AxxonSoft Limited

First CVE: Sep 10, 2025Active for: 1 year
8
CVEs Published
More CVEs Published than 22% of tracked CNAs
8.0
Avg CVEs / Year
More Avg CVEs / Year than 47% of tracked CNAs
7.0
Avg CVSS Score
Higher Avg CVSS Score than 41% of tracked CNAs
0.0%
In CISA KEV
Bottom 1%

Self-Reporting Analysis

Of all the CVEs published by AxxonSoft Limited as a CNA, 100.0% affect products that AxxonSoft Limited develops as a vendor.

100.0%
Self-reported: 8Third-party: 0

Of all the CVEs published that affect products developed by AxxonSoft Limited, 88.9% are self-published by AxxonSoft Limited as a CNA.

88.9%
11.1%
Self-published: 8Published by other CNAs: 1

Trends Over Time

The number and severity of CVEs published by AxxonSoft Limited over time

Volume of CVEsAvg CVSS Base Score
First CVE
Sep 10, 2025
10 months ago
Most Recent CVE
Sep 10, 2025
317 days ago

Top CVEs

All CVEs published by AxxonSoft Limited as a CNA, regardless of affected vendor or product.

8 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
Dependency on Vulnerable Third-Party Component (CWE-1395) in the PostgreSQL backend in AxxonSoft Axxon One (C-Werk) 2.0.8 and earlier on Windows and Linux allows a remote attacker
Sep 10, 20259.833NONO
Use of Unmaintained Third Party Components (CWE-1104) in the NuGet dependency components in AxxonSoft Axxon One VMS 2.0.0 through 2.0.4 on Windows allows a remote attacker to execu
Sep 10, 20259.833NONO
Improper Restriction of Operations within the Bounds of a Memory Buffer (CWE-119) in the OpenSSL-based session module in AxxonSoft Axxon One (C-Werk) 2.0.6 and earlier on Windows a
Sep 10, 20257.525NONO
Insufficient Session Expiration (CWE-613) in the Web Admin Panel in AxxonSoft Axxon One (C-Werk) prior to 2.0.3 on Windows allows a local or remote authenticated attacker to retain
Sep 10, 20258.125NONO
Improper Authentication (CWE-287) in the LDAP authentication engine in AxxonSoft Axxon One (C-Werk) 2.0.2 and earlier on Windows allows a remote authenticated user to be denied acc
Sep 10, 20257.124NONO
Insertion of Sensitive Information into Log File (CWE-532) in the ARP Agent component in AxxonSoft Axxon One / AxxonNet / C-WerkNet 2.0.4 and earlier on Windows platforms allows a
Sep 10, 20255.520NONO
Missing Encryption of Sensitive Data (CWE-311) in the Object Archive component in AxxonSoft Axxon One (C-Werk) before 2.0.8 on Windows and Linux allows a local attacker with acces
Sep 10, 20254.619NONO
Exposure of Sensitive Information to an Unauthorized Actor (CWE-200) in the diagnostic dump component in AxxonSoft Axxon One VMS (C-Werk) 2.0.0 through 2.0.1 on Windows allows a lo
Sep 10, 20253.316NONO

CVE Severity & Scoring

Severity distribution of CVEs published by this CNA8 CVEs
Severity distribution among all CVEs352,231 CVEs
LowMediumHighCritical
Attack Vector
Local2 (25.0%)
Network5 (62.5%)
Unknown0 (0.0%)
Physical1 (12.5%)
Adjacent Network0 (0.0%)
Attack Complexity
Low8 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None8 (100.0%)
Unknown0 (0.0%)
Required0 (0.0%)
Privileges Required
Low4 (50.0%)
High0 (0.0%)
None4 (50.0%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this cna scope (8 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

An overview of all social media posts that mention a CVE ID published by AxxonSoft Limited as a CNA.

Media Mentions

Media articles that mention a CVE ID published by AxxonSoft Limited as a CNA — matched by CVE ID, not by organization name.

Top Affected Vendors

Top Affected Products

Top CWEs