Skip to main content

Vendor archive

axis CVEs

Beta · best-effort

100 CVEs tagged to vendor axis14 Critical, 34 High, 49 Medium, 3 Low, 0 Unrated.

CVE-2026-1185

Published May 12, 2026

A configuration file on the local file system had improper input validation which could allow code execution and potentially lead to privilege escalation. This vulnerability can o…

CVSS 5.4 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-0804

Published May 12, 2026

An ACAP configuration file lacked sufficient input validation, which could allow a path traversal attack leading to potential privilege escalation. This vulnerability can only be…

CVSS 6.7 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-0802

Published May 12, 2026

An ACAP configuration file lacked sufficient input validation, which could allow command injection and potentially lead to privilege escalation. This vulnerability can only be exp…

CVSS 6.0 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-0541

Published May 12, 2026

ACAP applications can gain elevated privileges due to improper input validation during the installation process, potentially leading to privilege escalation. This vulnerability ca…

CVSS 6.7 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2025-12063

Published Feb 10, 2026

An insecure direct object reference allowed a non-admin user to modify or remove certain data objects without having the appropriate permissions.

CVSS 5.7 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2025-13064

Published Feb 10, 2026

A server-side injection was possible for a malicious admin to manipulate the application to include a malicious script which is executed by the server. This attack is only possibl…

CVSS 4.5 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2025-12757

Published Feb 10, 2026

An AXIS Camera Station Pro feature can be exploited in a way that allows a non-admin user to view information they are not permitted to.

CVSS 4.6 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2025-11547

Published Feb 10, 2026

AXIS Camera Station Pro contained a flaw to perform a privilege escalation attack on the server as a non-admin user.

CVSS 7.8 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2025-11142

Published Feb 10, 2026

The VAPIX API mediaclip.cgi that did not have a sufficient input validation allowing for a possible remote code execution. This flaw can only be exploited after authenticating wit…

CVSS 7.1 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2025-6779

Published Nov 11, 2025

An ACAP configuration file has improper permissions, which could allow command injection and potentially lead to privilege escalation. This vulnerability can only be exploited if…

CVSS 6.7 · Medium

CVE-2025-6298

Published Nov 11, 2025

ACAP applications can gain elevated privileges due to improper input validation, potentially leading to privilege escalation. This vulnerability can only be exploited if the Axis…

CVSS 6.7 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-5718

Published Nov 11, 2025

The ACAP Application framework could allow privilege escalation through a symlink attack. This vulnerability can only be exploited if the Axis device is configured to allow the in…

CVSS 6.8 · Medium

CVE-2025-5454

Published Nov 11, 2025

An ACAP configuration file lacked sufficient input validation, which could allow a path traversal attack leading to potential privilege escalation. This vulnerability can only be…

CVSS 6.4 · Medium

CVE-2025-5452

Published Nov 11, 2025

A malicious ACAP application can gain access to admin-level service account credentials used by legitimate ACAP applications, leading to potential privilege escalation of the mali…

CVSS 6.6 · Medium

CVE-2025-4645

Published Nov 11, 2025

An ACAP configuration file lacked sufficient input validation, which could allow for arbitrary code execution. This vulnerability can only be exploited if the Axis device is confi…

CVSS 6.7 · Medium

CVE-2025-3892

Published Aug 12, 2025

ACAP applications can be executed with elevated privileges, potentially leading to privilege escalation. This vulnerability can only be exploited if the Axis device is configured…

CVSS 6.7 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-30027

Published Aug 12, 2025

An ACAP configuration file lacked sufficient input validation, which could allow for arbitrary code execution. This vulnerability can only be exploited if the Axis device is confi…

CVSS 6.7 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-30024

Published Jul 11, 2025

The communication protocol used between client and server had a flaw that could be leveraged to execute a man in the middle attack.

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-0358

Published Jun 2, 2025

During an annual penetration test conducted on behalf of Axis Communication, Truesec discovered a flaw in the VAPIX Device Configuration framework that allowed a privilege escalat…

CVSS 8.8 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2025-0324

Published Jun 2, 2025

The VAPIX Device Configuration framework allowed a privilege escalation, enabling a lower-privileged user to gain administrator privileges.

CVSS 9.4 · Critical
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort
Showing 1-25 of 100 CVEsPage 1 of 4