Axis / Axis OS
56 CVEs
| CVE ID | Description | Severity | CVSS | Published |
|---|---|---|---|---|
| CVE-2026-4757 | Axis: Axis: Code execution and privilege escalation via VAPIX API improper input validation | HIGH | 7.2 | Aug 11, 2026 |
| CVE-2026-6505 | The ACAP framework contains a Time-of-Check to Time-of-Use (TOCTOU) race condition, which could potentially lead to privilege escalation. This vulnerability ca… | MEDIUM | 5.1 | Aug 11, 2026 |
| CVE-2026-5304 | Axis: Axis: Privilege escalation via malicious ACAP application installation | MEDIUM | 5.7 | Aug 11, 2026 |
| CVE-2026-5303 | The ACAP framework contains a Time-of-Check to Time-of-Use (TOCTOU) race condition, which could potentially lead to privilege escalation. This vulnerability ca… | MEDIUM | 5.7 | Aug 11, 2026 |
| CVE-2026-6181 | The Device Configuration Framework is vulnerable to an authentication bypass flaw. This flaw can only be exploited after authenticating with a viewer-privilege… | MEDIUM | 5.9 | Aug 11, 2026 |
| CVE-2026-1185 | A configuration file on the local file system had improper input validation which could allow code execution and potentially lead to privilege escalation. This… | HIGH | 8.8 | May 12, 2026 |
| CVE-2026-0804 | An ACAP configuration file lacked sufficient input validation, which could allow a path traversal attack leading to potential privilege escalation. This vulner… | HIGH | 7.3 | May 12, 2026 |
| CVE-2026-0802 | An ACAP configuration file lacked sufficient input validation, which could allow command injection and potentially lead to privilege escalation. This vulnerabi… | HIGH | 7.3 | May 12, 2026 |
| CVE-2026-0541 | ACAP applications can gain elevated privileges due to improper input validation during the installation process, potentially leading to privilege escalation. T… | HIGH | 7.3 | May 12, 2026 |
| CVE-2025-11142 | The VAPIX API mediaclip.cgi that did not have a sufficient input validation allowing for a possible remote code execution. This flaw can only be exploited afte… | HIGH | 8.8 | Feb 10, 2026 |
| CVE-2025-9055 | The VAPIX Edge storage API that allowed a privilege escalation, enabling a VAPIX administrator-privileged user to gain Linux Root privileges. This flaw can onl… | MEDIUM | 6.4 | Nov 11, 2025 |
| CVE-2025-8998 | It was possible to upload files with a specific name to a temporary directory, which may result in process crashes and impact usability. This flaw can only be… | LOW | 3.1 | Nov 11, 2025 |
| CVE-2025-9524 | The VAPIX API port.cgi did not have sufficient input validation, which may result in process crashes and impact usability. This vulnerability can only be explo… | MEDIUM | 4.3 | Nov 11, 2025 |
| CVE-2025-8108 | An ACAP configuration file has improper permissions and lacks input validation, which could potentially lead to privilege escalation. This vulnerability can on… | MEDIUM | 6.7 | Nov 11, 2025 |
| CVE-2025-6779 | An ACAP configuration file has improper permissions, which could allow command injection and potentially lead to privilege escalation. This vulnerability can o… | MEDIUM | 6.7 | Nov 11, 2025 |
| CVE-2025-6571 | A 3rd-party component exposed its password in process arguments, allowing for low-privileged users to access it. | MEDIUM | 6.0 | Nov 11, 2025 |
| CVE-2025-5452 | A malicious ACAP application can gain access to admin-level service account credentials used by legitimate ACAP applications, leading to potential privilege es… | MEDIUM | 6.6 | Nov 11, 2025 |
| CVE-2025-6298 | ACAP applications can gain elevated privileges due to improper input validation, potentially leading to privilege escalation. This vulnerability can only be ex… | MEDIUM | 6.7 | Nov 11, 2025 |
| CVE-2025-5718 | The ACAP Application framework could allow privilege escalation through a symlink attack. This vulnerability can only be exploited if the Axis device is config… | MEDIUM | 6.8 | Nov 11, 2025 |
| CVE-2025-5454 | An ACAP configuration file lacked sufficient input validation, which could allow a path traversal attack leading to potential privilege escalation. This vulner… | MEDIUM | 6.7 | Nov 11, 2025 |
| CVE-2025-4645 | An ACAP configuration file lacked sufficient input validation, which could allow for arbitrary code execution. This vulnerability can only be exploited if the… | MEDIUM | 6.7 | Nov 11, 2025 |
| CVE-2025-30027 | An ACAP configuration file lacked sufficient input validation, which could allow for arbitrary code execution. This vulnerability can only be exploited if the… | MEDIUM | 6.7 | Aug 12, 2025 |
| CVE-2025-3892 | ACAP applications can be executed with elevated privileges, potentially leading to privilege escalation. This vulnerability can only be exploited if the Axis d… | MEDIUM | 6.7 | Aug 12, 2025 |
| CVE-2025-0358 | During an annual penetration test conducted on behalf of Axis Communication, Truesec discovered a flaw in the VAPIX Device Configuration framework that allowed… | HIGH | 8.8 | Jun 2, 2025 |
| CVE-2025-0325 | A Guard Tour VAPIX API parameter allowed the use of arbitrary values and can be incorrectly called, allowing an attacker to block access to the guard tour conf… | MEDIUM | 4.3 | Jun 2, 2025 |
Showing 1 to 25 of 56 CVEs