Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2737▼ 484 respecto a la semana anterior
Críticas / altas1302▼ 187 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)227▼ 275 respecto a la semana anterior
–

147 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (4.3)35%💥 ExploitApache Axis227/5/201016/6/2026
Cross-site scripting (XSS) vulnerability in axis2-admin/axis2-admin/engagingglobally in the administration console in Apache Axis2/Java 1.4.1, 1.5.1, and possibly other versions, as used in SAP Business Objects 12, 3com IMC, and possibly other products, allows remote attackers to inject arbitrary web script or HTML…
ModificadaAlta (9.3)5.8%—Axis Camera Control26/1/200916/6/2026
Heap-based buffer overflow in the CamImage.CamImage.1 ActiveX control in AxisCamControl.ocx in AXIS Camera Control 2.40.0.0 allows remote attackers to execute arbitrary code via a long image_pan_tilt property value.
ModificadaMedia (4.3)3.0%💥 ExploitMaxiscript Website Directory9/10/200816/6/2026
Cross-site scripting (XSS) vulnerability in index.php in MaxiScript Website Directory allows remote attackers to inject arbitrary web script or HTML via the keyword parameter in a search action.
ModificadaMedia (4.3)2.4%—Axis 2100 Network Camera4/10/200716/6/2026
Multiple cross-site scripting (XSS) vulnerabilities in the AXIS 2100 Network Camera 2.02 with firmware 2.43 and earlier allow remote attackers to inject arbitrary web script or HTML via (1) the PATH_INFO to the default URI associated with a directory, as demonstrated by (a) the root directory and (b) the view/…
ModificadaMedia (4.3)1.9%—Axis 2100 Network CameraAxis 2100 Network Camera Firmware4/10/200716/6/2026
Multiple cross-site scripting (XSS) vulnerabilities in the AXIS 2100 Network Camera 2.02 with firmware before 2.43 allow remote attackers to inject arbitrary web script or HTML via (1) parameters associated with saved settings, as demonstrated by the conf_SMTP_MailServer1 parameter to ServerManager.srv; or (2) the…
ModificadaAlta (9.3)1.7%—Axis 2100 Network CameraAxis 2100 Network Camera Firmware4/10/200716/6/2026
Multiple cross-site request forgery (CSRF) vulnerabilities in the AXIS 2100 Network Camera 2.02 with firmware 2.43 and earlier allow remote attackers to perform actions as administrators, as demonstrated by (1) an SMTP server change through the conf_SMTP_MailServer1 parameter to ServerManager.srv and (2) a hostname…
ModificadaAlta (9.3)3.1%—Axis 207w Camera18/9/200716/6/2026
The AXIS 207W camera uses a base64-encoded cleartext username and password for authentication, which allows remote attackers to obtain sensitive information by sniffing the wireless network or by leveraging unspecified other vectors.
ModificadaBaja (3.5)1.8%—Axis 207w Network Camera18/9/200716/6/2026
axis-cgi/buffer/command.cgi on the AXIS 207W camera allows remote authenticated users to cause a denial of service (reboot) via many requests with unique buffer names in the buffername parameter in a start action.
ModificadaMedia (4.9)0.35%—Axis 207w Network Camera18/9/200716/6/2026
The AXIS 207W camera stores a WEP or WPA key in cleartext in the configuration file, which might allow local users to obtain sensitive information.
ModificadaMedia (4.3)2.0%—Axis 207w Network Camera18/9/200716/6/2026
Multiple cross-site scripting (XSS) vulnerabilities in the AXIS 207W camera allow remote attackers to inject arbitrary web script or HTML via the camNo parameter to incl/image_incl.shtml, and other unspecified vectors.
