Записи axis
102 опубликованных записей вендора axis.
Профиль для исследователя
- Попали в KEV
- 0 · 0 %
- С эксплойтом
- 3 · 2,9 %
- Pre-auth RCE
- 9
- С записью об исправлении
- 25,5 %
- Медиана: публикация → KEV
- Ни одна запись не попала в KEV
Повторяющиеся классы
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')8
- CWE-35 Path Traversal: '.../...//'7
- CWE-78 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')6
- CWE-1287 Improper Validation of Specified Type of Input5
- CWE-732 Incorrect Permission Assignment for Critical Resource5
- CWE-1286 Improper Validation of Syntactic Correctness of Input4
Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.
CWEВсе записи
102 записей| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
65На этой неделе | CVE-2018-10661Готовый эксплойт | An issue was discovered in multiple models of Axis IP Cameras.axis · a1001 firmware | Критическая9,8 | — | 86,5 % | 26 июн. 2018 г. |
64На этой неделе | CVE-2018-10660Готовый эксплойт | An issue was discovered in multiple models of Axis IP Cameras.axis · a1001 firmware · CWE-78 | Критическая9,8 | — | 82,1 % | 26 июн. 2018 г. |
63На этой неделе | CVE-2018-10662Готовый эксплойт | An issue was discovered in multiple models of Axis IP Cameras.axis · a1001 firmware | Критическая9,8 | — | 79,5 % | 26 июн. 2018 г. |
49В плане | CVE-2003-0240Proof of concept | The web-based administration capability for various Axis Network Camera products allows remote attackers to bypass access restrictions and maxis · 2100 network camera | Критическая10,0 | — | 29,5 % | 9 июн. 2003 г. |
43В плане | CVE-2000-0191Proof of concept | Axis StorPoint CD allows remote attackers to access administrator URLs without authentication via a ..axis · storpoint cd | Критическая10,0 | — | 10,9 % | 29 февр. 2000 г. |
42В плане | CVE-2004-2427Эксплойта нет | Axis Network Camera 2.40 and earlier, and Video Server 3.12 and earlier, allows remote attackers to obtain sensitive information via direct axis · 2100 network camera | Критическая10,0 | — | 5,4 % | 31 дек. 2004 г. |
41В плане | CVE-2007-2239Proof of concept | Stack-based buffer overflow in the SaveBMP method in the AXIS Camera Control (aka CamImage) ActiveX control before 2.40.0.0 in AxisCamControaxis · 2100 network camera | Критическая9,3 | — | 11,8 % | 7 мая 2007 г. |
40В плане | CVE-2015-8257Proof of concept | The devtools.sh script in AXIS network cameras allows remote authenticated users to execute arbitrary commands via shell metacharacters in taxis · network camera firmware · CWE-77 | Высокая8,8 | — | 17,7 % | 2 мая 2017 г. |
39Наблюдать | CVE-2015-8256Proof of concept | Multiple cross-site scripting (XSS) vulnerabilities in Axis network cameras.axis · network camera firmware · CWE-79 | Средняя6,1 | — | 50,8 % | 17 апр. 2017 г. |
39Наблюдать | CVE-2008-5260Эксплойта нет | Heap-based buffer overflow in the CamImage.CamImage.1 ActiveX control in AxisCamControl.ocx in AXIS Camera Control 2.40.0.0 allows remote ataxis · axis camera control · CWE-119 | Критическая9,3 | — | 5,8 % | 26 янв. 2009 г. |
39Наблюдать | CVE-2017-20049Эксплойта нет | A vulnerability, was found in legacy Axis devices such as P3225 and M3005.axis · p1204 firmware · CWE-269 | Критическая9,8 | — | 1,6 % | 15 июн. 2022 г. |
39Наблюдать | CVE-2023-21409Эксплойта нет | Insufficient file permissions leak administrator-privileged credentials in AXIS License Verifier ACAPaxis · license plate verifier · CWE-755 | Критическая9,8 | — | 0,6 % | 3 авг. 2023 г. |
39Наблюдать | CVE-2023-21408Эксплойта нет | Insufficient file permissions leak user credentials of 3rd party integration interfaces in AXIS License Verifier ACAPaxis · license plate verifier · CWE-755 | Критическая9,8 | — | 0,6 % | 3 авг. 2023 г. |
38Наблюдать | CVE-2007-4926Эксплойта нет | The AXIS 207W camera uses a base64-encoded cleartext username and password for authentication, which allows remote attackers to obtain sensiaxis · 207w camera · CWE-310 | Критическая9,3 | — | 3,1 % | 18 сент. 2007 г. |
