axis kayıtları
axis üreticisine ait 102 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 0 · %0
- Silahlaştırılmış
- 3 · %2,9
- Pre-auth RCE
- 9
- Düzeltme kaydı olan
- %25,5
- Yayından KEV’e ortanca
- KEV’e giren kayıt yok
Tekrar eden sınıflar
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')8
- CWE-35 Path Traversal: '.../...//'7
- CWE-78 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')6
- CWE-1287 Improper Validation of Specified Type of Input5
- CWE-732 Incorrect Permission Assignment for Critical Resource5
- CWE-1286 Improper Validation of Syntactic Correctness of Input4
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWETüm kayıtlar
102 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
65Bu hafta | CVE-2018-10661Silahlaştırılmış | An issue was discovered in multiple models of Axis IP Cameras.axis · a1001 firmware | Kritik9,8 | — | %86,5 | 26 Haz 2018 |
64Bu hafta | CVE-2018-10660Silahlaştırılmış | An issue was discovered in multiple models of Axis IP Cameras.axis · a1001 firmware · CWE-78 | Kritik9,8 | — | %82,1 | 26 Haz 2018 |
63Bu hafta | CVE-2018-10662Silahlaştırılmış | An issue was discovered in multiple models of Axis IP Cameras.axis · a1001 firmware | Kritik9,8 | — | %79,5 | 26 Haz 2018 |
49Planlayın | CVE-2003-0240Kavram kanıtı | The web-based administration capability for various Axis Network Camera products allows remote attackers to bypass access restrictions and maxis · 2100 network camera | Kritik10,0 | — | %29,5 | 9 Haz 2003 |
43Planlayın | CVE-2000-0191Kavram kanıtı | Axis StorPoint CD allows remote attackers to access administrator URLs without authentication via a ..axis · storpoint cd | Kritik10,0 | — | %10,9 | 29 Şub 2000 |
42Planlayın | CVE-2004-2427İstismar yok | Axis Network Camera 2.40 and earlier, and Video Server 3.12 and earlier, allows remote attackers to obtain sensitive information via direct axis · 2100 network camera | Kritik10,0 | — | %5,4 | 31 Ara 2004 |
41Planlayın | CVE-2007-2239Kavram kanıtı | Stack-based buffer overflow in the SaveBMP method in the AXIS Camera Control (aka CamImage) ActiveX control before 2.40.0.0 in AxisCamControaxis · 2100 network camera | Kritik9,3 | — | %11,8 | 7 May 2007 |
40Planlayın | CVE-2015-8257Kavram kanıtı | The devtools.sh script in AXIS network cameras allows remote authenticated users to execute arbitrary commands via shell metacharacters in taxis · network camera firmware · CWE-77 | Yüksek8,8 | — | %17,7 | 2 May 2017 |
39İzleyin | CVE-2015-8256Kavram kanıtı | Multiple cross-site scripting (XSS) vulnerabilities in Axis network cameras.axis · network camera firmware · CWE-79 | Orta6,1 | — | %50,8 | 17 Nis 2017 |
39İzleyin | CVE-2008-5260İstismar yok | Heap-based buffer overflow in the CamImage.CamImage.1 ActiveX control in AxisCamControl.ocx in AXIS Camera Control 2.40.0.0 allows remote ataxis · axis camera control · CWE-119 | Kritik9,3 | — | %5,8 | 26 Oca 2009 |
39İzleyin | CVE-2017-20049İstismar yok | A vulnerability, was found in legacy Axis devices such as P3225 and M3005.axis · p1204 firmware · CWE-269 | Kritik9,8 | — | %1,6 | 15 Haz 2022 |
39İzleyin | CVE-2023-21409İstismar yok | Insufficient file permissions leak administrator-privileged credentials in AXIS License Verifier ACAPaxis · license plate verifier · CWE-755 | Kritik9,8 | — | %0,6 | 3 Ağu 2023 |
39İzleyin | CVE-2023-21408İstismar yok | Insufficient file permissions leak user credentials of 3rd party integration interfaces in AXIS License Verifier ACAPaxis · license plate verifier · CWE-755 | Kritik9,8 | — | %0,6 | 3 Ağu 2023 |
38İzleyin | CVE-2007-4926İstismar yok | The AXIS 207W camera uses a base64-encoded cleartext username and password for authentication, which allows remote attackers to obtain sensiaxis · 207w camera · CWE-310 | Kritik9,3 | — | %3,1 | 18 Eyl 2007 |
38İzleyin | CVE-2007-5213İstismar yok | Multiple cross-site request forgery (CSRF) vulnerabilities in the AXIS 2100 Network Camera 2.02 with firmware 2.43 and earlier allow remote axis · 2100 network camera · CWE-352 | Kritik9,3 | — | %1,7 | 4 Eki 2007 |