ModificadaMedia (4.3)2.2%💥 ExploitAxis 207w Network Camera18/9/200716/6/2026
Multiple cross-site request forgery (CSRF) vulnerabilities in the AXIS 207W camera allow remote attackers to perform certain actions as administrators via (1) axis-cgi/admin/restart.cgi, (2) the user and sgrp parameters to axis-cgi/admin/pwdgrp.cgi in an add action, or (3) the server parameter to…
ModificadaAlta (9.3)12%💥 ExploitAxis 2100 Network CameraAxis 2110 Network CameraAxis 2120 Network CameraAxis 2130 PTZ Network Camera+67/5/200716/6/2026
Stack-based buffer overflow in the SaveBMP method in the AXIS Camera Control (aka CamImage) ActiveX control before 2.40.0.0 in AxisCamControl.ocx in AXIS 2100, 2110, 2120, 2130 PTZ, 2420, 2420-IR, 2400, 2400+, 2401, 2401+, 2411, and Panorama PTZ allows remote attackers to cause a denial of service (Internet Explorer…
ModificadaMedia (5)28%💥 ExploitApache Axis30/4/200716/6/2026
Apache Axis 1.0 allows remote attackers to obtain sensitive information by requesting a non-existent WSDL file, which reveals the installation path in the resulting exception message.
ModificadaMedia (5)4.2%—Axis 2100 Network CameraAxis 2110 Network CameraAxis 2120 Network CameraAxis 2130 PTZ Network Camera+1031/12/200416/6/2026
Directory traversal vulnerability in Axis Network Camera 2.40 and earlier, and Video Server 3.12 and earlier, allows remote attackers to bypass authentication via a .. (dot dot) in an HTTP POST request to ServerManager.srv, then use these privileges to conduct other activities, such as modifying files using…
ModificadaMedia (5)2.8%💥 PoCDelegateDnrdDON Moore MydnsMaradns+1131/12/200416/6/2026
Multiple implementations of the DNS protocol, including (1) Poslib 1.0.2-1 and earlier as used by Posadis, (2) Axis Network products before firmware 3.13, and (3) Men & Mice Suite 2.2x before 2.2.3 and 3.5.x before 3.5.2, allow remote attackers to cause a denial of service (CPU and network bandwidth consumption) by…
ModificadaAlta (7.5)14%💥 ExploitAxis 2100 Network CameraAxis 2110 Network CameraAxis 2120 Network CameraAxis 2130 PTZ Network Camera+1031/12/200416/6/2026
Axis Network Camera 2.40 and earlier, and Video Server 3.12 and earlier, allows remote attackers to execute arbitrary commands via accent (`) and possibly other shell metacharacters in the query string to virtualinput.cgi.
ModificadaAlta (10)5.4%—Axis 2100 Network CameraAxis 2110 Network CameraAxis 2120 Network CameraAxis 2130 PTZ Network Camera+1031/12/200416/6/2026
Axis Network Camera 2.40 and earlier, and Video Server 3.12 and earlier, allows remote attackers to obtain sensitive information via direct requests to (1) admin/getparam.cgi, (2) admin/systemlog.cgi, (3) admin/serverreport.cgi, and (4) admin/paramlist.cgi, modify system information via (5) setparam.cgi and (6)…
ModificadaMedia (6.4)7.7%💥 ExploitAxis 2400 Video ServerAxis 2401 Video Server31/12/200316/6/2026
AXIS 2400 Video Server 2.00 through 2.33 allows remote attackers to obtain sensitive information via an HTTP request to /support/messages, which displays the server's /var/log/messages file.
ModificadaAlta (10)30%💥 ExploitAxis 2100 Network CameraAxis 2110 Network CameraAxis 2120 Network CameraAxis 2130 PTZ Network Camera+59/6/200316/6/2026
The web-based administration capability for various Axis Network Camera products allows remote attackers to bypass access restrictions and modify configuration via an HTTP request to the admin/admin.shtml containing a leading // (double slash).
ModificadaAlta (7.5)2.4%—Axis 2100 Network CameraAxis 2110 Network CameraAxis 2120 Network CameraAxis Neteye 200+131/12/200116/6/2026
Axis network camera 2120, 2110, 2100, 200+ and 200 contains a default administration password "pass", which allows remote attackers to gain access to the camera.
ModificadaAlta (10)11%💥 ExploitAxis Storpoint CD29/2/200016/6/2026
Axis StorPoint CD allows remote attackers to access administrator URLs without authentication via a .. (dot dot) attack.
ModificadaAlta (7.5)1.6%—Axis 700 Network Document Server7/2/200016/6/2026
Axis 700 Network Scanner does not properly restrict access to administrator URLs, which allows users to bypass the password protection via a .. (dot dot) attack.