Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2624▼ 223 respecto a la semana anterior
Críticas / altas1373▲ 144 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)81▼ 449 respecto a la semana anterior
–

9 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaBaja (2.7)0.31%—OnenavAI15/9/202622/9/2026
OneNav v1.2.4 contains an authenticated arbitrary file deletion vulnerability in the Api::upload() method in class/Api.php. An authenticated administrator can submit a non-HTML upload filename matching an existing file in the application's working directory. The application passes the user-controlled filename to…
Pendiente de análisisAlta (8.1)0.46%—OnenavAI24/8/20269/9/2026
OneNav 1.2.4 contains an authenticated arbitrary file deletion vulnerability via import_link().
AnalizadaMedia (5.5)0.21%—Onenav28/3/202517/6/2026
OneNav 1.1.0 is vulnerable to Cross Site Scripting (XSS) in custom headers.
AnalizadaMedia (5.4)0.23%—Onenav28/3/202517/6/2026
OneNav 1.1.0 is vulnerable to Server-Side Request Forgery (SSRF) in custom headers.
AplazadaMedia (6.3)0.72%—OnenavAI30/4/202417/6/2026
OneNav v0.9.35-20240318 was discovered to contain a Server-Side Request Forgery (SSRF) via the component /index.php?c=api&method=get_link_info.
ModificadaCrítica (9.8)0.98%—Onenav7/1/202417/6/2026
A vulnerability was found in OneNav up to 0.9.33. It has been classified as critical. This affects an unknown part of the file /index.php?c=api of the component API. The manipulation of the argument X-Token leads to improper authentication. It is possible to initiate the attack remotely. The exploit has been disclosed…
ModificadaMedia (5.3)1.2%—Onenav12/3/202217/6/2026
An issue in index.php of OneNav v0.9.14 allows attackers to perform directory traversal.
ModificadaAlta (7.5)1.1%—Onenav16/8/202117/6/2026
OneNav 0.9.12 allows Information Disclosure of the onenav.db3 contents. NOTE: the vendor's recommended solution is to block the access via an NGINX configuration file.
ModificadaMedia (5.4)1.5%—Onenav5/8/202117/6/2026
OneNav beta 0.9.12 allows XSS via the Add Link feature. NOTE: the vendor's position is that there intentionally is not any XSS protection at present, because the attack risk is largely limited to a compromised account; however, XSS protection is planned for a future release.