36İzleyin | CVE-2013-3543Kavram kanıtı | The AXIS Media Control (AMC) ActiveX control (AxisMediaControlEmb.dll) 6.2.10.11 for AXIS network cameras allows remote attackers to create axis · media control activex control · CWE-264 | Yüksek8,8 | — | %4,1 | 4 Eki 2013 |
36İzleyin | CVE-2015-8255Kavram kanıtı | AXIS Communications products allow CSRF, as demonstrated by admin/pwdgrp.cgi, vaconfig.cgi, and admin/local_del.cgi.axis · axis communications firmware · CWE-352 | Yüksek8,8 | — | %2,2 | 9 Nis 2017 |
36İzleyin | CVE-2025-30023İstismar yok | The communication protocol used between client and server had a flaw that could lead to an authenticated user performing a remote code execuaxis · camera station · CWE-502 | Kritik9,0 | — | %0,6 | 11 Tem 2025 |
35İzleyin | CVE-2021-31988İstismar yok | A user controlled parameter related to SMTP test functionality is not correctly validated making it possible to add the Carriage Return and axis · axis os · CWE-1286 | Yüksek8,8 | — | %1,0 | 5 Eki 2021 |
35İzleyin | CVE-2023-21410İstismar yok | Non-sanitized user input could lead to arbitrary code execution in AXIS License Plate Verifieraxis · license plate verifier · CWE-78 | Yüksek8,8 | — | %0,8 | 3 Ağu 2023 |
35İzleyin | CVE-2023-21411İstismar yok | Non-sanitized user input could lead to arbitrary code execution during Access Control configuration in AXIS License Plate Verifieraxis · license plate verifier · CWE-78 | Yüksek8,8 | — | %0,8 | 3 Ağu 2023 |
35İzleyin | CVE-2023-5800İstismar yok | Insufficient input validation in VAPIX API create_overlay.cgiaxis · axis os · CWE-35 | Yüksek8,8 | — | %0,7 | 5 Şub 2024 |
35İzleyin | CVE-2023-21407İstismar yok | Privilege escalation in AXIS License Plate Verifier ACAPaxis · license plate verifier | Yüksek8,8 | — | %0,7 | 3 Ağu 2023 |
35İzleyin | CVE-2023-21412İstismar yok | Non-sanitized user input could lead to SQL injections in AXIS License Plate Verifieraxis · license plate verifier · CWE-89 | Yüksek8,8 | — | %0,6 | 3 Ağu 2023 |
35İzleyin | CVE-2023-5677İstismar yok | Brandon Rothel from QED Secure Solutions and Sam Hanson of Dragos have found that the VAPIX API tcptest.cgi did not have a sufficient input axis · m3024-lve firmware · CWE-78 | Yüksek8,8 | — | %0,6 | 5 Şub 2024 |
- CVE-2018-1066165Bu hafta
An issue was discovered in multiple models of Axis IP Cameras.
KritikCVSS 9,8SilahlaştırılmışEPSS %87axis · a1001 firmware26 Haz 2018
- CVE-2018-1066064Bu hafta
An issue was discovered in multiple models of Axis IP Cameras.
KritikCVSS 9,8SilahlaştırılmışEPSS %82axis · a1001 firmware26 Haz 2018
- CVE-2018-1066263Bu hafta
An issue was discovered in multiple models of Axis IP Cameras.
KritikCVSS 9,8SilahlaştırılmışEPSS %80axis · a1001 firmware26 Haz 2018
- CVE-2003-024049Planlayın
The web-based administration capability for various Axis Network Camera products allows remote attackers to bypass access restrictions and m
KritikCVSS 10,0Kavram kanıtıEPSS %30axis · 2100 network camera9 Haz 2003
- CVE-2000-019143Planlayın
Axis StorPoint CD allows remote attackers to access administrator URLs without authentication via a ..
KritikCVSS 10,0Kavram kanıtıEPSS %11axis · storpoint cd29 Şub 2000
- CVE-2004-242742Planlayın
Axis Network Camera 2.40 and earlier, and Video Server 3.12 and earlier, allows remote attackers to obtain sensitive information via direct
KritikCVSS 10,0İstismar yokEPSS %5axis · 2100 network camera31 Ara 2004
- CVE-2007-223941Planlayın
Stack-based buffer overflow in the SaveBMP method in the AXIS Camera Control (aka CamImage) ActiveX control before 2.40.0.0 in AxisCamContro
KritikCVSS 9,3Kavram kanıtıEPSS %12axis · 2100 network camera7 May 2007
- CVE-2015-825740Planlayın
The devtools.sh script in AXIS network cameras allows remote authenticated users to execute arbitrary commands via shell metacharacters in t
YüksekCVSS 8,8Kavram kanıtıEPSS %18axis · network camera firmware2 May 2017
- CVE-2015-825639İzleyin
Multiple cross-site scripting (XSS) vulnerabilities in Axis network cameras.
