Axis Communications AB
Self-Reporting Analysis
Of all the CVEs published by Axis Communications AB as a CNA, 69.8% affect products that Axis Communications AB develops as a vendor.
Of all the CVEs published that affect products developed by Axis Communications AB, 60.0% are self-published by Axis Communications AB as a CNA.
Trends Over Time
The number and severity of CVEs published by Axis Communications AB over time
Top CVEs
All CVEs published by Axis Communications AB as a CNA, regardless of affected vendor or product.
86 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-1185HIGH A configuration file on the local file system had improper input validation which could allow code execution and potentially lead to privilege escalation. This vulnerability can on | May 12, 2026 | 8.8 | 32 | NO | NO |
CVE-2017-20049CRITICAL A vulnerability, was found in legacy Axis devices such as P3225 and M3005. This affects an unknown part of the component CGI Script. The manipulation leads to improper privilege ma | Jun 15, 2022 | 9.8 | 32 | NO | NO |
CVE-2025-30026CRITICAL The AXIS Camera Station Server had a flaw that allowed
to bypass authentication that is normally required. | Jul 11, 2025 | 9.8 | 30 | NO | NO |
CVE-2023-21412HIGH User provided input is not sanitized on the AXIS License Plate Verifier specific “search.cgi” allowing for
SQL injections. | Aug 3, 2023 | 8.8 | 30 | NO | NO |
CVE-2025-30023CRITICAL The communication protocol used between client and server had a flaw that could lead to an authenticated user performing a remote code execution attack. | Jul 11, 2025 | 9.0 | 29 | NO | NO |
CVE-2026-0804HIGH An ACAP configuration file lacked sufficient input validation, which could allow a path traversal attack leading to potential privilege escalation. This vulnerability can only be e | May 12, 2026 | 7.3 | 28 | NO | NO |
CVE-2026-0802HIGH An ACAP configuration file lacked sufficient input validation, which could allow command injection and potentially lead to privilege escalation. This vulnerability can only be expl | May 12, 2026 | 7.3 | 28 | NO | NO |
CVE-2026-0541HIGH ACAP applications can gain elevated privileges due to improper input validation during the installation process, potentially leading to privilege escalation. This vulnerability can | May 12, 2026 | 7.3 | 28 | NO | NO |
CVE-2025-11142HIGH The VAPIX API mediaclip.cgi that did not have a sufficient input validation allowing for a possible remote code execution. This flaw can only be exploited after authenticating with | Feb 10, 2026 | 8.8 | 28 | NO | NO |
CVE-2023-5800HIGH Vintage,
member of the AXIS OS Bug Bounty Program, has found that the VAPIX API create_overlay.cgi
did not have a sufficient input validation allowing for a possible remote code
ex | Feb 5, 2024 | 8.8 | 28 | NO | NO |
CVE Severity & Scoring
Exploit Exposure
Signals from CVEs in this cna scope (86 CVEs).
Social Chatter
An overview of all social media posts that mention a CVE ID published by Axis Communications AB as a CNA.
Media Mentions
Media articles that mention a CVE ID published by Axis Communications AB as a CNA — matched by CVE ID, not by organization name.