Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2721▲ 17 respecto a la semana anterior
Críticas / altas1459▲ 351 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)72▼ 458 respecto a la semana anterior
–

147 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
Pendiente de análisisMedia (6.8)0.17%—Araxis MergeAI24/9/202626/9/2026
Araxis Merge for Windows version 2011.4074 through 2026.0 stores user-configured credentials for remote servers in the Windows registry and does not apply sufficient cryptographic protection. An authenticated, non-administrative attacker could retrieve and unencrypt all credentials the target user has stored in Merge.
Pendiente de análisisMedia (5.3)0.29%—Axis Signed Video FrameworkAI11/8/20263/9/2026
The Signed Video Framework contained a buffer overflow issue which could lead the application using this framework to crash. The issue exclusively affects the tools used for the validation of signed content. The AXIS OS device's signed video functionality remains unaffected.
Pendiente de análisisMedia (5.1)0.09%—Axis AcapAI11/8/20263/9/2026
The ACAP framework contains a Time-of-Check to Time-of-Use (TOCTOU) race condition, which could potentially lead to privilege escalation. This vulnerability can only be exploited if the Axis device is configured to allow the installation of unsigned ACAP applications, and if an attacker convinces the victim to install…
Pendiente de análisisMedia (5.7)0.31%—Axis AcapAI11/8/20263/9/2026
An ACAP configuration file lacks input validation, which could potentially lead to privilege escalation. This vulnerability can only be exploited if the Axis device is configured to allow the installation of unsigned ACAP applications, and if an attacker convinces the victim to install a malicious ACAP application.
Pendiente de análisisMedia (5.7)0.23%—Axis AcapAI11/8/20263/9/2026
The ACAP framework contains a Time-of-Check to Time-of-Use (TOCTOU) race condition, which could potentially lead to privilege escalation. This vulnerability can only be exploited if the Axis device is configured to allow the installation of unsigned ACAP applications, and if an attacker convinces the victim to install…
Pendiente de análisisAlta (7.2)0.57%—Axis Vapix APIAI11/8/20263/9/2026
A VAPIX API parameter had improper input validation which could allow code execution and potentially lead to a privilege escalation. This flaw can only be exploited after authenticating with an administrator-privileged service account.
AnalizadaCrítica (9.8)1.7%—Apache Axis2/java28/7/20265/8/2026
Deserialization of Untrusted Data (CWE-502) in the Tribes-based clustering component in Apache Software Foundation Apache Axis2/Java through 2.0.0 on Apache Tomcat (only when Tribes clustering is enabled, which is off by default) allows an unauthenticated remote attacker with network access to the clustering port to…
AnalizadaAlta (8.8)0.23%—Axis OS12/5/202617/6/2026
A configuration file on the local file system had improper input validation which could allow code execution and potentially lead to privilege escalation. This vulnerability can only be exploited if an attacker can log in to the Axis device using SSH.
AnalizadaAlta (7.3)0.13%—Axis OS12/5/202617/6/2026
An ACAP configuration file lacked sufficient input validation, which could allow a path traversal attack leading to potential privilege escalation. This vulnerability can only be exploited if the Axis device is configured to allow the installation of unsigned ACAP applications, and if an attacker convinces the victim…
AnalizadaAlta (7.3)0.40%—Axis OS12/5/202617/6/2026
An ACAP configuration file lacked sufficient input validation, which could allow command injection and potentially lead to privilege escalation. This vulnerability can only be exploited if the Axis device is configured to allow the installation of unsigned ACAP applications, and if an attacker convinces the victim to…
AnalizadaAlta (7.3)0.10%—Axis OS12/5/202617/6/2026
ACAP applications can gain elevated privileges due to improper input validation during the installation process, potentially leading to privilege escalation. This vulnerability can only be exploited if the Axis device is configured to allow the installation of unsigned ACAP applications, and if an attacker convinces…
AplazadaCrítica (9.3)1.1%—Apache Axis2AISangoma FilestoreAI24/4/202617/6/2026
BridgeHead FileStore versions prior to 24A (released in early 2024) expose the Apache Axis2 administration module on network-accessible endpoints with default credentials that allows unauthenticated remote attackers to execute arbitrary OS commands. Attackers can authenticate to the admin console using default…
AnalizadaMedia (5.7)0.18%—Axis Camera Station PRO10/2/202617/6/2026
An insecure direct object reference allowed a non-admin user to modify or remove certain data objects without having the appropriate permissions.
