Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2819▲ 23 respecto a la semana anterior
Críticas / altas1469▲ 249 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)83▼ 429 respecto a la semana anterior
21 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (7.1) | 0.51% | — | OnyxAI | 4/9/2026 | 23/9/2026 | Onyx 4.6.6 fails to properly restrict access to custom tool credentials stored in custom_headers, allowing any authenticated user to read admin-defined API keys. Attackers with basic authentication can call GET /tool/{tool_id} or GET /tool endpoints to retrieve plaintext authorization headers and third-party API… | |
| Aplazada | Crítica (9.6) | 0.49% | — | OnyxAI | 17/8/2026 | 18/9/2026 | Onyx is an open-source AI platform. Prior to 3.1.10, 3.2.14, and 4.0.0, Onyx's GET /api/mcp/servers and GET /api/mcp/servers/persona/{persona_id} endpoints expose another user's OAuth Authorization header because OnyxTokenStorage.set_tokens and OnyxTokenStorage.set_client_info in… | |
| Aplazada | Media (6.5) | 0.52% | — | OnyxAI | 17/8/2026 | 18/9/2026 | Onyx is an open-source AI platform. Prior to 4.3.0, Onyx Enterprise Edition's PATCH /manage/admin/user-group/{user_group_id} and POST /manage/admin/user-group/{user_group_id}/add-users endpoints in ee/onyx/server/user_group/api.py call update_user_group and add_users_to_user_group in ee/onyx/db/user_group.py without… | |
| Analizada | Media (6.5) | 0.34% | — | Onyx | 8/5/2026 | 17/6/2026 | Onyx is an open-source AI platform. Prior to versions 3.0.9, 3.1.6, and 3.2.6, the GET /chat/file/{file_id} endpoint allows any authenticated user to download any other user's uploaded files by providing the file UUID. The endpoint verifies the caller is authenticated but never checks that the file belongs to them. An… | |
| Analizada | Media (4.3) | 0.43% | — | Onyx | 8/5/2026 | 17/6/2026 | Onyx is an open-source AI platform. Prior to versions 3.0.9, 3.1.6, and 3.2.6, the POST /chat/stop-chat-session/{chat_session_id} endpoint lets any authenticated user stop any other user's active chat session. The endpoint checks authentication but never verifies the session belongs to the caller. An attacker who… | |
| Modificada | Media (6.9) | 0.73% | — | Webonyx Graphql-php | 17/4/2026 | 14/9/2026 | graphql-go is a Go implementation of GraphQL. In versions 15.31.4 and below, the OverlappingFieldsCanBeMerged validation rule performs O(n²) pairwise comparisons of fields sharing the same response name. An attacker can send a query with thousands of repeated identical fields, causing excessive CPU usage during… | |
| Aplazada | Alta (8.1) | 0.53% | — | Ancorathemes MonyxiAI | 18/12/2025 | 17/6/2026 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in AncoraThemes Monyxi monyxi allows PHP Local File Inclusion.This issue affects Monyxi: from n/a through <= 1.1.8. | |
| Aplazada | Crítica (9.4) | 0.35% | — | Onyxia-apiAIKubernetesAIHelmAI | 5/9/2025 | 17/6/2026 | Onyxia is a data science environment for kubernetes. In versions 4.6.0 through 4.8.0, Onyxia-API leaked the credentials of private helm repositories in the public (unauthenticated) /public/catalogs endpoint.vOnly instances using private helm repositories (i.e setting username & password in the catalogs configuration)… | |
| Analizada | Media (5.4) | 0.29% | — | Onyx | 22/7/2025 | 17/6/2026 | Authorization bypass in update_user_group in onyx-dot-app Onyx Enterprise Edition 0.27.0 allows remote authenticated attackers to modify arbitrary user groups via crafted PATCH requests to the /api/manage/admin/user-group/id endpoint, bypassing intended curator-group assignment checks. | |
| Analizada | Baja (2.1) | 0.52% | — | Onyx | 20/7/2025 | 17/6/2026 | A vulnerability, which was classified as critical, has been found in Onyx up to 0.29.1. This issue affects the function generate_simple_sql of the file backend/onyx/agents/agent_search/kb_search/nodes/a3_generate_simple_sql.py of the component Chat Interface. The manipulation leads to sql injection. The attack may be… | |
