CVE Browser

Search and filter CVEs by severity, ecosystem, EPSS score, and more.

Clear
More filters (active)

Page 1 (more results available)

CVE-2026-4757 HIGH

Axis: Axis: Code execution and privilege escalation via VAPIX API improper input validation

CVSS 7.2 EPSS 0.57% Aug 11, 2026
CVE-2026-6505 MEDIUM

The ACAP framework contains a Time-of-Check to Time-of-Use (TOCTOU) race condition, which could potentially lead to privilege escalation. This vulnerability ca…

CVSS 5.1 EPSS 0.09% Aug 11, 2026
CVE-2026-5304 MEDIUM

Axis: Axis: Privilege escalation via malicious ACAP application installation

CVSS 5.7 EPSS 0.31% Aug 11, 2026
CVE-2026-5303 MEDIUM

The ACAP framework contains a Time-of-Check to Time-of-Use (TOCTOU) race condition, which could potentially lead to privilege escalation. This vulnerability ca…

CVSS 5.7 EPSS 0.23% Aug 11, 2026
CVE-2026-8158 MEDIUM

The Signed Video Framework contained a buffer overflow issue which could lead the application using this framework to crash. The issue exclusively affects the…

CVSS 5.3 EPSS 0.29% Aug 11, 2026
CVE-2026-6181 MEDIUM

The Device Configuration Framework is vulnerable to an authentication bypass flaw. This flaw can only be exploited after authenticating with a viewer-privilege…

CVSS 5.9 EPSS 0.39% Aug 11, 2026
CVE-2026-1185 HIGH

A configuration file on the local file system had improper input validation which could allow code execution and potentially lead to privilege escalation. This…

CVSS 8.8 EPSS 0.23% May 12, 2026
CVE-2026-0804 HIGH

An ACAP configuration file lacked sufficient input validation, which could allow a path traversal attack leading to potential privilege escalation. This vulner…

CVSS 7.3 EPSS 0.13% May 12, 2026
CVE-2026-0802 HIGH

An ACAP configuration file lacked sufficient input validation, which could allow command injection and potentially lead to privilege escalation. This vulnerabi…

CVSS 7.3 EPSS 0.40% May 12, 2026
CVE-2026-0541 HIGH

ACAP applications can gain elevated privileges due to improper input validation during the installation process, potentially leading to privilege escalation. T…

CVSS 7.3 EPSS 0.10% May 12, 2026
CVE-2025-12063 MEDIUM

An insecure direct object reference allowed a non-admin user to modify or remove certain data objects without having the appropriate permissions.

CVSS 5.7 EPSS 0.18% Feb 10, 2026
CVE-2025-12757 MEDIUM

An AXIS Camera Station Pro feature can be exploited in a way that allows a non-admin user to view information they are not permitted to.

CVSS 4.6 EPSS 0.26% Feb 10, 2026
CVE-2025-13064 MEDIUM

A server-side injection was possible for a malicious admin to manipulate the application to include a malicious script which is executed by the server. This at…

CVSS 4.5 EPSS 0.23% Feb 10, 2026
CVE-2025-11547 HIGH

AXIS Camera Station Pro contained a flaw to perform a privilege escalation attack on the server as a non-admin user.

CVSS 7.8 EPSS 0.16% Feb 10, 2026
CVE-2025-11142 HIGH

The VAPIX API mediaclip.cgi that did not have a sufficient input validation allowing for a possible remote code execution. This flaw can only be exploited afte…

CVSS 8.8 EPSS 0.53% Feb 10, 2026
CVE-2025-9055 MEDIUM

The VAPIX Edge storage API that allowed a privilege escalation, enabling a VAPIX administrator-privileged user to gain Linux Root privileges. This flaw can onl…

CVSS 6.4 EPSS 0.11% Nov 11, 2025
CVE-2025-8998 LOW

It was possible to upload files with a specific name to a temporary directory, which may result in process crashes and impact usability. This flaw can only be…

CVSS 3.1 EPSS 0.22% Nov 11, 2025
CVE-2025-9524 MEDIUM

The VAPIX API port.cgi did not have sufficient input validation, which may result in process crashes and impact usability. This vulnerability can only be explo…

CVSS 4.3 EPSS 0.25% Nov 11, 2025
CVE-2025-10714 HIGH

AXIS Optimizer was vulnerable to an unquoted search path vulnerability, which could potentially lead to privilege escalation within Microsoft Windows operating…

CVSS 8.4 EPSS 0.12% Nov 11, 2025
CVE-2025-8108 MEDIUM

An ACAP configuration file has improper permissions and lacks input validation, which could potentially lead to privilege escalation. This vulnerability can on…

CVSS 6.7 EPSS 0.13% Nov 11, 2025
CVE-2025-6779 MEDIUM

An ACAP configuration file has improper permissions, which could allow command injection and potentially lead to privilege escalation. This vulnerability can o…

CVSS 6.7 EPSS 1.07% Nov 11, 2025
CVE-2025-6571 MEDIUM

A 3rd-party component exposed its password in process arguments, allowing for low-privileged users to access it.

CVSS 6.0 EPSS 0.11% Nov 11, 2025
CVE-2025-5452 MEDIUM

A malicious ACAP application can gain access to admin-level service account credentials used by legitimate ACAP applications, leading to potential privilege es…

CVSS 6.6 EPSS 0.29% Nov 11, 2025
CVE-2025-6298 MEDIUM

ACAP applications can gain elevated privileges due to improper input validation, potentially leading to privilege escalation. This vulnerability can only be ex…

CVSS 6.7 EPSS 0.14% Nov 11, 2025
CVE-2025-5718 MEDIUM

The ACAP Application framework could allow privilege escalation through a symlink attack. This vulnerability can only be exploited if the Axis device is config…

CVSS 6.8 EPSS 0.36% Nov 11, 2025

Showing 1 to 25 CVEs · page 1 (more available)