Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2721▲ 17 respecto a la semana anterior
Críticas / altas1459▲ 351 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)72▼ 458 respecto a la semana anterior
147 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Pendiente de análisis | Media (6.8) | 0.17% | — | Araxis MergeAI | 24/9/2026 | 26/9/2026 | Araxis Merge for Windows version 2011.4074 through 2026.0 stores user-configured credentials for remote servers in the Windows registry and does not apply sufficient cryptographic protection. An authenticated, non-administrative attacker could retrieve and unencrypt all credentials the target user has stored in Merge. | |
| Pendiente de análisis | Media (5.3) | 0.29% | — | Axis Signed Video FrameworkAI | 11/8/2026 | 3/9/2026 | The Signed Video Framework contained a buffer overflow issue which could lead the application using this framework to crash. The issue exclusively affects the tools used for the validation of signed content. The AXIS OS device's signed video functionality remains unaffected. | |
| Pendiente de análisis | Media (5.1) | 0.09% | — | Axis AcapAI | 11/8/2026 | 3/9/2026 | The ACAP framework contains a Time-of-Check to Time-of-Use (TOCTOU) race condition, which could potentially lead to privilege escalation. This vulnerability can only be exploited if the Axis device is configured to allow the installation of unsigned ACAP applications, and if an attacker convinces the victim to install… | |
| Pendiente de análisis | Media (5.7) | 0.31% | — | Axis AcapAI | 11/8/2026 | 3/9/2026 | An ACAP configuration file lacks input validation, which could potentially lead to privilege escalation. This vulnerability can only be exploited if the Axis device is configured to allow the installation of unsigned ACAP applications, and if an attacker convinces the victim to install a malicious ACAP application. | |
| Pendiente de análisis | Media (5.7) | 0.23% | — | Axis AcapAI | 11/8/2026 | 3/9/2026 | The ACAP framework contains a Time-of-Check to Time-of-Use (TOCTOU) race condition, which could potentially lead to privilege escalation. This vulnerability can only be exploited if the Axis device is configured to allow the installation of unsigned ACAP applications, and if an attacker convinces the victim to install… | |
| Pendiente de análisis | Alta (7.2) | 0.57% | — | Axis Vapix APIAI | 11/8/2026 | 3/9/2026 | A VAPIX API parameter had improper input validation which could allow code execution and potentially lead to a privilege escalation. This flaw can only be exploited after authenticating with an administrator-privileged service account. | |
| Analizada | Crítica (9.8) | 1.7% | — | Apache Axis2/java | 28/7/2026 | 5/8/2026 | Deserialization of Untrusted Data (CWE-502) in the Tribes-based clustering component in Apache Software Foundation Apache Axis2/Java through 2.0.0 on Apache Tomcat (only when Tribes clustering is enabled, which is off by default) allows an unauthenticated remote attacker with network access to the clustering port to… | |
| Analizada | Alta (8.8) | 0.23% | — | Axis OS | 12/5/2026 | 17/6/2026 | A configuration file on the local file system had improper input validation which could allow code execution and potentially lead to privilege escalation. This vulnerability can only be exploited if an attacker can log in to the Axis device using SSH. | |
| Analizada | Alta (7.3) | 0.13% | — | Axis OS | 12/5/2026 | 17/6/2026 | An ACAP configuration file lacked sufficient input validation, which could allow a path traversal attack leading to potential privilege escalation. This vulnerability can only be exploited if the Axis device is configured to allow the installation of unsigned ACAP applications, and if an attacker convinces the victim… | |
| Analizada | Alta (7.3) | 0.40% | — | Axis OS | 12/5/2026 | 17/6/2026 | An ACAP configuration file lacked sufficient input validation, which could allow command injection and potentially lead to privilege escalation. This vulnerability can only be exploited if the Axis device is configured to allow the installation of unsigned ACAP applications, and if an attacker convinces the victim to… | |
| Analizada | Alta (7.3) | 0.10% | — | Axis OS | 12/5/2026 | 17/6/2026 | ACAP applications can gain elevated privileges due to improper input validation during the installation process, potentially leading to privilege escalation. This vulnerability can only be exploited if the Axis device is configured to allow the installation of unsigned ACAP applications, and if an attacker convinces… | |
