Vulnerabilities

Summary — last 7 days

New vulnerabilities2,723▼ 18 vs. last week
Critical / high1,271▼ 242 vs. last week
New active exploitation (KEV)6▼ 1 vs. last week
Unscored (no CVSS)230▲ 212 vs. last week
–

25 results, sorted by published date (most recent first)

CVEStatusSeverityEPSS Active exploitationAffected technologiesPublished ▼Modified Description
DeferredMedium (5.4)0.40%—OnionshareAI7/31/20269/10/2026
OnionShare is an open source tool that lets you securely and anonymously share files, host websites, and chat with friends using the Tor network. Prior to 2.6.4, OnionShare CLI/Desktop does not enforce the Receive mode disable_files setting in cli/onionshare_cli/web/receive_mode.py, where…
DeferredMedium (4.8)0.34%—OnionshareAI7/31/20269/10/2026
OnionShare is an open source tool that lets you securely and anonymously share files, host websites, and chat with friends using the Tor network. Prior to 2.6.4, OnionShare CLI/Desktop follows symbolic links in cli/onionshare_cli/web/send_base_mode.py through SendBaseModeWeb.set_file_info() and…
DeferredHigh (8.7)0.34%—Onion-site-templateAI8/6/20256/17/2026
onion-site-template is a complete, scalable tor hidden service self-hosting sample. Versions which include commit 3196bd89 contain a baked-in tor image if the secrets were copied from an existing onion domain. A website could be compromised if a user shared the baked-in image, or if someone were able to acquire access…
DeferredHigh (7.1)0.12%—Looks Awesome Onionbuzz Viral QuizAI6/27/20256/17/2026
Cross-Site Request Forgery (CSRF) vulnerability in Looks Awesome OnionBuzz onionbuzz-viral-quiz allows Stored XSS.This issue affects OnionBuzz: from n/a through <= 1.0.7.
ModifiedHigh (8.2)1.1%—Mozilla FirefoxOnion Project Onion11/19/20226/17/2026
A vulnerability was found in davidmoreno onion. It has been rated as problematic. Affected by this issue is the function onion_response_flush of the file src/onion/response.c of the component Log Handler. The manipulation leads to allocation of resources. The name of the patch is…
ModifiedMedium (5.3)1.3%—Onionshare1/18/20226/17/2026
OnionShare is an open source tool that lets you securely and anonymously share files, host websites, and chat with friends using the Tor network. The website mode of the onionshare allows to use a hardened CSP, which will block any scripts and external resources. It is not possible to configure this CSP for individual…
ModifiedMedium (4.3)0.78%—Onionshare1/18/20226/17/2026
OnionShare is an open source tool that lets you securely and anonymously share files, host websites, and chat with friends using the Tor network. In affected versions anyone with access to the chat environment can write messages disguised as another chat participant.
ModifiedMedium (5.4)0.80%—Onionshare1/18/20226/17/2026
OnionShare is an open source tool that lets you securely and anonymously share files, host websites, and chat with friends using the Tor network. In affected versions The path parameter of the requested URL is not sanitized before being passed to the QT frontend. This path is used in all components for displaying the…
ModifiedMedium (5.3)0.86%—Onionshare1/18/20226/17/2026
OnionShare is an open source tool that lets you securely and anonymously share files, host websites, and chat with friends using the Tor network. In affected versions authenticated users (or unauthenticated in public mode) can send messages without being visible in the list of chat participants. This issue has been…
AnalyzedMedium (6.5)1.2%—Onionshare1/18/20226/17/2026
OnionShare is an open source tool that lets you securely and anonymously share files, host websites, and chat with friends using the Tor network. In affected versions an adversary with a primitive that allows for filesystem access from the context of the Onionshare process can access sensitive files in the entire user…
ModifiedMedium (4.3)0.68%—Onionshare1/18/20226/17/2026
OnionShare is an open source tool that lets you securely and anonymously share files, host websites, and chat with friends using the Tor network. In affected versions chat participants can spoof their channel leave message, tricking others into assuming they left the chatroom.
ModifiedHigh (7.5)1.3%—Onionshare1/18/20226/17/2026
