Skip to content
Noroxi

onenav records

7 published records for vendor onenav.

Researcher profile

Entered KEV
0 · 0%
Weaponized
0 · 0%
Pre-auth RCE
0
With a fix record
0%
Median publish → KEV
No record has entered KEV

All records

7 records
  • CVE-2023-7210
    39Monitor

    OneNav API improper authentication

    CriticalCVSS 9.8No exploitEPSS 1%

    onenav · onenavJan 7, 2024

  • OneNav 0.9.12 allows Information Disclosure of the onenav.db3 contents.

    HighCVSS 7.5No exploitEPSS 1%

    onenav · onenavAug 16, 2021

  • OneNav v0.9.35-20240318 was discovered to contain a Server-Side Request Forgery (SSRF) via the component /index.php?c=api&method=get_link_in

    MediumCVSS 6.3Proof of conceptEPSS 1%

    Apr 30, 2024

  • OneNav 1.1.0 is vulnerable to Cross Site Scripting (XSS) in custom headers.

    MediumCVSS 5.5No exploitEPSS 0%

    onenav · onenavMar 28, 2025

  • OneNav beta 0.9.12 allows XSS via the Add Link feature.

    MediumCVSS 5.4No exploitEPSS 2%

    onenav · onenavAug 5, 2021

  • An issue in index.php of OneNav v0.9.14 allows attackers to perform directory traversal.

    MediumCVSS 5.3No exploitEPSS 1%

    onenav · onenavMar 11, 2022

  • OneNav 1.1.0 is vulnerable to Server-Side Request Forgery (SSRF) in custom headers.

    MediumCVSS 5.4No exploitEPSS 0%

    onenav · onenavMar 28, 2025