Перейти к содержимому
Noroxi

Записи axis

102 опубликованных записей вендора axis.

Профиль для исследователя

Попали в KEV
0 · 0 %
С эксплойтом
3 · 2,9 %
Pre-auth RCE
9
С записью об исправлении
25,5 %
Медиана: публикация → KEV
Ни одна запись не попала в KEV

Все записи

102 записей
  • CVE-2018-10661
    65На этой неделе

    An issue was discovered in multiple models of Axis IP Cameras.

    КритическаяCVSS 9,8Готовый эксплойтEPSS 87 %

    axis · a1001 firmware26 июн. 2018 г.

  • CVE-2018-10660
    64На этой неделе

    An issue was discovered in multiple models of Axis IP Cameras.

    КритическаяCVSS 9,8Готовый эксплойтEPSS 82 %

    axis · a1001 firmware26 июн. 2018 г.

  • CVE-2018-10662
    63На этой неделе

    An issue was discovered in multiple models of Axis IP Cameras.

    КритическаяCVSS 9,8Готовый эксплойтEPSS 80 %

    axis · a1001 firmware26 июн. 2018 г.

  • CVE-2003-0240
    49В плане

    The web-based administration capability for various Axis Network Camera products allows remote attackers to bypass access restrictions and m

    КритическаяCVSS 10,0Proof of conceptEPSS 30 %

    axis · 2100 network camera9 июн. 2003 г.

  • CVE-2000-0191
    43В плане

    Axis StorPoint CD allows remote attackers to access administrator URLs without authentication via a ..

    КритическаяCVSS 10,0Proof of conceptEPSS 11 %

    axis · storpoint cd29 февр. 2000 г.

  • CVE-2004-2427
    42В плане

    Axis Network Camera 2.40 and earlier, and Video Server 3.12 and earlier, allows remote attackers to obtain sensitive information via direct

    КритическаяCVSS 10,0Эксплойта нетEPSS 5 %

    axis · 2100 network camera31 дек. 2004 г.

  • CVE-2007-2239
    41В плане

    Stack-based buffer overflow in the SaveBMP method in the AXIS Camera Control (aka CamImage) ActiveX control before 2.40.0.0 in AxisCamContro

    КритическаяCVSS 9,3Proof of conceptEPSS 12 %

    axis · 2100 network camera7 мая 2007 г.

  • CVE-2015-8257
    40В плане

    The devtools.sh script in AXIS network cameras allows remote authenticated users to execute arbitrary commands via shell metacharacters in t

    ВысокаяCVSS 8,8Proof of conceptEPSS 18 %

    axis · network camera firmware2 мая 2017 г.

  • CVE-2015-8256
    39Наблюдать

    Multiple cross-site scripting (XSS) vulnerabilities in Axis network cameras.

    СредняяCVSS 6,1Proof of conceptEPSS 51 %

    axis · network camera firmware17 апр. 2017 г.

  • CVE-2008-5260
    39Наблюдать

    Heap-based buffer overflow in the CamImage.CamImage.1 ActiveX control in AxisCamControl.ocx in AXIS Camera Control 2.40.0.0 allows remote at

    КритическаяCVSS 9,3Эксплойта нетEPSS 6 %

    axis · axis camera control26 янв. 2009 г.

  • CVE-2017-20049
    39Наблюдать

    A vulnerability, was found in legacy Axis devices such as P3225 and M3005.

    КритическаяCVSS 9,8Эксплойта нетEPSS 2 %

    axis · p1204 firmware15 июн. 2022 г.

  • CVE-2023-21409
    39Наблюдать

    Insufficient file permissions leak administrator-privileged credentials in AXIS License Verifier ACAP

    КритическаяCVSS 9,8Эксплойта нетEPSS 1 %

    axis · license plate verifier3 авг. 2023 г.

  • CVE-2023-21408
    39Наблюдать

    Insufficient file permissions leak user credentials of 3rd party integration interfaces in AXIS License Verifier ACAP

    КритическаяCVSS 9,8Эксплойта нетEPSS 1 %

    axis · license plate verifier3 авг. 2023 г.

  • CVE-2007-4926
    38Наблюдать

    The AXIS 207W camera uses a base64-encoded cleartext username and password for authentication, which allows remote attackers to obtain sensi

    КритическаяCVSS 9,3Эксплойта нетEPSS 3 %

    axis · 207w camera18 сент. 2007 г.

  • CVE-2007-5213
    38Наблюдать

    Multiple cross-site request forgery (CSRF) vulnerabilities in the AXIS 2100 Network Camera 2.02 with firmware 2.43 and earlier allow remote

    КритическаяCVSS 9,3Эксплойта нетEPSS 2 %

    axis · 2100 network camera4 окт. 2007 г.

  • CVE-2013-3543
    36Наблюдать

    The AXIS Media Control (AMC) ActiveX control (AxisMediaControlEmb.dll) 6.2.10.11 for AXIS network cameras allows remote attackers to create

    ВысокаяCVSS 8,8Proof of conceptEPSS 4 %

    axis · media control activex control4 окт. 2013 г.

  • CVE-2015-8255
    36Наблюдать

    AXIS Communications products allow CSRF, as demonstrated by admin/pwdgrp.cgi, vaconfig.cgi, and admin/local_del.cgi.

    ВысокаяCVSS 8,8Proof of conceptEPSS 2 %

    axis · axis communications firmware9 апр. 2017 г.

  • CVE-2025-30023
    36Наблюдать

    The communication protocol used between client and server had a flaw that could lead to an authenticated user performing a remote code execu

    КритическаяCVSS 9,0Эксплойта нетEPSS 1 %

    axis · camera station11 июл. 2025 г.

  • CVE-2021-31988
    35Наблюдать

    A user controlled parameter related to SMTP test functionality is not correctly validated making it possible to add the Carriage Return and

    ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %

    axis · axis os5 окт. 2021 г.

  • CVE-2023-21410
    35Наблюдать

    Non-sanitized user input could lead to arbitrary code execution in AXIS License Plate Verifier

    ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %

    axis · license plate verifier3 авг. 2023 г.

  • CVE-2023-21411
    35Наблюдать

    Non-sanitized user input could lead to arbitrary code execution during Access Control configuration in AXIS License Plate Verifier

    ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %

    axis · license plate verifier3 авг. 2023 г.

  • CVE-2023-5800
    35Наблюдать

    Insufficient input validation in VAPIX API create_overlay.cgi

    ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %

    axis · axis os5 февр. 2024 г.

  • CVE-2023-21407
    35Наблюдать

    Privilege escalation in AXIS License Plate Verifier ACAP

    ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %

    axis · license plate verifier3 авг. 2023 г.

  • CVE-2023-21412
    35Наблюдать

    Non-sanitized user input could lead to SQL injections in AXIS License Plate Verifier

    ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %

    axis · license plate verifier3 авг. 2023 г.

  • CVE-2023-5677
    35Наблюдать

    Brandon Rothel from QED Secure Solutions and Sam Hanson of Dragos have found that the VAPIX API tcptest.cgi did not have a sufficient input

    ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %

    axis · m3024-lve firmware5 февр. 2024 г.