38Наблюдать | CVE-2007-5213Эксплойта нет | Multiple cross-site request forgery (CSRF) vulnerabilities in the AXIS 2100 Network Camera 2.02 with firmware 2.43 and earlier allow remote axis · 2100 network camera · CWE-352 | Критическая9,3 | — | 1,7 % | 4 окт. 2007 г. |
36Наблюдать | CVE-2013-3543Proof of concept | The AXIS Media Control (AMC) ActiveX control (AxisMediaControlEmb.dll) 6.2.10.11 for AXIS network cameras allows remote attackers to create axis · media control activex control · CWE-264 | Высокая8,8 | — | 4,1 % | 4 окт. 2013 г. |
36Наблюдать | CVE-2015-8255Proof of concept | AXIS Communications products allow CSRF, as demonstrated by admin/pwdgrp.cgi, vaconfig.cgi, and admin/local_del.cgi.axis · axis communications firmware · CWE-352 | Высокая8,8 | — | 2,2 % | 9 апр. 2017 г. |
36Наблюдать | CVE-2025-30023Эксплойта нет | The communication protocol used between client and server had a flaw that could lead to an authenticated user performing a remote code execuaxis · camera station · CWE-502 | Критическая9,0 | — | 0,6 % | 11 июл. 2025 г. |
35Наблюдать | CVE-2021-31988Эксплойта нет | A user controlled parameter related to SMTP test functionality is not correctly validated making it possible to add the Carriage Return and axis · axis os · CWE-1286 | Высокая8,8 | — | 1,0 % | 5 окт. 2021 г. |
35Наблюдать | CVE-2023-21410Эксплойта нет | Non-sanitized user input could lead to arbitrary code execution in AXIS License Plate Verifieraxis · license plate verifier · CWE-78 | Высокая8,8 | — | 0,8 % | 3 авг. 2023 г. |
35Наблюдать | CVE-2023-21411Эксплойта нет | Non-sanitized user input could lead to arbitrary code execution during Access Control configuration in AXIS License Plate Verifieraxis · license plate verifier · CWE-78 | Высокая8,8 | — | 0,8 % | 3 авг. 2023 г. |
35Наблюдать | CVE-2023-5800Эксплойта нет | Insufficient input validation in VAPIX API create_overlay.cgiaxis · axis os · CWE-35 | Высокая8,8 | — | 0,7 % | 5 февр. 2024 г. |
35Наблюдать | CVE-2023-21407Эксплойта нет | Privilege escalation in AXIS License Plate Verifier ACAPaxis · license plate verifier | Высокая8,8 | — | 0,7 % | 3 авг. 2023 г. |
35Наблюдать | CVE-2023-21412Эксплойта нет | Non-sanitized user input could lead to SQL injections in AXIS License Plate Verifieraxis · license plate verifier · CWE-89 | Высокая8,8 | — | 0,6 % | 3 авг. 2023 г. |
35Наблюдать | CVE-2023-5677Эксплойта нет | Brandon Rothel from QED Secure Solutions and Sam Hanson of Dragos have found that the VAPIX API tcptest.cgi did not have a sufficient input axis · m3024-lve firmware · CWE-78 | Высокая8,8 | — | 0,6 % | 5 февр. 2024 г. |
- CVE-2018-1066165На этой неделе
An issue was discovered in multiple models of Axis IP Cameras.
КритическаяCVSS 9,8Готовый эксплойтEPSS 87 %axis · a1001 firmware26 июн. 2018 г.
- CVE-2018-1066064На этой неделе
An issue was discovered in multiple models of Axis IP Cameras.
КритическаяCVSS 9,8Готовый эксплойтEPSS 82 %axis · a1001 firmware26 июн. 2018 г.
- CVE-2018-1066263На этой неделе
An issue was discovered in multiple models of Axis IP Cameras.
КритическаяCVSS 9,8Готовый эксплойтEPSS 80 %axis · a1001 firmware26 июн. 2018 г.
- CVE-2003-024049В плане
The web-based administration capability for various Axis Network Camera products allows remote attackers to bypass access restrictions and m
КритическаяCVSS 10,0Proof of conceptEPSS 30 %axis · 2100 network camera9 июн. 2003 г.
- CVE-2000-019143В плане
Axis StorPoint CD allows remote attackers to access administrator URLs without authentication via a ..
КритическаяCVSS 10,0Proof of conceptEPSS 11 %axis · storpoint cd29 февр. 2000 г.
- CVE-2004-242742В плане
Axis Network Camera 2.40 and earlier, and Video Server 3.12 and earlier, allows remote attackers to obtain sensitive information via direct
КритическаяCVSS 10,0Эксплойта нетEPSS 5 %axis · 2100 network camera31 дек. 2004 г.
