Vulnerability index

Browse CVEs

86 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

HIGH 7.5 CVE-2024-6979 Amin Aliakbari, member of the AXIS OS Bug Bounty Program, has found a broken access control which would lead to less-privileged operator- and/or view… Axis Os 2024 11.11.94+ Fix from $1,9502024-09-10 MEDIUM 6.5 CVE-2024-0055 Sandro Poppi, member of the AXIS OS Bug Bounty Program, has found that the VAPIX APIs mediaclip.cgi and playclip.cgi was vulnerable for file globbing… Axis Os 10.12.228 / 11.9.53+ Fix from $1,6002024-03-19 HIGH 8.8 CVE-2023-5677 Brandon Rothel from QED Secure Solutions and Sam Hanson of Dragos have found that the VAPIX API tcptest.cgi did not have a sufficient input validatio… M3024 Lve Firmware 5.51.7.7+ Fix from $1,9502024-02-05 HIGH 8.8 CVE-2023-5800 Vintage, member of the AXIS OS Bug Bounty Program, has found that the VAPIX API create_overlay.cgi did not have a sufficient input validation allowin… Axis Os 9.80.55 / 10.12.220+ Fix from $1,9502024-02-05 MEDIUM 6.8 CVE-2023-5553 During internal Axis Security Development Model (ASDM) threat-modelling, a flaw was found in the protection for device tampering (commonly known as S… Axis Os 10.12.213 / 11.7.57+ Fix from $1,6002023-11-21 HIGH 7.1 CVE-2023-21417 Sandro Poppi, member of the AXIS OS Bug Bounty Program, has found that the VAPIX API manageoverlayimage.cgi was vulnerable to path traversal attacks… Axis Os 9.80.49 / 10.12.208+ Fix from $1,9502023-11-21 HIGH 7.1 CVE-2023-21418 Sandro Poppi, member of the AXIS OS Bug Bounty Program, has found that the VAPIX API irissetup.cgi was vulnerable to path traversal attacks that allo… Axis Os 6.50.5.15 / 8.40.35+ Fix from $1,9502023-11-21 MEDIUM 6.5 CVE-2023-21416 Sandro Poppi, member of the AXIS OS Bug Bounty Program, has found that the VAPIX API dynamicoverlay.cgi was vulnerable to a Denial-of-Service attack … Axis Os 10.12.213 / 11.7.57+ Fix from $1,6002023-11-21 HIGH 8.1 CVE-2023-21415 Sandro Poppi, member of the AXIS OS Bug Bounty Program, has found that the VAPIX API overlay_del.cgi is vulnerable to path traversal attacks that all… Axis Os 6.50.5.2 / 6.50.5.14+ Fix from $1,9502023-10-16 HIGH 7.2 CVE-2023-21413 GoSecure on behalf of Genetec Inc. has found a flaw that allows for a remote code execution during the installation of ACAP applications on the Axis … Axis Os 10.12.199 / 11.6.94+ Fix from $1,9502023-10-16 MEDIUM 6.8 CVE-2023-21414 NCC Group has found a flaw during the annual internal penetration test ordered by Axis Communications. The protection for device tampering (commonly … Axis Os 10.12.206 / 11.6.94+ Fix from $1,6002023-10-16 HIGH 8.8 CVE-2023-21411 User provided input is not sanitized in the “Settings > Access Control” configuration interface allowing for arbitrary code execution. License Plate Verifier after 2.8.3 Fix from $1,9502023-08-03 HIGH 8.8 CVE-2023-21412 User provided input is not sanitized on the AXIS License Plate Verifier specific “search.cgi” allowing for SQL injections. License Plate Verifier after 2.8.3 Fix from $1,9502023-08-03 CRITICAL 9.8 CVE-2023-21408 Due to insufficient file permissions, unprivileged users could gain access to unencrypted user credentials that are used in the integration interface… License Plate Verifier after 2.8.3 Fix from $2,3002023-08-03 CRITICAL 9.8 CVE-2023-21409 Due to insufficient file permissions, unprivileged users could gain access to unencrypted