Axis Communications AB

First CVE: Aug 25, 2021Active for: 5 years
86
CVEs Published
More CVEs Published than 68% of tracked CNAs
14.3
Avg CVEs / Year
More Avg CVEs / Year than 61% of tracked CNAs
6.8
Avg CVSS Score
Higher Avg CVSS Score than 34% of tracked CNAs
0.0%
In CISA KEV
Bottom 1%

Self-Reporting Analysis

Of all the CVEs published by Axis Communications AB as a CNA, 69.8% affect products that Axis Communications AB develops as a vendor.

69.8%
30.2%
Self-reported: 60Third-party: 26

Of all the CVEs published that affect products developed by Axis Communications AB, 60.0% are self-published by Axis Communications AB as a CNA.

60.0%
40.0%
Self-published: 60Published by other CNAs: 40

Trends Over Time

The number and severity of CVEs published by Axis Communications AB over time

Volume of CVEsAvg CVSS Base Score
First CVE
Aug 25, 2021
4 years ago
Most Recent CVE
May 12, 2026
73 days ago

Top CVEs

All CVEs published by Axis Communications AB as a CNA, regardless of affected vendor or product.

86 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
A configuration file on the local file system had improper input validation which could allow code execution and potentially lead to privilege escalation. This vulnerability can on
May 12, 20268.832NONO
A vulnerability, was found in legacy Axis devices such as P3225 and M3005. This affects an unknown part of the component CGI Script. The manipulation leads to improper privilege ma
Jun 15, 20229.832NONO
The AXIS Camera Station Server had a flaw that allowed to bypass authentication that is normally required.
Jul 11, 20259.830NONO
User provided input is not sanitized on the AXIS License Plate Verifier specific “search.cgi” allowing for SQL injections.
Aug 3, 20238.830NONO
The communication protocol used between client and server had a flaw that could lead to an authenticated user performing a remote code execution attack.
Jul 11, 20259.029NONO
An ACAP configuration file lacked sufficient input validation, which could allow a path traversal attack leading to potential privilege escalation. This vulnerability can only be e
May 12, 20267.328NONO
An ACAP configuration file lacked sufficient input validation, which could allow command injection and potentially lead to privilege escalation. This vulnerability can only be expl
May 12, 20267.328NONO
ACAP applications can gain elevated privileges due to improper input validation during the installation process, potentially leading to privilege escalation. This vulnerability can
May 12, 20267.328NONO
The VAPIX API mediaclip.cgi that did not have a sufficient input validation allowing for a possible remote code execution. This flaw can only be exploited after authenticating with
Feb 10, 20268.828NONO
Vintage, member of the AXIS OS Bug Bounty Program, has found that the VAPIX API create_overlay.cgi did not have a sufficient input validation allowing for a possible remote code ex
Feb 5, 20248.828NONO

CVE Severity & Scoring

Severity distribution of CVEs published by this CNA86 CVEs
Severity distribution among all CVEs352,231 CVEs
LowMediumHighCritical
Attack Vector
Local23 (26.7%)
Network50 (58.1%)
Unknown0 (0.0%)
Physical4 (4.7%)
Adjacent Network9 (10.5%)
Attack Complexity
Low76 (88.4%)
High10 (11.6%)
Unknown0 (0.0%)
User Interaction
None75 (87.2%)
Unknown0 (0.0%)
Required11 (12.8%)
Privileges Required
Low47 (54.7%)
High17 (19.8%)
None22 (25.6%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this cna scope (86 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

An overview of all social media posts that mention a CVE ID published by Axis Communications AB as a CNA.

Media Mentions

Media articles that mention a CVE ID published by Axis Communications AB as a CNA — matched by CVE ID, not by organization name.

Top Affected Vendors

Top Affected Products

Top CWEs