Axis
axis
98 CVEs • 1,082 products
Products (1,082)
Click to collapseToggle
Products (1,082)
Click to collapse
CVEs (98)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Axis 3Axis Os Axis Os 2020Axis Os 2022Jun 17, 2026 Nov 21, 2023 N/A· v4 7.1 HIGH· v3 N/A· v2 Sandro Poppi, member of the AXIS OS Bug Bounty Program, has found that the VAPIX API manageoverlayimage.cgi was vulnerable to path traversal attacks that allows for file/folder deletion. This flaw can only be exploited...Show more |
Sandro Poppi, member of the AXIS OS Bug Bounty Program, has found that the VAPIX API dynamicoverlay.cgi was vulnerable to a Denial-of-Service attack allowing for an attacker to block access to the overlay configuration p...Show more |
1Axis 5Axis Os Axis Os 2016Axis Os 2018+2 moreJun 17, 2026 Oct 16, 2023 N/A· v4 8.1 HIGH· v3 N/A· v2 Sandro Poppi, member of the AXIS OS Bug Bounty Program, has found that the VAPIX API overlay_del.cgi is vulnerable to path traversal attacks that allows for file deletion. This flaw can only be exploited after authentica...Show more |
NCC Group has found a flaw during the annual internal penetration test ordered by Axis Communications. The protection for device tampering (commonly known as Secure Boot) contains a flaw which provides an opportunity for...Show more |
GoSecure on behalf of Genetec Inc. has found a flaw that allows for a remote code execution during the installation of ACAP applications on the Axis device. The application handling service in AXIS OS was vulnerable to c...Show more |
User provided input is not sanitized on the AXIS License Plate Verifier specific “search.cgi” allowing for
SQL injections. |
User provided input is not sanitized in the “Settings > Access Control” configuration interface allowing for
arbitrary code execution. |
User provided input is not sanitized on the AXIS License Plate Verifier specific “api.cgi” allowing for
arbitrary code execution. |
Due to insufficient file permissions, unprivileged users could gain access to unencrypted administrator
credentials allowing the configuration of the application.
|
Due to insufficient file permissions, unprivileged users could gain access to unencrypted user credentials
that are used in the integration interface towards 3rd party systems.
|
A broken access control was found allowing for privileged escalation of the operator account to gain
administrator privileges. |
Ariel Harush and Roy Hodir from OTORIO have found a flaw in the AXIS A1001 when communicating over OSDP. A heap-based buffer overflow was found in the pacsiod process which is handling the OSDP communication allowing to...Show more |
1Axis 5A1001 Firmware A1210 ( B) FirmwareA1601 Firmware+2 moreJun 17, 2026 Jul 25, 2023 N/A· v4 6.5 MEDIUM· v3 N/A· v2 Knud from Fraktal.fi has found a flaw in some Axis Network Door Controllers and Axis Network Intercoms when communicating over OSDP, highlighting that the OSDP message parser crashes the pacsiod process, causing a tempor...Show more |
AXIS OS 11.0.X - 11.3.x use a static RSA key in legacy LUA-components to protect Axis-specific source code. The static RSA key is not used in any other secure communication nor can it be used to compromise the device or...Show more |
A Vulnerability was discovered in Axis 207W network camera. There is a reflected XSS vulnerability in the web administration portal, which allows an attacker to execute arbitrary JavaScript via URL. |
1Axis 6M3005 Firmware M3007 FirmwareM3045 Firmware+3 moreNov 21, 2024 Jun 15, 2022 N/A· v4 9.8 CRITICAL· v3 10.0 HIGH· v2 A vulnerability, was found in legacy Axis devices such as P3225 and M3005. This affects an unknown part of the component CGI Script. The manipulation leads to improper privilege management. It is possible to initiate the...Show more |
AXIS IP Utility before 4.18.0 allows for remote code execution and local privilege escalation by the means of DLL hijacking. IPUtility.exe would attempt to load DLLs from its current working directory which could allow f...Show more |
1Axis 4Axis Os Axis Os 2016Axis Os 2018+1 moreJun 17, 2026 Oct 5, 2021 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 A user controlled parameter related to SMTP test functionality is not correctly validated making it possible to add the Carriage Return and Line Feed (CRLF) control characters and include arbitrary SMTP headers in the ge...Show more |
1Axis 4Axis Os Axis Os 2016Axis Os 2018+1 moreJun 17, 2026 Oct 5, 2021 N/A· v4 7.5 HIGH· v3 5.1 MEDIUM· v2 A user controlled parameter related to SMTP test functionality is not correctly validated making it possible to bypass blocked network recipients. |
1Axis 4Axis Os Axis Os 2016Axis Os 2018+1 moreJun 17, 2026 Oct 5, 2021 N/A· v4 6.8 MEDIUM· v3 4.0 MEDIUM· v2 User controlled parameters related to SMTP notifications are not correctly validated. This can lead to a buffer overflow resulting in crashes and data leakage. |