CVE-2025-5454Medium· 6.4▾ SunlitAn ACAP configuration file lacked sufficient input validation, which could allow a path traversal attack leading to potential privilege escalation. This vulnerability can only be exploited if the Axis device is configured to allow the in…
▾ Sunlit zone — Low / medium · no exploitation signal
impact 35.2 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
Last analysed / modified upstream
0.2%
An ACAP configuration file lacked sufficient input validation, which could allow a path traversal attack leading to potential privilege escalation. This vulnerability can only be exploited if the Axis device is configured to allow the installation of unsigned ACAP applications, and if an attacker convinces the victim to install a malicious ACAP application.
axis_os >= 12.0.0, < 12.6.18Upgrade past the affected range:
axis_os 12.6.18Connected by shared product, vendor, weakness, or advisory.
CVE-2025-58972High· 7.2Path Traversal: '.../...//' vulnerability in Dmitry V
CVE-2025-48090High· 8.1Path Traversal: '.../...//' vulnerability in CocoBasic Blanka - One Page WordPress Theme blanka-wp allows PHP Local File Inclusion.This issue affects Blanka - One Page WordPress Theme: from n/a through < 1.5.
CVE-2025-22288Medium· 4.1Path Traversal: '.../...//' vulnerability in WPMU DEV - Your All-in-One WordPress Platform Smush Image Compression and Optimization wp-smushit allows Path Traversal.This issue affects Smush Image Compression and Optimization: from n/a th…
CVE-2026-5703High· 7.1Path traversal vulnerability in the Satel Iberia SenNet Datalogger Serie 200, specifically in the web portal provided by the device, which allows an authenticated user to read any file or list any directory accessible to the system user …
CVE-2026-105683Low· 3.8Ghost is a Node.js content management system
CVE-2025-60835High· 7.8An issue in the unrar.dll component of IZArc v4.6 allows attackers to execute a path traversal.