OrtaCVSS 6,1Kavram kanıtıEPSS %51axis · network camera firmware17 Nis 2017
- CVE-2008-526039İzleyin
Heap-based buffer overflow in the CamImage.CamImage.1 ActiveX control in AxisCamControl.ocx in AXIS Camera Control 2.40.0.0 allows remote at
KritikCVSS 9,3İstismar yokEPSS %6axis · axis camera control26 Oca 2009
- CVE-2017-2004939İzleyin
A vulnerability, was found in legacy Axis devices such as P3225 and M3005.
KritikCVSS 9,8İstismar yokEPSS %2axis · p1204 firmware15 Haz 2022
- CVE-2023-2140939İzleyin
Insufficient file permissions leak administrator-privileged credentials in AXIS License Verifier ACAP
KritikCVSS 9,8İstismar yokEPSS %1axis · license plate verifier3 Ağu 2023
- CVE-2023-2140839İzleyin
Insufficient file permissions leak user credentials of 3rd party integration interfaces in AXIS License Verifier ACAP
KritikCVSS 9,8İstismar yokEPSS %1axis · license plate verifier3 Ağu 2023
- CVE-2007-492638İzleyin
The AXIS 207W camera uses a base64-encoded cleartext username and password for authentication, which allows remote attackers to obtain sensi
KritikCVSS 9,3İstismar yokEPSS %3axis · 207w camera18 Eyl 2007
- CVE-2007-521338İzleyin
Multiple cross-site request forgery (CSRF) vulnerabilities in the AXIS 2100 Network Camera 2.02 with firmware 2.43 and earlier allow remote
KritikCVSS 9,3İstismar yokEPSS %2axis · 2100 network camera4 Eki 2007
- CVE-2013-354336İzleyin
The AXIS Media Control (AMC) ActiveX control (AxisMediaControlEmb.dll) 6.2.10.11 for AXIS network cameras allows remote attackers to create
YüksekCVSS 8,8Kavram kanıtıEPSS %4axis · media control activex control4 Eki 2013
- CVE-2015-825536İzleyin
AXIS Communications products allow CSRF, as demonstrated by admin/pwdgrp.cgi, vaconfig.cgi, and admin/local_del.cgi.
YüksekCVSS 8,8Kavram kanıtıEPSS %2axis · axis communications firmware9 Nis 2017
- CVE-2025-3002336İzleyin
The communication protocol used between client and server had a flaw that could lead to an authenticated user performing a remote code execu
KritikCVSS 9,0İstismar yokEPSS %1axis · camera station11 Tem 2025
- CVE-2021-3198835İzleyin
A user controlled parameter related to SMTP test functionality is not correctly validated making it possible to add the Carriage Return and
YüksekCVSS 8,8İstismar yokEPSS %1axis · axis os5 Eki 2021
- CVE-2023-2141035İzleyin
Non-sanitized user input could lead to arbitrary code execution in AXIS License Plate Verifier
YüksekCVSS 8,8İstismar yokEPSS %1axis · license plate verifier3 Ağu 2023
- CVE-2023-2141135İzleyin
Non-sanitized user input could lead to arbitrary code execution during Access Control configuration in AXIS License Plate Verifier
YüksekCVSS 8,8İstismar yokEPSS %1axis · license plate verifier3 Ağu 2023
- CVE-2023-580035İzleyin
Insufficient input validation in VAPIX API create_overlay.cgi
YüksekCVSS 8,8İstismar yokEPSS %1axis · axis os5 Şub 2024
- CVE-2023-2140735İzleyin
Privilege escalation in AXIS License Plate Verifier ACAP
YüksekCVSS 8,8İstismar yokEPSS %1axis · license plate verifier3 Ağu 2023
- CVE-2023-2141235İzleyin
Non-sanitized user input could lead to SQL injections in AXIS License Plate Verifier
YüksekCVSS 8,8İstismar yokEPSS %1axis · license plate verifier3 Ağu 2023
- CVE-2023-567735İzleyin
Brandon Rothel from QED Secure Solutions and Sam Hanson of Dragos have found that the VAPIX API tcptest.cgi did not have a sufficient input
YüksekCVSS 8,8İstismar yokEPSS %1axis · m3024-lve firmware5 Şub 2024