Vulnerability index

Browse CVEs

86 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

HIGH 8.8 CVE-2026-1185 A configuration file on the local file system had improper input validation which could allow code execution and potentially lead to privilege escala… Axis Os 12.10.37+ Fix from $1,9502026-05-12 HIGH 7.3 CVE-2026-0541 ACAP applications can gain elevated privileges due to improper input validation during the installation process, potentially leading to privilege esc… Axis Os 12.9.32+ Fix from $1,9502026-05-12 HIGH 7.3 CVE-2026-0802 An ACAP configuration file lacked sufficient input validation, which could allow command injection and potentially lead to privilege escalation. This… Axis Os 12.9.33+ Fix from $1,9502026-05-12 HIGH 7.3 CVE-2026-0804 An ACAP configuration file lacked sufficient input validation, which could allow a path traversal attack leading to potential privilege escalation. T… Axis Os 12.10.4+ Fix from $1,9502026-05-12 MEDIUM 5.7 CVE-2025-12063 An insecure direct object reference allowed a non-admin user to modify or remove certain data objects without having the appropriate permissions. Camera Station Pro 6.14.10768+ Fix from $1,6002026-02-10 HIGH 7.8 CVE-2025-11547 AXIS Camera Station Pro contained a flaw to perform a privilege escalation attack on the server as a non-admin user. Camera Station Pro 6.13.55835+ Fix from $1,9502026-02-10 HIGH 8.8 CVE-2025-11142 The VAPIX API mediaclip.cgi that did not have a sufficient input validation allowing for a possible remote code execution. This flaw can only be expl… Axis Os 12.7.36+ Fix from $1,9502026-02-10 MEDIUM 6.7 CVE-2025-8108 An ACAP configuration file has improper permissions and lacks input validation, which could potentially lead to privilege escalation. This vulnerabil… Axis Os 12.7.33+ Fix from $1,6002025-11-11 MEDIUM 6.8 CVE-2025-5718 The ACAP Application framework could allow privilege escalation through a symlink attack. This vulnerability can only be exploited if the Axis device… Axis Os 12.6.30+ Fix from $1,6002025-11-11 MEDIUM 6.7 CVE-2025-6298 ACAP applications can gain elevated privileges due to improper input validation, potentially leading to privilege escalation. This vulnerability can … Axis Os 12.6.28+ Fix from $1,6002025-11-11 MEDIUM 6.7 CVE-2025-6779 An ACAP configuration file has improper permissions, which could allow command injection and potentially lead to privilege escalation. This vulnerabi… Axis Os 12.6.40+ Fix from $1,6002025-11-11 MEDIUM 6.7 CVE-2025-5454 An ACAP configuration file lacked sufficient input validation, which could allow a path traversal attack leading to potential privilege escalation. T… Axis Os 12.6.18+ Fix from $1,6002025-11-11 MEDIUM 6.6 CVE-2025-5452 A malicious ACAP application can gain access to admin-level service account credentials used by legitimate ACAP applications, leading to potential pr… Axis Os 12.6.69+ Fix from $1,6002025-11-11 MEDIUM 6.7 CVE-2025-4645 An ACAP configuration file lacked sufficient input validation, which could allow for arbitrary code execution. This vulnerability can only be exploit… Axis Os 12.6.7+ Fix from $1,6002025-11-11 MEDIUM 6.7 CVE-2025-3892 ACAP applications can be executed with elevated privileges, potentially leading to privilege escalation. This vulnerability can only be exploited if … Axis Os 12.5.31+ Fix from $1,6002025-08-12 MEDIUM 6.7 CVE-2025-30027 An ACAP configuration file lacked sufficient input validation, which could allow for arbitrary code execution. This vulnerability can only be exploit… Axis Os 12.5.36+ Fix from $1,6002025-08-12 MEDIUM 5.7 CVE-2025-7622 During an internal security assessment, a Server-Side Request Forgery (SSRF) vulnerability that allowed an authenticated attacker to access internal … Camera Station 5.59.49607 / 6.10.49500+ Fix from $1,6002025-08-12 CRITICAL 9.8 CVE-2025-30026 The AXIS Camera Station Server had a flaw that allowed to bypass authentication that is normally required. Camera Station 5.58.47195 / 6.9.47069+ Fix from $2,3002025-07-11 CRITICAL 9.0 CVE-2025-30023 The communication protocol used between client and server had a flaw that could lead to an authenticated user performing a remote code execution atta… Camera Station 5.32.137 / 5.58.47195+ Fix from $2,3002025-07-11 HIGH 7.8 CVE-2025-30025 The communication protocol used between the server process and the service control had a flaw that could lead to a local privilege escalation. Camera Station Pro 5.32.137 / 6.8.43213+ Fix from $1,9502025-07-11 MEDIUM 6.8 CVE-2025-30024 The communication protocol used between client and server had a flaw that could be leveraged to execute a man in the middle attack. Device Manager 5.32.137+ Fix from $1,6002025-07-11 HIGH 8.8 CVE-2025-0324 The VAPIX Device Configuration framework allowed a privilege escalation, enabling a lower-privileged user to gain administrator privileges. Axis Os 11.11.140 / 12.3.33+ Fix from $1,9502025-06-02 HIGH 8.8 CVE-2025-0358 During an annual penetration test conducted on behalf of Axis Communication, Truesec discovered a flaw in the VAPIX Device Configuration framework th… Axis Os 12.4.0+ Fix from $1,9502025-06-02 MEDIUM 6.5 CVE-2025-1056 Gee-netics, member of AXIS Camera Station Pro Bug Bounty Program, has identified an issue with a specific file that the server is using. A non-admin … Camera Station Pro 6.8.43213+ Fix from $1,6002025-04-23 HIGH 7.3 CVE-2025-0926 Gee-netics, member of AXIS Camera Station Pro Bug Bounty Program, has found that it is possible for a non-admin user to remove system files causing a… Camera Station Pro 6.8.43213+ Fix from $1,9502025-04-23 MEDIUM 5.3 CVE-2025-0361 During an annual penetration test conducted on behalf of Axis Communications, Truesec discovered a flaw in the VAPIX Device Configuration framework t… Axis Os 11.11.141 / 12.3.56+ Fix from $1,6002025-04-08 HIGH 7.8 CVE-2025-0360 During an annual penetration test conducted on behalf of Axis Communication, Truesec discovered a flaw in the VAPIX Device Configuration framework th… Axis Os 11.11.135 / 12.2.41+ Fix from $1,9502025-03-04 MEDIUM 5.5 CVE-2025-0359 During an annual penetration test conducted on behalf of Axis Communication, Truesec discovered a flaw in the ACAP Application framework that allowed… Axis Os 11.11.135 / 12.2.52+ Fix from $1,6002025-03-04 HIGH 7.1 CVE-2024-47259 Girishunawane, member of the AXIS OS Bug Bounty Program, has found that the VAPIX API dynamicoverlay.cgi did not have a sufficient input validation a… Axis Os 11.11.126 / 12.2.52+ Fix from $1,9502025-03-04 MEDIUM 6.3 CVE-2024-7696 Seth Fogie, member of AXIS Camera Station Pro Bug Bounty Program, has found that it is possible for an authenticated malicious client to tamper with … Camera Station Pro 6.5.35848+ Fix from $1,6002025-01-07