← Back

Axis

axis

98 CVEs • 1,082 products

Products (1,082)

Click to collapse
Toggle
Axis Os
axis_os
Axis Os 2022
axis_os_2022
Axis Os 2024
axis_os_2024

CVEs (98)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Axis
1Device Manager
Jun 17, 2026
Aug 25, 2021
N/A· v4
5.3 MEDIUM· v3
3.5 LOW· v2
A user with permission to log on to the machine hosting the AXIS Device Manager client could under certain conditions extract a memory dump from the built-in Windows Task Manager application. The memory dump may potentia...Show more
A user with permission to log on to the machine hosting the AXIS Device Manager client could under certain conditions extract a memory dump from the built-in Windows Task Manager application. The memory dump may potentially contain credentials of connected Axis devices.Show less
1Axis
390A1001 Firmware
A8004 V FirmwareA8105 E Firmware+387 more
Nov 21, 2024
Jun 26, 2018
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
An issue was discovered in the httpd process in multiple models of Axis IP Cameras. There is Memory Corruption.
1Axis
390A1001 Firmware
A8004 V FirmwareA8105 E Firmware+387 more
Nov 21, 2024
Jun 26, 2018
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
An issue was discovered in multiple models of Axis IP Cameras. There is an Incorrect Size Calculation.
1Axis
390A1001 Firmware
A8004 V FirmwareA8105 E Firmware+387 more
Nov 21, 2024
Jun 26, 2018
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
An issue was discovered in multiple models of Axis IP Cameras. There is an Exposed Insecure Interface.
1Axis
390A1001 Firmware
A8004 V FirmwareA8105 E Firmware+387 more
Nov 21, 2024
Jun 26, 2018
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
An issue was discovered in multiple models of Axis IP Cameras. There is a bypass of access control.
1Axis
390A1001 Firmware
A8004 V FirmwareA8105 E Firmware+387 more
Nov 21, 2024
Jun 26, 2018
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
An issue was discovered in multiple models of Axis IP Cameras. There is Shell Command Injection.
1Axis
390A1001 Firmware
A8004 V FirmwareA8105 E Firmware+387 more
Nov 21, 2024
Jun 26, 2018
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
There was a Memory Corruption issue discovered in multiple models of Axis IP Cameras which allows remote attackers to cause a denial of service (crash) by sending a crafted command which will result in a code path that c...Show more
There was a Memory Corruption issue discovered in multiple models of Axis IP Cameras which allows remote attackers to cause a denial of service (crash) by sending a crafted command which will result in a code path that calls the UND undefined ARM instruction.Show less
1Axis
390A1001 Firmware
A8004 V FirmwareA8105 E Firmware+387 more
Nov 21, 2024
Jun 26, 2018
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
There was a Memory Corruption issue discovered in multiple models of Axis IP Cameras which causes a denial of service (crash). The crash arises from code inside libdbus-send.so shared object or similar.
1Axis
1M1033 W Firmware
Jun 17, 2026
Apr 1, 2018
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
An issue was discovered on AXIS M1033-W (IP camera) Firmware version 5.40.5.1 devices. They don't employ a suitable mechanism to prevent a DoS attack, which leads to a response time delay. An attacker can use the hping3...Show more
An issue was discovered on AXIS M1033-W (IP camera) Firmware version 5.40.5.1 devices. They don't employ a suitable mechanism to prevent a DoS attack, which leads to a response time delay. An attacker can use the hping3 tool to perform an IPv4 flood attack, and the services are interrupted from attack start to end.Show less
1Axis
1M1033 W Firmware
Jun 17, 2026
Apr 1, 2018
N/A· v4
7.5 HIGH· v3
7.6 HIGH· v2
An issue was discovered on AXIS M1033-W (IP camera) Firmware version 5.40.5.1 devices. The upload web page doesn't verify the file type, and an attacker can upload a webshell by making a fileUpload.shtml request for a cu...Show more
An issue was discovered on AXIS M1033-W (IP camera) Firmware version 5.40.5.1 devices. The upload web page doesn't verify the file type, and an attacker can upload a webshell by making a fileUpload.shtml request for a custom .shtml file, which is interpreted by the Apache HTTP Server mod_include module with "<!--#exec cmd=" support. The file needs to include a specific string to meet the internal system architecture. After the webshell upload, an attacker can use the webshell to perform remote code execution such as running a system command (ls, ping, cat /etc/passwd, etc.). NOTE: the vendor reportedly indicates that this is an intended feature or functionalityShow less
