Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6649
Adobe 6383
Ibm 6266
Cisco 5746
Debian 3919
Apache 2864
Mozilla 2857
Redhat 2581
HIGH 7.5
CVE-2024-6979
Amin Aliakbari, member of the AXIS OS Bug Bounty Program, has found a broken access control which would lead to less-privileged operator- and/or view…
Axis Os 2024
11.11.94+
MEDIUM 6.5
CVE-2024-0055
Sandro Poppi, member of the AXIS OS Bug Bounty Program, has found that the VAPIX APIs mediaclip.cgi and playclip.cgi was vulnerable for file globbing…
Axis Os
10.12.228 / 11.9.53+
HIGH 8.8
CVE-2023-5677
Brandon
Rothel from QED Secure Solutions and Sam Hanson of Dragos have found that the VAPIX API tcptest.cgi
did not have a sufficient input validatio…
M3024 Lve Firmware
5.51.7.7+
HIGH 8.8
CVE-2023-5800
Vintage,
member of the AXIS OS Bug Bounty Program, has found that the VAPIX API create_overlay.cgi
did not have a sufficient input validation allowin…
Axis Os
9.80.55 / 10.12.220+
MEDIUM 6.8
CVE-2023-5553
During internal Axis Security Development Model (ASDM) threat-modelling, a flaw was found in the protection for device tampering (commonly known as S…
Axis Os
10.12.213 / 11.7.57+
HIGH 7.1
CVE-2023-21417
Sandro Poppi, member of the AXIS OS Bug Bounty Program,
has found that the VAPIX API manageoverlayimage.cgi was vulnerable to path traversal attacks…
Axis Os
9.80.49 / 10.12.208+
HIGH 7.1
CVE-2023-21418
Sandro Poppi, member of the AXIS OS Bug Bounty Program, has found that the VAPIX API irissetup.cgi was vulnerable to path traversal attacks that allo…
Axis Os
6.50.5.15 / 8.40.35+
MEDIUM 6.5
CVE-2023-21416
Sandro Poppi, member of the AXIS OS Bug Bounty Program, has found that the VAPIX API dynamicoverlay.cgi was vulnerable to a Denial-of-Service attack …
Axis Os
10.12.213 / 11.7.57+
HIGH 8.1
CVE-2023-21415
Sandro Poppi, member of the AXIS OS Bug Bounty Program, has found that the VAPIX API overlay_del.cgi is vulnerable to path traversal attacks that all…
Axis Os
6.50.5.2 / 6.50.5.14+
HIGH 7.2
CVE-2023-21413
GoSecure on behalf of Genetec Inc. has found a flaw that allows for a remote code execution during the installation of ACAP applications on the Axis …
Axis Os
10.12.199 / 11.6.94+
MEDIUM 6.8
CVE-2023-21414
NCC Group has found a flaw during the annual internal penetration test ordered by Axis Communications. The protection for device tampering (commonly …
Axis Os
10.12.206 / 11.6.94+
HIGH 8.8
CVE-2023-21411
User provided input is not sanitized in the “Settings > Access Control” configuration interface allowing for
arbitrary code execution.
License Plate Verifier
after 2.8.3
HIGH 8.8
CVE-2023-21412
User provided input is not sanitized on the AXIS License Plate Verifier specific “search.cgi” allowing for
SQL injections.
License Plate Verifier
after 2.8.3
CRITICAL 9.8
CVE-2023-21408
Due to insufficient file permissions, unprivileged users could gain access to unencrypted user credentials
that are used in the integration interface…
License Plate Verifier
after 2.8.3
CRITICAL 9.8
CVE-2023-21409
Due to insufficient file permissions, unprivileged users could gain access to unencrypted administrator
credentials allowing the configuration of the…
License Plate Verifier
after 2.8.3
HIGH 8.8
CVE-2023-21407
A broken access control was found allowing for privileged escalation of the operator account to gain
administrator privileges.
License Plate Verifier
after 2.8.3
HIGH 8.8
CVE-2023-21410
User provided input is not sanitized on the AXIS License Plate Verifier specific “api.cgi” allowing for
arbitrary code execution.
License Plate Verifier
after 2.8.3
HIGH 8.8
CVE-2023-21406
Ariel Harush and Roy Hodir from OTORIO have found a flaw in the AXIS A1001 when
communicating over OSDP. A heap-based buffer overflow was found in th…
A1001 Firmware
after 1.65.4
MEDIUM 6.5
CVE-2023-21405
Knud from Fraktal.fi has found a flaw in some Axis Network Door Controllers and Axis Network
Intercoms when communicating over OSDP, highlighting tha…
A1001 Firmware
after 11.6.16.0
MEDIUM 5.3
CVE-2023-21404
AXIS OS 11.0.X - 11.3.x use a static RSA key in legacy LUA-components to protect Axis-specific source code. The static RSA key is not used in any oth…
Axis Os
11.4.52+
MEDIUM 6.1
CVE-2023-22984
A Vulnerability was discovered in Axis 207W network camera. There is a reflected XSS vulnerability in the web administration portal, which allows an …
207w Firmware
No fix yet
CRITICAL 9.8
CVE-2017-20049
A vulnerability, was found in legacy Axis devices such as P3225 and M3005. This affects an unknown part of the component CGI Script. The manipulation…
P1204 Firmware
after 6.30.1.1
HIGH 7.8
CVE-2022-23410
AXIS IP Utility before 4.18.0 allows for remote code execution and local privilege escalation by the means of DLL hijacking. IPUtility.exe would atte…
Ip Utility
4.18.0+
HIGH 8.8
CVE-2021-31988
A user controlled parameter related to SMTP test functionality is not correctly validated making it possible to add the Carriage Return and Line Feed…
Axis Os
6.50.5.5 / 8.40.4.3+
HIGH 7.5
CVE-2021-31987
A user controlled parameter related to SMTP test functionality is not correctly validated making it possible to bypass blocked network recipients.
Axis Os
6.50.5.5 / 8.40.4.3+
MEDIUM 6.8
CVE-2021-31986
User controlled parameters related to SMTP notifications are not correctly validated. This can lead to a buffer overflow resulting in crashes and dat…
Axis Os
6.50.5.5 / 8.40.4.3+
MEDIUM 5.3
CVE-2021-31989
A user with permission to log on to the machine hosting the AXIS Device Manager client could under certain conditions extract a memory dump from the …
Device Manager
after 5.16.063
CRITICAL 9.8
CVE-2018-10660EPSS 82%
An issue was discovered in multiple models of Axis IP Cameras. There is Shell Command Injection.
A1001 Firmware
1.65.0 / 1.65.1+
CRITICAL 9.8
CVE-2018-10661EPSS 87%
An issue was discovered in multiple models of Axis IP Cameras. There is a bypass of access control.
A1001 Firmware
1.65.0 / 1.65.1+
CRITICAL 9.8
CVE-2018-10662EPSS 80%
An issue was discovered in multiple models of Axis IP Cameras. There is an Exposed Insecure Interface.
A1001 Firmware
1.65.0 / 1.65.1+