Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2737▼ 486 respecto a la semana anterior
Críticas / altas1302▼ 188 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)227▼ 275 respecto a la semana anterior
147 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Crítica (9.8) | 82% | 💥 Exploit | Axis A1001 FirmwareAxis A8004-v FirmwareAxis A8105-e FirmwareAxis A9161 Firmware+386 | 26/6/2018 | 17/6/2026 | An issue was discovered in multiple models of Axis IP Cameras. There is Shell Command Injection. | |
| Modificada | Alta (7.5) | 1.8% | — | Axis A1001 FirmwareAxis A8004-v FirmwareAxis A8105-e FirmwareAxis A9161 Firmware+386 | 26/6/2018 | 17/6/2026 | There was a Memory Corruption issue discovered in multiple models of Axis IP Cameras which allows remote attackers to cause a denial of service (crash) by sending a crafted command which will result in a code path that calls the UND undefined ARM instruction. | |
| Modificada | Alta (7.5) | 1.5% | — | Axis A1001 FirmwareAxis A8004-v FirmwareAxis A8105-e FirmwareAxis A9161 Firmware+386 | 26/6/2018 | 17/6/2026 | There was a Memory Corruption issue discovered in multiple models of Axis IP Cameras which causes a denial of service (crash). The crash arises from code inside libdbus-send.so shared object or similar. | |
| Modificada | Alta (7.5) | 1.2% | — | Axis M1033-w Firmware | 1/4/2018 | 17/6/2026 | An issue was discovered on AXIS M1033-W (IP camera) Firmware version 5.40.5.1 devices. They don't employ a suitable mechanism to prevent a DoS attack, which leads to a response time delay. An attacker can use the hping3 tool to perform an IPv4 flood attack, and the services are interrupted from attack start to end. | |
| Modificada | Alta (7.5) | 3.1% | — | Axis M1033-w Firmware | 1/4/2018 | 17/6/2026 | An issue was discovered on AXIS M1033-W (IP camera) Firmware version 5.40.5.1 devices. The upload web page doesn't verify the file type, and an attacker can upload a webshell by making a fileUpload.shtml request for a custom .shtml file, which is interpreted by the Apache HTTP Server mod_include module with "<!--#exec… | |
| Modificada | Alta (7.5) | 3.8% | — | Axis P1354 Firmware | 1/4/2018 | 17/6/2026 | An issue was discovered on AXIS P1354 (IP camera) Firmware version 5.90.1.1 devices. The upload web page doesn't verify the file type, and an attacker can upload a webshell by making a fileUpload.shtml request for a custom .shtml file, which is interpreted by the Apache HTTP Server mod_include module with "<!--#exec… | |
| Modificada | Media (6.1) | 0.61% | — | Axis 2100 Network Camera Firmware | 25/10/2017 | 17/6/2026 | Reflected XSS in the web administration portal on the Axis 2100 Network Camera 2.03 allows an attacker to execute arbitrary JavaScript via the conf_Layout_OwnTitle parameter to view/view.shtml. NOTE: this might overlap CVE-2007-5214. | |
| Modificada | Media (6.1) | 1.1% | — | Axis 2100 Network Camera Firmware | 4/8/2017 | 17/6/2026 | AXIS 2100 devices 2.43 have XSS via the URI, possibly related to admin/admin.shtml. | |
| Modificada | Alta (8.8) | 18% | 💥 Exploit | Axis Network Camera Firmware | 2/5/2017 | 17/6/2026 | The devtools.sh script in AXIS network cameras allows remote authenticated users to execute arbitrary commands via shell metacharacters in the app parameter to (1) app_license.shtml, (2) app_license_custom.shtml, (3) app_index.shtml, or (4) app_params.shtml. | |
| Modificada | Media (6.1) | 51% | 💥 Exploit | Axis Network Camera Firmware | 17/4/2017 | 17/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in Axis network cameras. | |
| Modificada | Alta (7.5) | 8.8% | 💥 Exploit | Axis Communications Firmware | 10/4/2017 | 17/6/2026 | AXIS Communications products with firmware through 5.80.x allow remote attackers to modify arbitrary files as root via vectors involving Open Script Editor, aka a "resource injection vulnerability." | |
| Modificada | Alta (8.8) | 2.2% | 💥 Exploit | Axis Communications Firmware | 10/4/2017 | 17/6/2026 | AXIS Communications products allow CSRF, as demonstrated by admin/pwdgrp.cgi, vaconfig.cgi, and admin/local_del.cgi. | |