AnalizadaMedia (4.5)0.23%—Axis Camera Station PRO10/2/202617/6/2026
A server-side injection was possible for a malicious admin to manipulate the application to include a malicious script which is executed by the server. This attack is only possible if the admin uses a client that have been tampered with.
AnalizadaMedia (4.6)0.26%—Axis Camera Station PRO10/2/202617/6/2026
An AXIS Camera Station Pro feature can be exploited in a way that allows a non-admin user to view information they are not permitted to.
AnalizadaAlta (7.8)0.16%—Axis Camera Station PRO10/2/202617/6/2026
AXIS Camera Station Pro contained a flaw to perform a privilege escalation attack on the server as a non-admin user.
AnalizadaAlta (8.8)0.53%—Axis OS10/2/202617/6/2026
The VAPIX API mediaclip.cgi that did not have a sufficient input validation allowing for a possible remote code execution. This flaw can only be exploited after authenticating with an operator- or administrator- privileged service account.
AplazadaAlta (8.4)0.65%—Parallaxis Cuckoo ClockAI7/2/202617/6/2026
Parallaxis Cuckoo Clock 5.0 contains a buffer overflow vulnerability that allows attackers to execute arbitrary code by overwriting memory registers in the alarm scheduling feature. Attackers can craft a malicious payload exceeding 260 bytes to overwrite EIP and EBP, enabling shellcode execution with potential remote…
AnalizadaCrítica (9.8)0.50%—Netaxis API Orchestrator17/12/202517/6/2026
Netaxis API Orchestrator (APIO) before 0.19.3 allows server side template injection (SSTI).
AnalizadaMedia (5.3)0.24%—Compassplustechnologies Tranzaxis4/12/202517/6/2026
TranzAxis 3.2.41.10.26 allows authenticated users to inject cross-site scripting via the `Open Object in Tree` endpoint, allowing attackers to steal session cookies and potentially escalate privileges.
AplazadaMedia (4.3)0.25%—Axis Vapix APIAI11/11/202517/6/2026
The VAPIX API port.cgi did not have sufficient input validation, which may result in process crashes and impact usability. This vulnerability can only be exploited after authenticating with a viewer- operator- or administrator-privileged service account.
AplazadaMedia (6.4)0.11%—Axis Vapix Edge Storage APIAI11/11/202517/6/2026
The VAPIX Edge storage API that allowed a privilege escalation, enabling a VAPIX administrator-privileged user to gain Linux Root privileges. This flaw can only be exploited after authenticating with an administrator-privileged service account.
AplazadaAlta (8.4)0.12%—Axis OptimizerAIMicrosoft WindowsAI11/11/202517/6/2026
AXIS Optimizer was vulnerable to an unquoted search path vulnerability, which could potentially lead to privilege escalation within Microsoft Windows operating system. This vulnerability can only be exploited if the attacker has access to the local Windows machine and sufficient access rights (administrator) to write…
AnalizadaMedia (6.7)0.13%—Axis OS11/11/202517/6/2026
An ACAP configuration file has improper permissions and lacks input validation, which could potentially lead to privilege escalation. This vulnerability can only be exploited if the Axis device is configured to allow the installation of unsigned ACAP applications, and if an attacker convinces the victim to install a…
AnalizadaMedia (6.7)1.1%—Axis OS11/11/202517/6/2026
An ACAP configuration file has improper permissions, which could allow command injection and potentially lead to privilege escalation. This vulnerability can only be exploited if the Axis device is configured to allow the installation of unsigned ACAP applications, and if an attacker convinces the victim to install a…