Vulnerabilities
Summary — last 7 days
New vulnerabilities2,723▼ 18 vs. last week
Critical / high1,271▼ 242 vs. last week
New active exploitation (KEV)6▼ 1 vs. last week
Unscored (no CVSS)230▲ 212 vs. last week
25 results, sorted by published date (most recent first)
| CVE | Status | Severity | EPSS | Active exploitation | Affected technologies | Published ▼ | Modified | Description |
|---|---|---|---|---|---|---|---|---|
| Deferred | Medium (5.4) | 0.40% | — | OnionshareAI | 7/31/2026 | 9/10/2026 | OnionShare is an open source tool that lets you securely and anonymously share files, host websites, and chat with friends using the Tor network. Prior to 2.6.4, OnionShare CLI/Desktop does not enforce the Receive mode disable_files setting in cli/onionshare_cli/web/receive_mode.py, where… | |
| Deferred | Medium (4.8) | 0.34% | — | OnionshareAI | 7/31/2026 | 9/10/2026 | OnionShare is an open source tool that lets you securely and anonymously share files, host websites, and chat with friends using the Tor network. Prior to 2.6.4, OnionShare CLI/Desktop follows symbolic links in cli/onionshare_cli/web/send_base_mode.py through SendBaseModeWeb.set_file_info() and… | |
| Deferred | High (8.7) | 0.34% | — | Onion-site-templateAI | 8/6/2025 | 6/17/2026 | onion-site-template is a complete, scalable tor hidden service self-hosting sample. Versions which include commit 3196bd89 contain a baked-in tor image if the secrets were copied from an existing onion domain. A website could be compromised if a user shared the baked-in image, or if someone were able to acquire access… | |
| Deferred | High (7.1) | 0.12% | — | Looks Awesome Onionbuzz Viral QuizAI | 6/27/2025 | 6/17/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Looks Awesome OnionBuzz onionbuzz-viral-quiz allows Stored XSS.This issue affects OnionBuzz: from n/a through <= 1.0.7. | |
| Modified | High (8.2) | 1.1% | — | Mozilla FirefoxOnion Project Onion | 11/19/2022 | 6/17/2026 | A vulnerability was found in davidmoreno onion. It has been rated as problematic. Affected by this issue is the function onion_response_flush of the file src/onion/response.c of the component Log Handler. The manipulation leads to allocation of resources. The name of the patch is… | |
| Modified | Medium (5.3) | 1.3% | — | Onionshare | 1/18/2022 | 6/17/2026 | OnionShare is an open source tool that lets you securely and anonymously share files, host websites, and chat with friends using the Tor network. The website mode of the onionshare allows to use a hardened CSP, which will block any scripts and external resources. It is not possible to configure this CSP for individual… | |
| Modified | Medium (4.3) | 0.78% | — | Onionshare | 1/18/2022 | 6/17/2026 | OnionShare is an open source tool that lets you securely and anonymously share files, host websites, and chat with friends using the Tor network. In affected versions anyone with access to the chat environment can write messages disguised as another chat participant. | |
| Modified | Medium (5.4) | 0.80% | — | Onionshare | 1/18/2022 | 6/17/2026 | OnionShare is an open source tool that lets you securely and anonymously share files, host websites, and chat with friends using the Tor network. In affected versions The path parameter of the requested URL is not sanitized before being passed to the QT frontend. This path is used in all components for displaying the… | |
| Modified | Medium (5.3) | 0.86% | — | Onionshare | 1/18/2022 | 6/17/2026 | OnionShare is an open source tool that lets you securely and anonymously share files, host websites, and chat with friends using the Tor network. In affected versions authenticated users (or unauthenticated in public mode) can send messages without being visible in the list of chat participants. This issue has been… | |
| Analyzed | Medium (6.5) | 1.2% | — | Onionshare | 1/18/2022 | 6/17/2026 | OnionShare is an open source tool that lets you securely and anonymously share files, host websites, and chat with friends using the Tor network. In affected versions an adversary with a primitive that allows for filesystem access from the context of the Onionshare process can access sensitive files in the entire user… | |
| Modified | Medium (4.3) | 0.68% | — | Onionshare | 1/18/2022 | 6/17/2026 | OnionShare is an open source tool that lets you securely and anonymously share files, host websites, and chat with friends using the Tor network. In affected versions chat participants can spoof their channel leave message, tricking others into assuming they left the chatroom. | |
| Modified | High (7.5) | 1.3% | — | Onionshare | 1/18/2022 | 6/17/2026 | OnionShare is an open source tool that lets you securely and anonymously share files, host websites, and chat with friends using the Tor network. In affected versions the receive mode limits concurrent uploads to 100 per second and blocks other uploads in the same second, which can be triggered by a simple script. An… | |