OnionShare is an open source tool that lets you securely and anonymously share files, host websites, and chat with friends using the Tor network. In affected versions the receive mode limits concurrent uploads to 100 per second and blocks other uploads in the same second, which can be triggered by a simple script. An…
ModifiedMedium (5.5)0.79%—Onionshare1/18/20226/17/2026
OnionShare is an open source tool that lets you securely and anonymously share files, host websites, and chat with friends using the Tor network. Affected versions of the desktop application were found to be vulnerable to denial of service via an undisclosed vulnerability in the QT image parsing. Roughly 20 bytes lead…
ModifiedMedium (4.3)0.71%—Onionshare1/18/20226/17/2026
OnionShare is an open source tool that lets you securely and anonymously share files, host websites, and chat with friends using the Tor network. In affected versions it is possible to change the username to that of another chat participant with an additional space character at the end of the name string. An adversary…
ModifiedCritical (9.8)2.4%—Onionshare10/4/20216/17/2026
OnionShare 2.3 before 2.4 allows remote unauthenticated attackers to upload files on a non-public node when using the --receive functionality.
ModifiedMedium (5.3)1.8%—Onionshare10/4/20216/17/2026
An information disclosure vulnerability in OnionShare 2.3 before 2.4 allows remote unauthenticated attackers to retrieve the full list of participants of a non-public OnionShare node via the --chat feature.
ModifiedCritical (9.8)3.0%—Onion-oled-js Project Onion-oled-js4/18/20216/17/2026
This affects all versions of package onion-oled-js. If attacker-controlled user input is given to the scroll function, it is possible for an attacker to execute arbitrary commands. This is due to use of the child_process exec function without input sanitization.
ModifiedHigh (7.8)0.53%—Securityonionsolutions Security Onion11/23/20206/17/2026
Security Onion v2 prior to 2.3.10 has an incorrect sudo configuration, which allows the administrative user to obtain root access without using the sudo password by editing and executing /home/<user>/SecurityOnion/setup/so-setup.
ModifiedCritical (9.8)4.6%—Onionbuzz7/21/20196/17/2026
An issue was discovered in the Viral Quiz Maker - OnionBuzz plugin before 1.2.2 for WordPress. One could exploit the points parameter in the ob_get_results ajax nopriv handler due to there being no sanitization prior to use in a SQL query in getResultByPointsTrivia. This allows an unauthenticated/unprivileged user to…
ModifiedCritical (9.8)4.6%—Onionbuzz7/21/20196/17/2026
An issue was discovered in the Viral Quiz Maker - OnionBuzz plugin before 1.2.7 for WordPress. One could exploit the id parameter in the set_count ajax nopriv handler due to there being no sanitization prior to use in a SQL query in saveQuestionVote. This allows an unauthenticated/unprivileged user to perform a SQL…
ModifiedHigh (7)0.34%—Onionshare12/7/20186/17/2026
The debug_mode function in web/web.py in OnionShare through 1.3.1, when --debug is enabled, uses the /tmp/onionshare_server.log pathname for logging, which might allow local users to overwrite files or obtain sensitive information by using this pathname.
ModifiedCritical (9.8)1.9%—Securityonion Squert2/9/20186/17/2026
Security Onion Solutions Squert version 1.1.1 through 1.6.7 contains a SQL Injection vulnerability in .inc/callback.php that can result in execution of SQL commands. This attack appear to be exploitable via Web request to .inc/callback.php with the payload in the sensors parameter, used in ec(). This vulnerability…
ModifiedCritical (9.8)3.9%—Securityonion Squert2/9/20186/17/2026
Security Onion Solutions Squert version 1.0.1 through 1.6.7 contains a CWE-78: Improper Neutralization of Special Elements used in an OS Command (OS Command Injection) vulnerability in .inc/callback.php that can result in execution of OS Commands. This attack appear to be exploitable via Web request to…
ModifiedCritical (9.8)3.9%—Securityonion Squert2/9/20186/17/2026
Security Onion Solutions Squert version 1.3.0 through 1.6.7 contains a CWE-78: Improper Neutralization of Special Elements used in an OS Command (OS Command Injection) vulnerability in .inc/callback.php that can result in execution of OS Commands. This attack appear to be exploitable via Web request to…
ModifiedMedium (5.5)0.33%—Onionshare1/30/20176/17/2026
hs.py in OnionShare before 0.9.1 allows local users to modify the hiddenservice by pre-creating the /tmp/onionshare directory.
Orbitaley — Vulnerabilities