administrator credentials allowing the configuration of the… License Plate Verifier after 2.8.3 Fix from $2,3002023-08-03 HIGH 8.8 CVE-2023-21407 A broken access control was found allowing for privileged escalation of the operator account to gain administrator privileges. License Plate Verifier after 2.8.3 Fix from $1,9502023-08-03 HIGH 8.8 CVE-2023-21410 User provided input is not sanitized on the AXIS License Plate Verifier specific “api.cgi” allowing for arbitrary code execution. License Plate Verifier after 2.8.3 Fix from $1,9502023-08-03 HIGH 8.8 CVE-2023-21406 Ariel Harush and Roy Hodir from OTORIO have found a flaw in the AXIS A1001 when communicating over OSDP. A heap-based buffer overflow was found in th… A1001 Firmware after 1.65.4 Fix from $1,9502023-07-25 MEDIUM 6.5 CVE-2023-21405 Knud from Fraktal.fi has found a flaw in some Axis Network Door Controllers and Axis Network Intercoms when communicating over OSDP, highlighting tha… A1001 Firmware after 11.6.16.0 Fix from $1,6002023-07-25 MEDIUM 5.3 CVE-2023-21404 AXIS OS 11.0.X - 11.3.x use a static RSA key in legacy LUA-components to protect Axis-specific source code. The static RSA key is not used in any oth… Axis Os 11.4.52+ Fix from $1,6002023-05-08 MEDIUM 6.1 CVE-2023-22984 A Vulnerability was discovered in Axis 207W network camera. There is a reflected XSS vulnerability in the web administration portal, which allows an … 207w Firmware No fix yet Fix from $1,6002023-02-21 CRITICAL 9.8 CVE-2017-20049 A vulnerability, was found in legacy Axis devices such as P3225 and M3005. This affects an unknown part of the component CGI Script. The manipulation… P1204 Firmware after 6.30.1.1 Fix from $2,3002022-06-15 HIGH 7.8 CVE-2022-23410 AXIS IP Utility before 4.18.0 allows for remote code execution and local privilege escalation by the means of DLL hijacking. IPUtility.exe would atte… Ip Utility 4.18.0+ Fix from $1,9502022-02-14 HIGH 8.8 CVE-2021-31988 A user controlled parameter related to SMTP test functionality is not correctly validated making it possible to add the Carriage Return and Line Feed… Axis Os 6.50.5.5 / 8.40.4.3+ Fix from $1,9502021-10-05 HIGH 7.5 CVE-2021-31987 A user controlled parameter related to SMTP test functionality is not correctly validated making it possible to bypass blocked network recipients. Axis Os 6.50.5.5 / 8.40.4.3+ Fix from $1,9502021-10-05 MEDIUM 6.8 CVE-2021-31986 User controlled parameters related to SMTP notifications are not correctly validated. This can lead to a buffer overflow resulting in crashes and dat… Axis Os 6.50.5.5 / 8.40.4.3+ Fix from $1,6002021-10-05 MEDIUM 5.3 CVE-2021-31989 A user with permission to log on to the machine hosting the AXIS Device Manager client could under certain conditions extract a memory dump from the … Device Manager after 5.16.063 Fix from $1,6002021-08-25 CRITICAL 9.8 CVE-2018-10660EPSS 82% An issue was discovered in multiple models of Axis IP Cameras. There is Shell Command Injection. A1001 Firmware 1.65.0 / 1.65.1+ Fix from $2,3002018-06-26 CRITICAL 9.8 CVE-2018-10661EPSS 87% An issue was discovered in multiple models of Axis IP Cameras. There is a bypass of access control. A1001 Firmware 1.65.0 / 1.65.1+ Fix from $2,3002018-06-26 CRITICAL 9.8 CVE-2018-10662EPSS 80% An issue was discovered in multiple models of Axis IP Cameras. There is an Exposed Insecure Interface. A1001 Firmware 1.65.0 / 1.65.1+ Fix from $2,3002018-06-26