Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2737▼ 484 respecto a la semana anterior
Críticas / altas1302▼ 187 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)227▼ 275 respecto a la semana anterior
147 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (4.3) | 35% | 💥 Exploit | Apache Axis2 | 27/5/2010 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in axis2-admin/axis2-admin/engagingglobally in the administration console in Apache Axis2/Java 1.4.1, 1.5.1, and possibly other versions, as used in SAP Business Objects 12, 3com IMC, and possibly other products, allows remote attackers to inject arbitrary web script or HTML… | |
| Modificada | Alta (9.3) | 5.8% | — | Axis Camera Control | 26/1/2009 | 16/6/2026 | Heap-based buffer overflow in the CamImage.CamImage.1 ActiveX control in AxisCamControl.ocx in AXIS Camera Control 2.40.0.0 allows remote attackers to execute arbitrary code via a long image_pan_tilt property value. | |
| Modificada | Media (4.3) | 3.0% | 💥 Exploit | Maxiscript Website Directory | 9/10/2008 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in index.php in MaxiScript Website Directory allows remote attackers to inject arbitrary web script or HTML via the keyword parameter in a search action. | |
| Modificada | Media (4.3) | 2.4% | — | Axis 2100 Network Camera | 4/10/2007 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in the AXIS 2100 Network Camera 2.02 with firmware 2.43 and earlier allow remote attackers to inject arbitrary web script or HTML via (1) the PATH_INFO to the default URI associated with a directory, as demonstrated by (a) the root directory and (b) the view/… | |
| Modificada | Media (4.3) | 1.9% | — | Axis 2100 Network CameraAxis 2100 Network Camera Firmware | 4/10/2007 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in the AXIS 2100 Network Camera 2.02 with firmware before 2.43 allow remote attackers to inject arbitrary web script or HTML via (1) parameters associated with saved settings, as demonstrated by the conf_SMTP_MailServer1 parameter to ServerManager.srv; or (2) the… | |
| Modificada | Alta (9.3) | 1.7% | — | Axis 2100 Network CameraAxis 2100 Network Camera Firmware | 4/10/2007 | 16/6/2026 | Multiple cross-site request forgery (CSRF) vulnerabilities in the AXIS 2100 Network Camera 2.02 with firmware 2.43 and earlier allow remote attackers to perform actions as administrators, as demonstrated by (1) an SMTP server change through the conf_SMTP_MailServer1 parameter to ServerManager.srv and (2) a hostname… | |
| Modificada | Alta (9.3) | 3.1% | — | Axis 207w Camera | 18/9/2007 | 16/6/2026 | The AXIS 207W camera uses a base64-encoded cleartext username and password for authentication, which allows remote attackers to obtain sensitive information by sniffing the wireless network or by leveraging unspecified other vectors. | |
| Modificada | Baja (3.5) | 1.8% | — | Axis 207w Network Camera | 18/9/2007 | 16/6/2026 | axis-cgi/buffer/command.cgi on the AXIS 207W camera allows remote authenticated users to cause a denial of service (reboot) via many requests with unique buffer names in the buffername parameter in a start action. | |
| Modificada | Media (4.9) | 0.35% | — | Axis 207w Network Camera | 18/9/2007 | 16/6/2026 | The AXIS 207W camera stores a WEP or WPA key in cleartext in the configuration file, which might allow local users to obtain sensitive information. | |
| Modificada | Media (4.3) | 2.0% | — | Axis 207w Network Camera | 18/9/2007 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in the AXIS 207W camera allow remote attackers to inject arbitrary web script or HTML via the camNo parameter to incl/image_incl.shtml, and other unspecified vectors. | |
| Modificada | Media (4.3) | 2.2% | 💥 Exploit | Axis 207w Network Camera | 18/9/2007 | 16/6/2026 | Multiple cross-site request forgery (CSRF) vulnerabilities in the AXIS 207W camera allow remote attackers to perform certain actions as administrators via (1) axis-cgi/admin/restart.cgi, (2) the user and sgrp parameters to axis-cgi/admin/pwdgrp.cgi in an add action, or (3) the server parameter to… | |
