Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2737▼ 486 respecto a la semana anterior
Críticas / altas1302▼ 188 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)227▼ 275 respecto a la semana anterior
–

147 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaCrítica (9.8)82%💥 ExploitAxis A1001 FirmwareAxis A8004-v FirmwareAxis A8105-e FirmwareAxis A9161 Firmware+38626/6/201817/6/2026
An issue was discovered in multiple models of Axis IP Cameras. There is Shell Command Injection.
ModificadaAlta (7.5)1.8%—Axis A1001 FirmwareAxis A8004-v FirmwareAxis A8105-e FirmwareAxis A9161 Firmware+38626/6/201817/6/2026
There was a Memory Corruption issue discovered in multiple models of Axis IP Cameras which allows remote attackers to cause a denial of service (crash) by sending a crafted command which will result in a code path that calls the UND undefined ARM instruction.
ModificadaAlta (7.5)1.5%—Axis A1001 FirmwareAxis A8004-v FirmwareAxis A8105-e FirmwareAxis A9161 Firmware+38626/6/201817/6/2026
There was a Memory Corruption issue discovered in multiple models of Axis IP Cameras which causes a denial of service (crash). The crash arises from code inside libdbus-send.so shared object or similar.
ModificadaAlta (7.5)1.2%—Axis M1033-w Firmware1/4/201817/6/2026
An issue was discovered on AXIS M1033-W (IP camera) Firmware version 5.40.5.1 devices. They don't employ a suitable mechanism to prevent a DoS attack, which leads to a response time delay. An attacker can use the hping3 tool to perform an IPv4 flood attack, and the services are interrupted from attack start to end.
ModificadaAlta (7.5)3.1%—Axis M1033-w Firmware1/4/201817/6/2026
An issue was discovered on AXIS M1033-W (IP camera) Firmware version 5.40.5.1 devices. The upload web page doesn't verify the file type, and an attacker can upload a webshell by making a fileUpload.shtml request for a custom .shtml file, which is interpreted by the Apache HTTP Server mod_include module with "<!--#exec…
ModificadaAlta (7.5)3.8%—Axis P1354 Firmware1/4/201817/6/2026
An issue was discovered on AXIS P1354 (IP camera) Firmware version 5.90.1.1 devices. The upload web page doesn't verify the file type, and an attacker can upload a webshell by making a fileUpload.shtml request for a custom .shtml file, which is interpreted by the Apache HTTP Server mod_include module with "<!--#exec…
ModificadaMedia (6.1)0.61%—Axis 2100 Network Camera Firmware25/10/201717/6/2026
Reflected XSS in the web administration portal on the Axis 2100 Network Camera 2.03 allows an attacker to execute arbitrary JavaScript via the conf_Layout_OwnTitle parameter to view/view.shtml. NOTE: this might overlap CVE-2007-5214.
ModificadaMedia (6.1)1.1%—Axis 2100 Network Camera Firmware4/8/201717/6/2026
AXIS 2100 devices 2.43 have XSS via the URI, possibly related to admin/admin.shtml.
ModificadaAlta (8.8)18%💥 ExploitAxis Network Camera Firmware2/5/201717/6/2026
The devtools.sh script in AXIS network cameras allows remote authenticated users to execute arbitrary commands via shell metacharacters in the app parameter to (1) app_license.shtml, (2) app_license_custom.shtml, (3) app_index.shtml, or (4) app_params.shtml.
ModificadaMedia (6.1)51%💥 ExploitAxis Network Camera Firmware17/4/201717/6/2026
Multiple cross-site scripting (XSS) vulnerabilities in Axis network cameras.
ModificadaAlta (7.5)8.8%💥 ExploitAxis Communications Firmware10/4/201717/6/2026
AXIS Communications products with firmware through 5.80.x allow remote attackers to modify arbitrary files as root via vectors involving Open Script Editor, aka a "resource injection vulnerability."
ModificadaAlta (8.8)2.2%💥 ExploitAxis Communications Firmware10/4/201717/6/2026
AXIS Communications products allow CSRF, as demonstrated by admin/pwdgrp.cgi, vaconfig.cgi, and admin/local_del.cgi.