| Modified | Medium (5.5) | 0.79% | — | Onionshare | 1/18/2022 | 6/17/2026 | OnionShare is an open source tool that lets you securely and anonymously share files, host websites, and chat with friends using the Tor network. Affected versions of the desktop application were found to be vulnerable to denial of service via an undisclosed vulnerability in the QT image parsing. Roughly 20 bytes lead… | |
| Modified | Medium (4.3) | 0.71% | — | Onionshare | 1/18/2022 | 6/17/2026 | OnionShare is an open source tool that lets you securely and anonymously share files, host websites, and chat with friends using the Tor network. In affected versions it is possible to change the username to that of another chat participant with an additional space character at the end of the name string. An adversary… | |
| Modified | Critical (9.8) | 2.4% | — | Onionshare | 10/4/2021 | 6/17/2026 | OnionShare 2.3 before 2.4 allows remote unauthenticated attackers to upload files on a non-public node when using the --receive functionality. | |
| Modified | Medium (5.3) | 1.8% | — | Onionshare | 10/4/2021 | 6/17/2026 | An information disclosure vulnerability in OnionShare 2.3 before 2.4 allows remote unauthenticated attackers to retrieve the full list of participants of a non-public OnionShare node via the --chat feature. | |
| Modified | Critical (9.8) | 3.0% | — | Onion-oled-js Project Onion-oled-js | 4/18/2021 | 6/17/2026 | This affects all versions of package onion-oled-js. If attacker-controlled user input is given to the scroll function, it is possible for an attacker to execute arbitrary commands. This is due to use of the child_process exec function without input sanitization. | |
| Modified | High (7.8) | 0.53% | — | Securityonionsolutions Security Onion | 11/23/2020 | 6/17/2026 | Security Onion v2 prior to 2.3.10 has an incorrect sudo configuration, which allows the administrative user to obtain root access without using the sudo password by editing and executing /home/<user>/SecurityOnion/setup/so-setup. | |
| Modified | Critical (9.8) | 4.6% | — | Onionbuzz | 7/21/2019 | 6/17/2026 | An issue was discovered in the Viral Quiz Maker - OnionBuzz plugin before 1.2.2 for WordPress. One could exploit the points parameter in the ob_get_results ajax nopriv handler due to there being no sanitization prior to use in a SQL query in getResultByPointsTrivia. This allows an unauthenticated/unprivileged user to… | |
| Modified | Critical (9.8) | 4.6% | — | Onionbuzz | 7/21/2019 | 6/17/2026 | An issue was discovered in the Viral Quiz Maker - OnionBuzz plugin before 1.2.7 for WordPress. One could exploit the id parameter in the set_count ajax nopriv handler due to there being no sanitization prior to use in a SQL query in saveQuestionVote. This allows an unauthenticated/unprivileged user to perform a SQL… | |
| Modified | High (7) | 0.34% | — | Onionshare | 12/7/2018 | 6/17/2026 | The debug_mode function in web/web.py in OnionShare through 1.3.1, when --debug is enabled, uses the /tmp/onionshare_server.log pathname for logging, which might allow local users to overwrite files or obtain sensitive information by using this pathname. | |
| Modified | Critical (9.8) | 1.9% | — | Securityonion Squert | 2/9/2018 | 6/17/2026 | Security Onion Solutions Squert version 1.1.1 through 1.6.7 contains a SQL Injection vulnerability in .inc/callback.php that can result in execution of SQL commands. This attack appear to be exploitable via Web request to .inc/callback.php with the payload in the sensors parameter, used in ec(). This vulnerability… | |
| Modified | Critical (9.8) | 3.9% | — | Securityonion Squert | 2/9/2018 | 6/17/2026 | Security Onion Solutions Squert version 1.0.1 through 1.6.7 contains a CWE-78: Improper Neutralization of Special Elements used in an OS Command (OS Command Injection) vulnerability in .inc/callback.php that can result in execution of OS Commands. This attack appear to be exploitable via Web request to… | |
| Modified | Critical (9.8) | 3.9% | — | Securityonion Squert | 2/9/2018 | 6/17/2026 | Security Onion Solutions Squert version 1.3.0 through 1.6.7 contains a CWE-78: Improper Neutralization of Special Elements used in an OS Command (OS Command Injection) vulnerability in .inc/callback.php that can result in execution of OS Commands. This attack appear to be exploitable via Web request to… | |
| Modified | Medium (5.5) | 0.33% | — | Onionshare | 1/30/2017 | 6/17/2026 | hs.py in OnionShare before 0.9.1 allows local users to modify the hiddenservice by pre-creating the /tmp/onionshare directory. |