| Aplazada | Media (6.4) | 0.27% | — | ACF Onyx PollAI | 13/6/2025 | 17/6/2026 | The ACF Onyx Poll plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘class’ parameter in all versions up to, and including, 1.1.9 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject… | |
| Analizada | Media (6.5) | 0.72% | — | Onyx | 20/3/2025 | 17/6/2026 | In danswer-ai/danswer v0.3.94, administrators can set the visibility of pages within a workspace, including the search page. When the search page is set to be invisible, regular users cannot view the search page or access its functionalities from the front-end interface. However, the back-end does not verify the… | |
| Modificada | Alta (8.1) | 0.59% | — | Onyx | 20/3/2025 | 17/6/2026 | An improper access control vulnerability exists in danswer-ai/danswer version v0.3.94. This vulnerability allows the first user created in the system to view, modify, and delete chats created by an Admin. This can lead to unauthorized access to sensitive information, loss of data integrity, and potential compliance… | |
| Aplazada | Crítica (9.4) | 0.65% | — | Onyxia-apiAI | 20/12/2024 | 17/6/2026 | Onyxia is a web app that aims at being the glue between multiple open source backend technologies to provide a state of art working environment for data scientists. This critical vulnerability allows authenticated users to remotely execute code within the Onyxia-API, leading to potential consequences such as… | |
| Analizada | Alta (8.8) | 1.1% | — | Nvidia Mlnx-osNvidia OnyxNvidia Mlnx-gwNvidia Nvda-os XC | 12/8/2024 | 17/6/2026 | NVIDIA Mellanox OS, ONYX, Skyway, and MetroX-3 XCC contain a vulnerability in the web support, where an attacker can cause a CGI path traversal by a specially crafted URI. A successful exploit of this vulnerability might lead to escalation of privileges and information disclosure. | |
| Analizada | Alta (8.8) | 0.27% | — | Nvidia OnyxNvidia Mlnx-osNvidia Mlnx-gwNvidia Nvda-os XC | 8/8/2024 | 17/6/2026 | NVIDIA Mellanox OS, ONYX, Skyway, MetroX-2 and MetroX-3 XC contain a vulnerability in the LDAP AAA component, where a user can cause improper access. A successful exploit of this vulnerability might lead to information disclosure, data tampering, and escalation of privileges. | |
| Analizada | Alta (7.5) | 0.53% | — | Nvidia Mlnx-osNvidia Mlnx-gwNvidia OnyxNvidia Nvda-os XC | 8/8/2024 | 17/6/2026 | NVIDIA Mellanox OS, ONYX, Skyway, MetroX-2 and MetroX-3 XC contain a vulnerability in ipfilter, where improper ipfilter definitions could enable an attacker to cause a failure by attacking the switch. A successful exploit of this vulnerability might lead to denial of service. | |
| Modificada | Alta (7.5) | 0.56% | — | Plesk Onyx | 22/9/2023 | 17/6/2026 | Plesk Onyx 17.8.11 has accessKeyId and secretAccessKey fields that are related to an Amazon AWS Firehose component. NOTE: the vendor's position is that there is no security threat. | |
| Modificada | Crítica (9.3) | 1.5% | — | Onyxforum Project Onyxforum | 11/7/2022 | 17/6/2026 | The ChaoticOnyx/OnyxForum repository before 2022-05-04 on GitHub allows absolute path traversal because the Flask send_file function is used unsafely. | |
| Modificada | Media (6.1) | 0.91% | — | Plesk Onyx | 3/8/2020 | 17/6/2026 | A GET-based XSS reflected vulnerability in Plesk Onyx 17.8.11 allows remote unauthenticated users to inject arbitrary JavaScript, HTML, or CSS via a GET parameter. | |
| Modificada | Media (6.5) | 0.64% | — | Blueonyx 5209r Firmware | 5/5/2020 | 17/6/2026 | CSRF in the /login URI in BlueOnyx 5209R allows an attacker to access the dashboard and perform scraping or other analysis. |