| Aplazada | Crítica (9.3) | 1.1% | — | Apache Axis2AISangoma FilestoreAI | 24/4/2026 | 17/6/2026 | BridgeHead FileStore versions prior to 24A (released in early 2024) expose the Apache Axis2 administration module on network-accessible endpoints with default credentials that allows unauthenticated remote attackers to execute arbitrary OS commands. Attackers can authenticate to the admin console using default… | |
| Analizada | Media (5.7) | 0.18% | — | Axis Camera Station PRO | 10/2/2026 | 17/6/2026 | An insecure direct object reference allowed a non-admin user to modify or remove certain data objects without having the appropriate permissions. | |
| Analizada | Media (4.5) | 0.23% | — | Axis Camera Station PRO | 10/2/2026 | 17/6/2026 | A server-side injection was possible for a malicious admin to manipulate the application to include a malicious script which is executed by the server. This attack is only possible if the admin uses a client that have been tampered with. | |
| Analizada | Media (4.6) | 0.26% | — | Axis Camera Station PRO | 10/2/2026 | 17/6/2026 | An AXIS Camera Station Pro feature can be exploited in a way that allows a non-admin user to view information they are not permitted to. | |
| Analizada | Alta (7.8) | 0.16% | — | Axis Camera Station PRO | 10/2/2026 | 17/6/2026 | AXIS Camera Station Pro contained a flaw to perform a privilege escalation attack on the server as a non-admin user. | |
| Analizada | Alta (8.8) | 0.53% | — | Axis OS | 10/2/2026 | 17/6/2026 | The VAPIX API mediaclip.cgi that did not have a sufficient input validation allowing for a possible remote code execution. This flaw can only be exploited after authenticating with an operator- or administrator- privileged service account. | |
| Aplazada | Alta (8.4) | 0.65% | — | Parallaxis Cuckoo ClockAI | 7/2/2026 | 17/6/2026 | Parallaxis Cuckoo Clock 5.0 contains a buffer overflow vulnerability that allows attackers to execute arbitrary code by overwriting memory registers in the alarm scheduling feature. Attackers can craft a malicious payload exceeding 260 bytes to overwrite EIP and EBP, enabling shellcode execution with potential remote… | |
| Analizada | Crítica (9.8) | 0.50% | — | Netaxis API Orchestrator | 17/12/2025 | 17/6/2026 | Netaxis API Orchestrator (APIO) before 0.19.3 allows server side template injection (SSTI). | |
| Analizada | Media (5.3) | 0.24% | — | Compassplustechnologies Tranzaxis | 4/12/2025 | 17/6/2026 | TranzAxis 3.2.41.10.26 allows authenticated users to inject cross-site scripting via the `Open Object in Tree` endpoint, allowing attackers to steal session cookies and potentially escalate privileges. | |
| Aplazada | Media (4.3) | 0.25% | — | Axis Vapix APIAI | 11/11/2025 | 17/6/2026 | The VAPIX API port.cgi did not have sufficient input validation, which may result in process crashes and impact usability. This vulnerability can only be exploited after authenticating with a viewer- operator- or administrator-privileged service account. | |
| Aplazada | Media (6.4) | 0.11% | — | Axis Vapix Edge Storage APIAI | 11/11/2025 | 17/6/2026 | The VAPIX Edge storage API that allowed a privilege escalation, enabling a VAPIX administrator-privileged user to gain Linux Root privileges. This flaw can only be exploited after authenticating with an administrator-privileged service account. | |
| Aplazada | Alta (8.4) | 0.12% | — | Axis OptimizerAIMicrosoft WindowsAI | 11/11/2025 | 17/6/2026 | AXIS Optimizer was vulnerable to an unquoted search path vulnerability, which could potentially lead to privilege escalation within Microsoft Windows operating system. This vulnerability can only be exploited if the attacker has access to the local Windows machine and sufficient access rights (administrator) to write… | |
| Analizada | Media (6.7) | 0.13% | — | Axis OS | 11/11/2025 | 17/6/2026 | An ACAP configuration file has improper permissions and lacks input validation, which could potentially lead to privilege escalation. This vulnerability can only be exploited if the Axis device is configured to allow the installation of unsigned ACAP applications, and if an attacker convinces the victim to install a… | |
| Analizada | Media (6.7) | 1.1% | — | Axis OS | 11/11/2025 | 17/6/2026 | An ACAP configuration file has improper permissions, which could allow command injection and potentially lead to privilege escalation. This vulnerability can only be exploited if the Axis device is configured to allow the installation of unsigned ACAP applications, and if an attacker convinces the victim to install a… |