| Modificada | Baja (3.5) | 0.83% | — | Polycom Realpresence Cloudaxis Suite | 3/9/2015 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in Polycom RealPresence CloudAXIS Suite before 1.7.0 allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors. | |
| Modificada | Media (4.3) | 2.2% | — | Apache Axis2/c | 29/9/2014 | 16/6/2026 | Apache Axis2/C does not verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltName field of the X.509 certificate, which allows man-in-the-middle attackers to spoof SSL servers via an arbitrary valid certificate. | |
| Modificada | Media (5.4) | 0.27% | — | Adt-taxis ADT Taxis | 9/9/2014 | 17/6/2026 | The ADT Taxis (aka com.icabbi.adttaxisApp) application 6 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate. | |
| Modificada | Media (5.8) | 9.2% | — | Apache Axis | 27/8/2014 | 17/6/2026 | The getCN function in Apache Axis 1.4 and earlier does not properly verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltName field of the X.509 certificate, which allows man-in-the-middle attackers to spoof SSL servers via a certificate with a subject that specifies a… | |
| Modificada | Alta (8.8) | 4.1% | 💥 Exploit | Axis Media Control Activex Control | 4/10/2013 | 16/6/2026 | The AXIS Media Control (AMC) ActiveX control (AxisMediaControlEmb.dll) 6.2.10.11 for AXIS network cameras allows remote attackers to create or overwrite arbitrary files via a file path to the (1) StartRecord, (2) SaveCurrentImage, or (3) StartRecordMedia methods. | |
| Modificada | Media (4.3) | 3.6% | 💥 Exploit | Axis M10 Series Network Cameras FirmwareAxis M1054 Network Camera | 12/2/2013 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in serverreport.cgi in Axis M10 Series Network Cameras M1054 firmware 5.21 and earlier allows remote attackers to inject arbitrary web script or HTML via the pageTitle parameter to admin/showReport.shtml. | |
| Modificada | Media (5.8) | 2.2% | — | Apache Axis2 | 4/11/2012 | 16/6/2026 | Apache Axis2/Java 1.6.2 and earlier does not verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltName field of the X.509 certificate, which allows man-in-the-middle attackers to spoof SSL servers via an arbitrary valid certificate. | |
| Modificada | Media (5.8) | 5.7% | — | Apache ActivemqApache AxisPaypal Mass PAYPaypal Payments PRO+1 | 4/11/2012 | 16/6/2026 | Apache Axis 1.4 and earlier, as used in PayPal Payments Pro, PayPal Mass Pay, PayPal Transactional Information SOAP, the Java Message Service implementation in Apache ActiveMQ, and other products, does not verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltName field… | |
| Modificada | Media (6.4) | 5.1% | — | Apache Axis2 | 9/10/2012 | 16/6/2026 | Apache Axis2 allows remote attackers to forge messages and bypass authentication via a SAML assertion that lacks a Signature element, aka a "Signature exclusion attack," a different vulnerability than CVE-2012-4418. | |
| Modificada | Media (5.8) | 6.0% | — | Apache Axis2 | 9/10/2012 | 16/6/2026 | Apache Axis2 allows remote attackers to forge messages and bypass authentication via an "XML Signature wrapping attack." | |
| Modificada | Media (5.8) | 1.3% | — | Neoaxis WEB Player | 20/1/2012 | 16/6/2026 | Directory traversal vulnerability in the web player in NeoAxis NeoAxis web player 1.4 and earlier allows user-assisted remote attackers to write arbitrary files via a .. (dot dot) in a filename in the neoaxis_web_application_win32.zip ZIP archive. | |
| Modificada | Alta (10) | 91% | 💥 Exploit | Apache Axis2SAP Businessobjects | 18/10/2010 | 16/6/2026 | Apache Axis2, as used in dswsbobje.war in SAP BusinessObjects Enterprise XI 3.2, CA ARCserve D2D r15, and other products, has a default password of axis2 for the admin account, which makes it easier for remote attackers to execute arbitrary code by uploading a crafted web service. | |
| Modificada | Alta (7.5) | 22% | — | Apache Axis2 | 22/6/2010 | 16/6/2026 | Apache Axis2 before 1.5.2, as used in IBM WebSphere Application Server (WAS) 7.0 through 7.0.0.12, IBM Feature Pack for Web Services 6.1.0.9 through 6.1.0.32, IBM Feature Pack for Web 2.0 1.0.1.0, Apache Synapse, Apache ODE, Apache Tuscany, Apache Geronimo, and other products, does not properly reject DTDs in SOAP… |