1Axis
1P1354 Firmware
Jun 17, 2026
Apr 1, 2018
N/A· v4
7.5 HIGH· v3
7.6 HIGH· v2
An issue was discovered on AXIS P1354 (IP camera) Firmware version 5.90.1.1 devices. The upload web page doesn't verify the file type, and an attacker can upload a webshell by making a fileUpload.shtml request for a cust...Show more
An issue was discovered on AXIS P1354 (IP camera) Firmware version 5.90.1.1 devices. The upload web page doesn't verify the file type, and an attacker can upload a webshell by making a fileUpload.shtml request for a custom .shtml file, which is interpreted by the Apache HTTP Server mod_include module with "<!--#exec cmd=" support. The file needs to include a specific string to meet the internal system architecture. After the webshell upload, an attacker can use the webshell to perform remote code execution such as running a system command (ls, ping, cat /etc/passwd, etc.). NOTE: the vendor reportedly indicates that this is an intended feature or functionalityShow less
1Axis
12100 Network Camera Firmware
May 13, 2026
Oct 25, 2017
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Reflected XSS in the web administration portal on the Axis 2100 Network Camera 2.03 allows an attacker to execute arbitrary JavaScript via the conf_Layout_OwnTitle parameter to view/view.shtml. NOTE: this might overlap C...Show more
Reflected XSS in the web administration portal on the Axis 2100 Network Camera 2.03 allows an attacker to execute arbitrary JavaScript via the conf_Layout_OwnTitle parameter to view/view.shtml. NOTE: this might overlap CVE-2007-5214.Show less
1Axis
12100 Network Camera Firmware
May 13, 2026
Aug 4, 2017
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
AXIS 2100 devices 2.43 have XSS via the URI, possibly related to admin/admin.shtml.
1Axis
1Network Camera Firmware
May 13, 2026
May 2, 2017
N/A· v4
8.8 HIGH· v3
9.0 HIGH· v2
The devtools.sh script in AXIS network cameras allows remote authenticated users to execute arbitrary commands via shell metacharacters in the app parameter to (1) app_license.shtml, (2) app_license_custom.shtml, (3) app...Show more
The devtools.sh script in AXIS network cameras allows remote authenticated users to execute arbitrary commands via shell metacharacters in the app parameter to (1) app_license.shtml, (2) app_license_custom.shtml, (3) app_index.shtml, or (4) app_params.shtml.Show less
1Axis
1Network Camera Firmware
May 13, 2026
Apr 17, 2017
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Multiple cross-site scripting (XSS) vulnerabilities in Axis network cameras.
1Axis
1Axis Communications Firmware
May 13, 2026
Apr 10, 2017
N/A· v4
7.5 HIGH· v3
7.8 HIGH· v2
AXIS Communications products with firmware through 5.80.x allow remote attackers to modify arbitrary files as root via vectors involving Open Script Editor, aka a "resource injection vulnerability."
1Axis
1Axis Communications Firmware
May 13, 2026
Apr 10, 2017
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
AXIS Communications products allow CSRF, as demonstrated by admin/pwdgrp.cgi, vaconfig.cgi, and admin/local_del.cgi.
1Axis
1Media Control Activex Control
Apr 29, 2026
Oct 4, 2013
N/A· v4
N/A· v3
8.8 HIGH· v2
The AXIS Media Control (AMC) ActiveX control (AxisMediaControlEmb.dll) 6.2.10.11 for AXIS network cameras allows remote attackers to create or overwrite arbitrary files via a file path to the (1) StartRecord, (2) SaveCur...Show more
The AXIS Media Control (AMC) ActiveX control (AxisMediaControlEmb.dll) 6.2.10.11 for AXIS network cameras allows remote attackers to create or overwrite arbitrary files via a file path to the (1) StartRecord, (2) SaveCurrentImage, or (3) StartRecordMedia methods.Show less
1Axis
2M1054 Network Camera
M10 Series Network Cameras Firmware
Apr 29, 2026
Feb 12, 2013
N/A· v4
N/A· v3
4.3 MEDIUM· v2
Cross-site scripting (XSS) vulnerability in serverreport.cgi in Axis M10 Series Network Cameras M1054 firmware 5.21 and earlier allows remote attackers to inject arbitrary web script or HTML via the pageTitle parameter t...Show more
Cross-site scripting (XSS) vulnerability in serverreport.cgi in Axis M10 Series Network Cameras M1054 firmware 5.21 and earlier allows remote attackers to inject arbitrary web script or HTML via the pageTitle parameter to admin/showReport.shtml.Show less
1Axis
1Axis Camera Control
Apr 23, 2026
Jan 26, 2009
N/A· v4
N/A· v3
9.3 HIGH· v2
Heap-based buffer overflow in the CamImage.CamImage.1 ActiveX control in AxisCamControl.ocx in AXIS Camera Control 2.40.0.0 allows remote attackers to execute arbitrary code via a long image_pan_tilt property value.