- CVE-2007-223941В плане
Stack-based buffer overflow in the SaveBMP method in the AXIS Camera Control (aka CamImage) ActiveX control before 2.40.0.0 in AxisCamContro
КритическаяCVSS 9,3Proof of conceptEPSS 12 %axis · 2100 network camera7 мая 2007 г.
- CVE-2015-825740В плане
The devtools.sh script in AXIS network cameras allows remote authenticated users to execute arbitrary commands via shell metacharacters in t
ВысокаяCVSS 8,8Proof of conceptEPSS 18 %axis · network camera firmware2 мая 2017 г.
- CVE-2015-825639Наблюдать
Multiple cross-site scripting (XSS) vulnerabilities in Axis network cameras.
СредняяCVSS 6,1Proof of conceptEPSS 51 %axis · network camera firmware17 апр. 2017 г.
- CVE-2008-526039Наблюдать
Heap-based buffer overflow in the CamImage.CamImage.1 ActiveX control in AxisCamControl.ocx in AXIS Camera Control 2.40.0.0 allows remote at
КритическаяCVSS 9,3Эксплойта нетEPSS 6 %axis · axis camera control26 янв. 2009 г.
- CVE-2017-2004939Наблюдать
A vulnerability, was found in legacy Axis devices such as P3225 and M3005.
КритическаяCVSS 9,8Эксплойта нетEPSS 2 %axis · p1204 firmware15 июн. 2022 г.
- CVE-2023-2140939Наблюдать
Insufficient file permissions leak administrator-privileged credentials in AXIS License Verifier ACAP
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %axis · license plate verifier3 авг. 2023 г.
- CVE-2023-2140839Наблюдать
Insufficient file permissions leak user credentials of 3rd party integration interfaces in AXIS License Verifier ACAP
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %axis · license plate verifier3 авг. 2023 г.
- CVE-2007-492638Наблюдать
The AXIS 207W camera uses a base64-encoded cleartext username and password for authentication, which allows remote attackers to obtain sensi
КритическаяCVSS 9,3Эксплойта нетEPSS 3 %axis · 207w camera18 сент. 2007 г.
- CVE-2007-521338Наблюдать
Multiple cross-site request forgery (CSRF) vulnerabilities in the AXIS 2100 Network Camera 2.02 with firmware 2.43 and earlier allow remote
КритическаяCVSS 9,3Эксплойта нетEPSS 2 %axis · 2100 network camera4 окт. 2007 г.
- CVE-2013-354336Наблюдать
The AXIS Media Control (AMC) ActiveX control (AxisMediaControlEmb.dll) 6.2.10.11 for AXIS network cameras allows remote attackers to create
ВысокаяCVSS 8,8Proof of conceptEPSS 4 %axis · media control activex control4 окт. 2013 г.
- CVE-2015-825536Наблюдать
AXIS Communications products allow CSRF, as demonstrated by admin/pwdgrp.cgi, vaconfig.cgi, and admin/local_del.cgi.
ВысокаяCVSS 8,8Proof of conceptEPSS 2 %axis · axis communications firmware9 апр. 2017 г.
- CVE-2025-3002336Наблюдать
The communication protocol used between client and server had a flaw that could lead to an authenticated user performing a remote code execu
КритическаяCVSS 9,0Эксплойта нетEPSS 1 %axis · camera station11 июл. 2025 г.
- CVE-2021-3198835Наблюдать
A user controlled parameter related to SMTP test functionality is not correctly validated making it possible to add the Carriage Return and
ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %axis · axis os5 окт. 2021 г.
- CVE-2023-2141035Наблюдать
Non-sanitized user input could lead to arbitrary code execution in AXIS License Plate Verifier
ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %axis · license plate verifier3 авг. 2023 г.
- CVE-2023-2141135Наблюдать
Non-sanitized user input could lead to arbitrary code execution during Access Control configuration in AXIS License Plate Verifier
ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %axis · license plate verifier3 авг. 2023 г.
- CVE-2023-580035Наблюдать
Insufficient input validation in VAPIX API create_overlay.cgi
ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %axis · axis os5 февр. 2024 г.
- CVE-2023-2140735Наблюдать
Privilege escalation in AXIS License Plate Verifier ACAP
ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %axis · license plate verifier3 авг. 2023 г.
- CVE-2023-2141235Наблюдать
Non-sanitized user input could lead to SQL injections in AXIS License Plate Verifier
ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %axis · license plate verifier3 авг. 2023 г.
- CVE-2023-567735Наблюдать
Brandon Rothel from QED Secure Solutions and Sam Hanson of Dragos have found that the VAPIX API tcptest.cgi did not have a sufficient input
ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %axis · m3024-lve firmware5 февр. 2024 г.