ModificadaBaja (3.5)0.83%—Polycom Realpresence Cloudaxis Suite3/9/201517/6/2026
Cross-site scripting (XSS) vulnerability in Polycom RealPresence CloudAXIS Suite before 1.7.0 allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors.
ModificadaMedia (4.3)2.2%—Apache Axis2/c29/9/201416/6/2026
Apache Axis2/C does not verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltName field of the X.509 certificate, which allows man-in-the-middle attackers to spoof SSL servers via an arbitrary valid certificate.
ModificadaMedia (5.4)0.27%—Adt-taxis ADT Taxis9/9/201417/6/2026
The ADT Taxis (aka com.icabbi.adttaxisApp) application 6 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.
ModificadaMedia (5.8)9.2%—Apache Axis27/8/201417/6/2026
The getCN function in Apache Axis 1.4 and earlier does not properly verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltName field of the X.509 certificate, which allows man-in-the-middle attackers to spoof SSL servers via a certificate with a subject that specifies a…
ModificadaAlta (8.8)4.1%💥 ExploitAxis Media Control Activex Control4/10/201316/6/2026
The AXIS Media Control (AMC) ActiveX control (AxisMediaControlEmb.dll) 6.2.10.11 for AXIS network cameras allows remote attackers to create or overwrite arbitrary files via a file path to the (1) StartRecord, (2) SaveCurrentImage, or (3) StartRecordMedia methods.
ModificadaMedia (4.3)3.6%💥 ExploitAxis M10 Series Network Cameras FirmwareAxis M1054 Network Camera12/2/201316/6/2026
Cross-site scripting (XSS) vulnerability in serverreport.cgi in Axis M10 Series Network Cameras M1054 firmware 5.21 and earlier allows remote attackers to inject arbitrary web script or HTML via the pageTitle parameter to admin/showReport.shtml.
ModificadaMedia (5.8)2.2%—Apache Axis24/11/201216/6/2026
Apache Axis2/Java 1.6.2 and earlier does not verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltName field of the X.509 certificate, which allows man-in-the-middle attackers to spoof SSL servers via an arbitrary valid certificate.
ModificadaMedia (5.8)5.7%—Apache ActivemqApache AxisPaypal Mass PAYPaypal Payments PRO+14/11/201216/6/2026
Apache Axis 1.4 and earlier, as used in PayPal Payments Pro, PayPal Mass Pay, PayPal Transactional Information SOAP, the Java Message Service implementation in Apache ActiveMQ, and other products, does not verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltName field…
ModificadaMedia (6.4)5.1%—Apache Axis29/10/201216/6/2026
Apache Axis2 allows remote attackers to forge messages and bypass authentication via a SAML assertion that lacks a Signature element, aka a "Signature exclusion attack," a different vulnerability than CVE-2012-4418.
ModificadaMedia (5.8)6.0%—Apache Axis29/10/201216/6/2026
Apache Axis2 allows remote attackers to forge messages and bypass authentication via an "XML Signature wrapping attack."
ModificadaMedia (5.8)1.3%—Neoaxis WEB Player20/1/201216/6/2026
Directory traversal vulnerability in the web player in NeoAxis NeoAxis web player 1.4 and earlier allows user-assisted remote attackers to write arbitrary files via a .. (dot dot) in a filename in the neoaxis_web_application_win32.zip ZIP archive.
ModificadaAlta (10)91%💥 ExploitApache Axis2SAP Businessobjects18/10/201016/6/2026
Apache Axis2, as used in dswsbobje.war in SAP BusinessObjects Enterprise XI 3.2, CA ARCserve D2D r15, and other products, has a default password of axis2 for the admin account, which makes it easier for remote attackers to execute arbitrary code by uploading a crafted web service.
ModificadaAlta (7.5)22%—Apache Axis222/6/201016/6/2026
Apache Axis2 before 1.5.2, as used in IBM WebSphere Application Server (WAS) 7.0 through 7.0.0.12, IBM Feature Pack for Web Services 6.1.0.9 through 6.1.0.32, IBM Feature Pack for Web 2.0 1.0.1.0, Apache Synapse, Apache ODE, Apache Tuscany, Apache Geronimo, and other products, does not properly reject DTDs in SOAP…