Crítica (9.8) | 0.63% | — | Axis License Plate Verifier | 3/8/2023 | 17/6/2026 | Due to insufficient file permissions, unprivileged users could gain access to unencrypted user credentials that are used in the integration interface towards 3rd party systems. | |
| Modificada | Alta (8.8) | 0.67% | — | Axis License Plate Verifier | 3/8/2023 | 17/6/2026 | A broken access control was found allowing for privileged escalation of the operator account to gain administrator privileges. | |
| Modificada | Alta (8.8) | 0.31% | — | Axis A1001 Firmware | 25/7/2023 | 17/6/2026 | Ariel Harush and Roy Hodir from OTORIO have found a flaw in the AXIS A1001 when communicating over OSDP. A heap-based buffer overflow was found in the pacsiod process which is handling the OSDP communication allowing to write outside of the allocated buffer. By appending invalid data to an OSDP message it was possible… | |
| Modificada | Media (6.5) | 0.30% | — | Axis A1001 FirmwareAxis A1210 (-b) FirmwareAxis A1601 FirmwareAxis A1610 (-b) Firmware+1 | 25/7/2023 | 17/6/2026 | Knud from Fraktal.fi has found a flaw in some Axis Network Door Controllers and Axis Network Intercoms when communicating over OSDP, highlighting that the OSDP message parser crashes the pacsiod process, causing a temporary unavailability of the door-controlling functionalities meaning that doors cannot be opened or… | |
| Modificada | Media (5.3) | 0.28% | — | Axis OS | 8/5/2023 | 17/6/2026 | AXIS OS 11.0.X - 11.3.x use a static RSA key in legacy LUA-components to protect Axis-specific source code. The static RSA key is not used in any other secure communication nor can it be used to compromise the device or any customer data. | |
| Modificada | Media (6.1) | 0.47% | — | Axis 207w Firmware | 21/2/2023 | 17/6/2026 | A Vulnerability was discovered in Axis 207W network camera. There is a reflected XSS vulnerability in the web administration portal, which allows an attacker to execute arbitrary JavaScript via URL. | |
| Modificada | Crítica (9.8) | 1.6% | — | Axis P1204 FirmwareAxis P3225 FirmwareAxis P3367 FirmwareAxis M3045 Firmware+2 | 15/6/2022 | 17/6/2026 | A vulnerability, was found in legacy Axis devices such as P3225 and M3005. This affects an unknown part of the component CGI Script. The manipulation leads to improper privilege management. It is possible to initiate the attack remotely. | |
| Modificada | Alta (7.8) | 0.38% | — | Axis IP Utility | 14/2/2022 | 17/6/2026 | AXIS IP Utility before 4.18.0 allows for remote code execution and local privilege escalation by the means of DLL hijacking. IPUtility.exe would attempt to load DLLs from its current working directory which could allow for remote code execution if a compromised DLL would be placed in the same folder. | |
| Modificada | Alta (8.8) | 0.95% | — | Axis OSAxis OS 2016Axis OS 2018Axis OS 2020 | 5/10/2021 | 17/6/2026 | A user controlled parameter related to SMTP test functionality is not correctly validated making it possible to add the Carriage Return and Line Feed (CRLF) control characters and include arbitrary SMTP headers in the generated test email. | |
| Modificada | Alta (7.5) | 0.89% | — | Axis OSAxis OS 2016Axis OS 2018Axis OS 2020 | 5/10/2021 | 17/6/2026 | A user controlled parameter related to SMTP test functionality is not correctly validated making it possible to bypass blocked network recipients. | |
| Modificada | Media (6.8) | 0.80% | — | Axis OSAxis OS 2016Axis OS 2018Axis OS 2020 | 5/10/2021 | 17/6/2026 | User controlled parameters related to SMTP notifications are not correctly validated. This can lead to a buffer overflow resulting in crashes and data leakage. | |
| Modificada | Media (5.3) | 0.40% | — | Axis Device Manager | 25/8/2021 | 17/6/2026 | A user with permission to log on to the machine hosting the AXIS Device Manager client could under certain conditions extract a memory dump from the built-in Windows Task Manager application. The memory dump may potentially contain credentials of connected Axis devices. | |
| Modificada | Alta (8.8) | 2.9% | — | Jenkins Yaml Axis | 16/4/2020 | 17/6/2026 | Jenkins Yaml Axis Plugin 0.2.0 and earlier does not configure its YAML parser to prevent the instantiation of arbitrary types, resulting in a remote code execution vulnerability. | |
| Modificada | Alta (7.5) | 92% | 💥 Exploit | Apache AxisOracle Agile Engineering Data ManagementOracle Agile Product Lifecycle ManagementOracle Application Testing Suite+33 | 1/5/2019 | 17/6/2026 | A Server Side Request Forgery (SSRF) vulnerability affected the Apache Axis 1.4 distribution that was last released in 2006. Security and bug commits commits continue in the projects Axis 1.x Subversion repository, legacy users are encouraged to build from source. The successor to Axis 1.x is Axis2, the latest version… | |
| Modificada | Media (6.1) | 11% | 💥 PoC | Apache AxisOracle Agile Engineering Data ManagementOracle Agile Product Lifecycle ManagementOracle Application Testing Suite+34 | 2/8/2018 | 17/6/2026 | Apache Axis 1.x up to and including 1.4 is vulnerable to a cross-site scripting (XSS) attack in the default servlet/services. | |
| Modificada | Alta (7.5) | 1.5% | — | Axis A1001 FirmwareAxis A8004-v FirmwareAxis A8105-e FirmwareAxis A9161 Firmware+386 | 26/6/2018 | 17/6/2026 | An issue was discovered in the httpd process in multiple models of Axis IP Cameras. There is Memory Corruption. | |
| Modificada | Alta (7.5) | 1.5% | — | Axis A1001 FirmwareAxis A8004-v FirmwareAxis A8105-e FirmwareAxis A9161 Firmware+386 | 26/6/2018 | 17/6/2026 | An issue was discovered in multiple models of Axis IP Cameras. There is an Incorrect Size Calculation. | |
| Modificada | Crítica (9.8) | 80% | 💥 Exploit | Axis A1001 FirmwareAxis A8004-v FirmwareAxis A8105-e FirmwareAxis A9161 Firmware+386 | 26/6/2018 | 17/6/2026 | An issue was discovered in multiple models of Axis IP Cameras. There is an Exposed Insecure Interface. | |
| Modificada | Crítica (9.8) | 87% | 💥 Exploit | Axis A1001 FirmwareAxis A8004-v FirmwareAxis A8105-e FirmwareAxis A9161 Firmware+386 | 26/6/2018 | 17/6/2026 | An issue was discovered in multiple models of Axis IP Cameras. There is a bypass of access control. |