VulnSea

axxonsoft has 6 CVEs on record. The median CVSS is 5.5 (medium), with 1 rated critical. None have a confirmed exploitation report.

CVEs per month

Last 12 months, by publish date

101112010203040506070809
Exploited share
0% vs 1% corpus
Median CVSS
5.5
Publish → KEV
—
Last 90 days
0 prev 0

Products

  • axxon_one 6
6
Total CVEs
1
Critical
0
CISA KEV
0
Exploited

axxonsoft vulnerabilities

CVEs affecting axxonsoft, newest first. Open any entry for full detail, references, and exploit status.

6 CVEsRSS

CVE-2025-10227Medium· 4.6
1y ago

Missing Encryption of Sensitive Data (CWE-311) in the Object Archive component in AxxonSoft Axxon One (C-Werk) before 2.0.8 on Windows and Linux allows a local attacker with access to exported storage or stolen physical drives to extrac…

Missing Encryption of Sensitive Data (CWE-311) in the Object Archive component in AxxonSoft Axxon One (C-Werk) before 2.0.8 on Windows and Linux allows a local attacker with access to exported storage or stolen physical drives to extrac…

▾ Sunlitaxxonsoft · axxon_oneEPSS 0.08%via NVD
CVE-2025-10225High· 7.5
1y ago

Improper Restriction of Operations within the Bounds of a Memory Buffer (CWE-119) in the OpenSSL-based session module in AxxonSoft Axxon One (C-Werk) 2.0.6 and earlier on Windows allows a remote attacker under high load conditions to cau…

Improper Restriction of Operations within the Bounds of a Memory Buffer (CWE-119) in the OpenSSL-based session module in AxxonSoft Axxon One (C-Werk) 2.0.6 and earlier on Windows allows a remote attacker under high load conditions to cau…

▾ Twilightaxxonsoft · axxon_oneEPSS 0.40%via NVD
CVE-2025-10223Medium· 5.4
1y ago

Insufficient Session Expiration (CWE-613) in the Web Admin Panel in AxxonSoft Axxon One (C-Werk) prior to 2.0.3 on Windows allows a local or remote authenticated attacker to retain access with removed privileges via continued use of an u…

Insufficient Session Expiration (CWE-613) in the Web Admin Panel in AxxonSoft Axxon One (C-Werk) prior to 2.0.3 on Windows allows a local or remote authenticated attacker to retain access with removed privileges via continued use of an u…

▾ Sunlitaxxonsoft · axxon_oneEPSS 0.25%via NVD
CVE-2025-10222Low· 3.3
1y ago

Exposure of Sensitive Information to an Unauthorized Actor (CWE-200) in the diagnostic dump component in AxxonSoft Axxon One VMS (C-Werk) 2.0.0 through 2.0.1 on Windows allows a local attacker to obtain licensing-related information such…

Exposure of Sensitive Information to an Unauthorized Actor (CWE-200) in the diagnostic dump component in AxxonSoft Axxon One VMS (C-Werk) 2.0.0 through 2.0.1 on Windows allows a local attacker to obtain licensing-related information such…

▾ Sunlitaxxonsoft · axxon_oneEPSS 0.12%via NVD
CVE-2025-10221Medium· 5.5
1y ago

Insertion of Sensitive Information into Log File (CWE-532) in the ARP Agent component in AxxonSoft Axxon One / AxxonNet / C-WerkNet 2.0.4 and earlier on Windows platforms allows a local attacker to obtain plaintext credentials via readin…

Insertion of Sensitive Information into Log File (CWE-532) in the ARP Agent component in AxxonSoft Axxon One / AxxonNet / C-WerkNet 2.0.4 and earlier on Windows platforms allows a local attacker to obtain plaintext credentials via readin…

▾ Sunlitaxxonsoft · axxon_oneEPSS 0.13%via NVD
CVE-2025-10220Critical· 9.8
1y ago

Use of Unmaintained Third Party Components (CWE-1104) in the NuGet dependency components in AxxonSoft Axxon One VMS 2.0.0 through 2.0.4 on Windows allows a remote attacker to execute arbitrary code or bypass security features via exploit…

Use of Unmaintained Third Party Components (CWE-1104) in the NuGet dependency components in AxxonSoft Axxon One VMS 2.0.0 through 2.0.4 on Windows allows a remote attacker to execute arbitrary code or bypass security features via exploit…

▾ Midnightaxxonsoft · axxon_oneEPSS 0.73%via NVD
axxonsoft vulnerabilities (CVEs) · VulnSea