AxxonSoft Limited develops a narrow portfolio of video-management and physical-security software, including its flagship Axxon One and Next platforms, which occupy a specialized role in surveillance and access-control infrastructure. Vulnerabilities affecting the vendor skew toward serious outcomes and frequently acquire public exploit code; the recurring weakness classes—including authentication bypass, path traversal, sensitive-information exposure, and memory-safety flaws—reflect the authentication boundaries and file-access control inherent to a networked security appliance. Defenders managing these platforms should treat disclosed vulnerabilities as urgent; live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by AxxonSoft Limited over time
Of all the CVEs published by AxxonSoft Limited as a CNA, 100.0% affect products that AxxonSoft Limited develops as a vendor.
Of all the CVEs published that affect products developed by AxxonSoft Limited, 88.9% are self-published by AxxonSoft Limited as a CNA.
Signals from CVEs in this vendor scope (9 CVEs).
9 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2018-7467HIGH AxxonSoft Axxon Next has Directory Traversal via an initial /css//..%2f substring in a URI. | Feb 27, 2018 | 7.5 | 40 | NO | YES |
CVE-2025-10226CRITICAL Dependency on Vulnerable Third-Party Component (CWE-1395) in the PostgreSQL backend in AxxonSoft Axxon One (C-Werk) 2.0.8 and earlier on Windows and Linux allows a remote attacker | Sep 10, 2025 | 9.8 | 33 | NO | NO |
CVE-2025-10220CRITICAL Use of Unmaintained Third Party Components (CWE-1104) in the NuGet dependency components in AxxonSoft Axxon One VMS 2.0.0 through 2.0.4 on Windows allows a remote attacker to execu | Sep 10, 2025 | 9.8 | 33 | NO | NO |
CVE-2025-10225HIGH Improper Restriction of Operations within the Bounds of a Memory Buffer (CWE-119) in the OpenSSL-based session module in AxxonSoft Axxon One (C-Werk) 2.0.6 and earlier on Windows a | Sep 10, 2025 | 7.5 | 25 | NO | NO |
CVE-2025-10223HIGH Insufficient Session Expiration (CWE-613) in the Web Admin Panel in AxxonSoft Axxon One (C-Werk) prior to 2.0.3 on Windows allows a local or remote authenticated attacker to retain | Sep 10, 2025 | 8.1 | 25 | NO | NO |
CVE-2025-10224HIGH Improper Authentication (CWE-287) in the LDAP authentication engine in AxxonSoft Axxon One (C-Werk) 2.0.2 and earlier on Windows allows a remote authenticated user to be denied acc | Sep 10, 2025 | 7.1 | 24 | NO | NO |
CVE-2025-10221MEDIUM Insertion of Sensitive Information into Log File (CWE-532) in the ARP Agent component in AxxonSoft Axxon One / AxxonNet / C-WerkNet 2.0.4 and earlier on Windows platforms allows a | Sep 10, 2025 | 5.5 | 20 | NO | NO |
CVE-2025-10227MEDIUM Missing Encryption of Sensitive Data (CWE-311) in the Object Archive component in AxxonSoft Axxon One (C-Werk) before 2.0.8 on Windows and Linux allows a local attacker with acces | Sep 10, 2025 | 4.6 | 19 | NO | NO |
Exposure of Sensitive Information to an Unauthorized Actor (CWE-200) in the diagnostic dump component in AxxonSoft Axxon One VMS (C-Werk) 2.0.0 through 2.0.1 on Windows allows a lo | Sep 10, 2025 | 3.3 | 16 | NO | NO |
Signals from CVEs in this vendor scope (9 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by AxxonSoft Limited.
Media articles that mention a CVE ID that affects a product developed by AxxonSoft Limited — matched by CVE ID, not by vendor name.