| Modificada | Alta (9.3) | 12% | 💥 Exploit | Axis 2100 Network CameraAxis 2110 Network CameraAxis 2120 Network CameraAxis 2130 PTZ Network Camera+6 | 7/5/2007 | 16/6/2026 | Stack-based buffer overflow in the SaveBMP method in the AXIS Camera Control (aka CamImage) ActiveX control before 2.40.0.0 in AxisCamControl.ocx in AXIS 2100, 2110, 2120, 2130 PTZ, 2420, 2420-IR, 2400, 2400+, 2401, 2401+, 2411, and Panorama PTZ allows remote attackers to cause a denial of service (Internet Explorer… | |
| Modificada | Media (5) | 28% | 💥 Exploit | Apache Axis | 30/4/2007 | 16/6/2026 | Apache Axis 1.0 allows remote attackers to obtain sensitive information by requesting a non-existent WSDL file, which reveals the installation path in the resulting exception message. | |
| Modificada | Media (5) | 4.2% | — | Axis 2100 Network CameraAxis 2110 Network CameraAxis 2120 Network CameraAxis 2130 PTZ Network Camera+10 | 31/12/2004 | 16/6/2026 | Directory traversal vulnerability in Axis Network Camera 2.40 and earlier, and Video Server 3.12 and earlier, allows remote attackers to bypass authentication via a .. (dot dot) in an HTTP POST request to ServerManager.srv, then use these privileges to conduct other activities, such as modifying files using… | |
| Modificada | Media (5) | 2.8% | 💥 PoC | DelegateDnrdDON Moore MydnsMaradns+11 | 31/12/2004 | 16/6/2026 | Multiple implementations of the DNS protocol, including (1) Poslib 1.0.2-1 and earlier as used by Posadis, (2) Axis Network products before firmware 3.13, and (3) Men & Mice Suite 2.2x before 2.2.3 and 3.5.x before 3.5.2, allow remote attackers to cause a denial of service (CPU and network bandwidth consumption) by… | |
| Modificada | Alta (7.5) | 14% | 💥 Exploit | Axis 2100 Network CameraAxis 2110 Network CameraAxis 2120 Network CameraAxis 2130 PTZ Network Camera+10 | 31/12/2004 | 16/6/2026 | Axis Network Camera 2.40 and earlier, and Video Server 3.12 and earlier, allows remote attackers to execute arbitrary commands via accent (`) and possibly other shell metacharacters in the query string to virtualinput.cgi. | |
| Modificada | Alta (10) | 5.4% | — | Axis 2100 Network CameraAxis 2110 Network CameraAxis 2120 Network CameraAxis 2130 PTZ Network Camera+10 | 31/12/2004 | 16/6/2026 | Axis Network Camera 2.40 and earlier, and Video Server 3.12 and earlier, allows remote attackers to obtain sensitive information via direct requests to (1) admin/getparam.cgi, (2) admin/systemlog.cgi, (3) admin/serverreport.cgi, and (4) admin/paramlist.cgi, modify system information via (5) setparam.cgi and (6)… | |
| Modificada | Media (6.4) | 7.7% | 💥 Exploit | Axis 2400 Video ServerAxis 2401 Video Server | 31/12/2003 | 16/6/2026 | AXIS 2400 Video Server 2.00 through 2.33 allows remote attackers to obtain sensitive information via an HTTP request to /support/messages, which displays the server's /var/log/messages file. | |
| Modificada | Alta (10) | 30% | 💥 Exploit | Axis 2100 Network CameraAxis 2110 Network CameraAxis 2120 Network CameraAxis 2130 PTZ Network Camera+5 | 9/6/2003 | 16/6/2026 | The web-based administration capability for various Axis Network Camera products allows remote attackers to bypass access restrictions and modify configuration via an HTTP request to the admin/admin.shtml containing a leading // (double slash). | |
| Modificada | Alta (7.5) | 2.4% | — | Axis 2100 Network CameraAxis 2110 Network CameraAxis 2120 Network CameraAxis Neteye 200+1 | 31/12/2001 | 16/6/2026 | Axis network camera 2120, 2110, 2100, 200+ and 200 contains a default administration password "pass", which allows remote attackers to gain access to the camera. | |
| Modificada | Alta (10) | 11% | 💥 Exploit | Axis Storpoint CD | 29/2/2000 | 16/6/2026 | Axis StorPoint CD allows remote attackers to access administrator URLs without authentication via a .. (dot dot) attack. | |
| Modificada | Alta (7.5) | 1.6% | — | Axis 700 Network Document Server | 7/2/2000 | 16/6/2026 | Axis 700 Network Scanner does not properly restrict access to administrator URLs, which allows users to bypass the password protection via a .. (dot dot) attack. |