AxxonSoft records
9 published records for vendor axxonsoft.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 2
- With a fix record
- 0%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-1104 Use of Unmaintained Third Party Components1
- CWE-119 Improper Restriction of Operations within the Bounds of a Memory Buffer1
- CWE-1395 Dependency on Vulnerable Third-Party Component1
- CWE-200 Exposure of Sensitive Information to an Unauthorized Actor1
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')1
- CWE-287 Improper Authentication1
The weakness classes this vendor ships most often: where to look.
CWEAll records
9 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
37Monitor | CVE-2025-10220No exploit | Outdated Third-Party NuGet Packages in AxxonSoft Axxon One VMS 2.0.0 through 2.0.4axxonsoft · axxon one · CWE-1104 | Critical9.3 | — | 0.7% | Sep 10, 2025 |
37Monitor | CVE-2025-10226No exploit | PostgreSQL Upgrade from v10 to v17.4 in AxxonSoft Axxon One (C-Werk) 2.0.8 and earlier to Address Multiple Vulnerabilitiesaxxonsoft · axxon one · CWE-1395 | Critical9.3 | — | 0.6% | Sep 10, 2025 |
34Monitor | CVE-2025-10225No exploit | Incorrect Memory Allocation in OpenSSL-Based Session Module in AxxonSoft Axxon One (C-Werk)axxonsoft · axxon one · CWE-119 | High8.7 | — | 0.4% | Sep 10, 2025 |
33Monitor | CVE-2018-7467Proof of concept | AxxonSoft Axxon Next has Directory Traversal via an initial /css//..%2f substring in a URI.axxonsoft · next · CWE-22 | High7.5 | — | 10.2% | Feb 27, 2018 |
26Monitor | CVE-2025-10221No exploit | Hardcoded Password Exposure in AxxonNet (C-WerkNet) ARP Agent Logsaxxonsoft · axxon one · CWE-532 | Medium6.7 | — | 0.1% | Sep 10, 2025 |
21Monitor | CVE-2025-10224No exploit | Incorrect Evaluation of LDAP Nested Groups during Login in AxxonSoft Axxon One (C-Werk)axxonsoft · axxon one · CWE-287 | Medium5.3 | — | 0.3% | Sep 10, 2025 |
21Monitor | CVE-2025-10223No exploit | Improper Session Cleanup on Role Removal in Web Admin Panel in AxxonSoft Axxon One (C-Werk)axxonsoft · axxon one · CWE-613 | Medium5.3 | — | 0.3% | Sep 10, 2025 |
20Monitor | CVE-2025-10227No exploit | Lack of Encryption in Object Archive in AxxonSoft Axxon One (C-Werk) before 2.0.8axxonsoft · axxon one · CWE-311 | Medium5.1 | — | 0.1% | Sep 10, 2025 |
19Monitor | CVE-2025-10222No exploit | Sensitive Information Disclosure in Diagnostic Dumps in AxxonSoft Axxon One VMSaxxonsoft · axxon one · CWE-200 | Medium4.8 | — | 0.1% | Sep 10, 2025 |
- CVE-2025-1022037Monitor
Outdated Third-Party NuGet Packages in AxxonSoft Axxon One VMS 2.0.0 through 2.0.4
CriticalCVSS 9.3No exploitEPSS 1%axxonsoft · axxon oneSep 10, 2025
- CVE-2025-1022637Monitor
PostgreSQL Upgrade from v10 to v17.4 in AxxonSoft Axxon One (C-Werk) 2.0.8 and earlier to Address Multiple Vulnerabilities
CriticalCVSS 9.3No exploitEPSS 1%axxonsoft · axxon oneSep 10, 2025
- CVE-2025-1022534Monitor
Incorrect Memory Allocation in OpenSSL-Based Session Module in AxxonSoft Axxon One (C-Werk)
HighCVSS 8.7No exploitEPSS 0%axxonsoft · axxon oneSep 10, 2025
- CVE-2018-746733Monitor
AxxonSoft Axxon Next has Directory Traversal via an initial /css//..%2f substring in a URI.
HighCVSS 7.5Proof of conceptEPSS 10%axxonsoft · nextFeb 27, 2018
- CVE-2025-1022126Monitor
Hardcoded Password Exposure in AxxonNet (C-WerkNet) ARP Agent Logs
MediumCVSS 6.7No exploitEPSS 0%axxonsoft · axxon oneSep 10, 2025
- CVE-2025-1022421Monitor
Incorrect Evaluation of LDAP Nested Groups during Login in AxxonSoft Axxon One (C-Werk)
MediumCVSS 5.3No exploitEPSS 0%axxonsoft · axxon oneSep 10, 2025
- CVE-2025-1022321Monitor
Improper Session Cleanup on Role Removal in Web Admin Panel in AxxonSoft Axxon One (C-Werk)
MediumCVSS 5.3No exploitEPSS 0%axxonsoft · axxon oneSep 10, 2025
- CVE-2025-1022720Monitor
Lack of Encryption in Object Archive in AxxonSoft Axxon One (C-Werk) before 2.0.8
MediumCVSS 5.1No exploitEPSS 0%axxonsoft · axxon oneSep 10, 2025
- CVE-2025-1022219Monitor
Sensitive Information Disclosure in Diagnostic Dumps in AxxonSoft Axxon One VMS
MediumCVSS 4.8No exploitEPSS 0%axxonsoft · axxon oneSep 10, 2025