Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2624▼ 223 respecto a la semana anterior
Críticas / altas1373▲ 144 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)81▼ 449 respecto a la semana anterior
9 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Baja (2.7) | 0.31% | — | OnenavAI | 15/9/2026 | 22/9/2026 | OneNav v1.2.4 contains an authenticated arbitrary file deletion vulnerability in the Api::upload() method in class/Api.php. An authenticated administrator can submit a non-HTML upload filename matching an existing file in the application's working directory. The application passes the user-controlled filename to… | |
| Pendiente de análisis | Alta (8.1) | 0.46% | — | OnenavAI | 24/8/2026 | 9/9/2026 | OneNav 1.2.4 contains an authenticated arbitrary file deletion vulnerability via import_link(). | |
| Analizada | Media (5.5) | 0.21% | — | Onenav | 28/3/2025 | 17/6/2026 | OneNav 1.1.0 is vulnerable to Cross Site Scripting (XSS) in custom headers. | |
| Analizada | Media (5.4) | 0.23% | — | Onenav | 28/3/2025 | 17/6/2026 | OneNav 1.1.0 is vulnerable to Server-Side Request Forgery (SSRF) in custom headers. | |
| Aplazada | Media (6.3) | 0.72% | — | OnenavAI | 30/4/2024 | 17/6/2026 | OneNav v0.9.35-20240318 was discovered to contain a Server-Side Request Forgery (SSRF) via the component /index.php?c=api&method=get_link_info. | |
| Modificada | Crítica (9.8) | 0.98% | — | Onenav | 7/1/2024 | 17/6/2026 | A vulnerability was found in OneNav up to 0.9.33. It has been classified as critical. This affects an unknown part of the file /index.php?c=api of the component API. The manipulation of the argument X-Token leads to improper authentication. It is possible to initiate the attack remotely. The exploit has been disclosed… | |
| Modificada | Media (5.3) | 1.2% | — | Onenav | 12/3/2022 | 17/6/2026 | An issue in index.php of OneNav v0.9.14 allows attackers to perform directory traversal. | |
| Modificada | Alta (7.5) | 1.1% | — | Onenav | 16/8/2021 | 17/6/2026 | OneNav 0.9.12 allows Information Disclosure of the onenav.db3 contents. NOTE: the vendor's recommended solution is to block the access via an NGINX configuration file. | |
| Modificada | Media (5.4) | 1.5% | — | Onenav | 5/8/2021 | 17/6/2026 | OneNav beta 0.9.12 allows XSS via the Add Link feature. NOTE: the vendor's position is that there intentionally is not any XSS protection at present, because the attack risk is largely limited to a compromised account; however, XSS protection is planned for a future release. |