onenav records
7 published records for vendor onenav.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 0
- With a fix record
- 0%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')2
- CWE-918 Server-Side Request Forgery (SSRF)2
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')1
- CWE-287 Improper Authentication1
- CWE-668 Exposure of Resource to Wrong Sphere1
The weakness classes this vendor ships most often: where to look.
CWEAttack profile
All records
7 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
39Monitor | CVE-2023-7210No exploit | OneNav API improper authenticationonenav · onenav · CWE-287 | Critical9.8 | — | 1.0% | Jan 7, 2024 |
30Monitor | CVE-2021-38712No exploit | OneNav 0.9.12 allows Information Disclosure of the onenav.db3 contents.onenav · onenav · CWE-668 | High7.5 | — | 1.1% | Aug 16, 2021 |
25Monitor | CVE-2024-33832Proof of concept | OneNav v0.9.35-20240318 was discovered to contain a Server-Side Request Forgery (SSRF) via the component /index.php?c=api&method=get_link_inCWE-918 | Medium6.3 | — | 0.7% | Apr 30, 2024 |
22Monitor | CVE-2025-28097No exploit | OneNav 1.1.0 is vulnerable to Cross Site Scripting (XSS) in custom headers.onenav · onenav · CWE-79 | Medium5.5 | — | 0.2% | Mar 28, 2025 |
21Monitor | CVE-2021-38138No exploit | OneNav beta 0.9.12 allows XSS via the Add Link feature.onenav · onenav · CWE-79 | Medium5.4 | — | 1.5% | Aug 5, 2021 |
21Monitor | CVE-2022-26276No exploit | An issue in index.php of OneNav v0.9.14 allows attackers to perform directory traversal.onenav · onenav · CWE-22 | Medium5.3 | — | 1.2% | Mar 11, 2022 |
21Monitor | CVE-2025-28096No exploit | OneNav 1.1.0 is vulnerable to Server-Side Request Forgery (SSRF) in custom headers.onenav · onenav · CWE-918 | Medium5.4 | — | 0.2% | Mar 28, 2025 |
- CVE-2023-721039Monitor
OneNav API improper authentication
CriticalCVSS 9.8No exploitEPSS 1%onenav · onenavJan 7, 2024
- CVE-2021-3871230Monitor
OneNav 0.9.12 allows Information Disclosure of the onenav.db3 contents.
HighCVSS 7.5No exploitEPSS 1%onenav · onenavAug 16, 2021
- CVE-2024-3383225Monitor
OneNav v0.9.35-20240318 was discovered to contain a Server-Side Request Forgery (SSRF) via the component /index.php?c=api&method=get_link_in
MediumCVSS 6.3Proof of conceptEPSS 1%Apr 30, 2024
- CVE-2025-2809722Monitor
OneNav 1.1.0 is vulnerable to Cross Site Scripting (XSS) in custom headers.
MediumCVSS 5.5No exploitEPSS 0%onenav · onenavMar 28, 2025
- CVE-2021-3813821Monitor
OneNav beta 0.9.12 allows XSS via the Add Link feature.
MediumCVSS 5.4No exploitEPSS 2%onenav · onenavAug 5, 2021
- CVE-2022-2627621Monitor
An issue in index.php of OneNav v0.9.14 allows attackers to perform directory traversal.
MediumCVSS 5.3No exploitEPSS 1%onenav · onenavMar 11, 2022
- CVE-2025-2809621Monitor
OneNav 1.1.0 is vulnerable to Server-Side Request Forgery (SSRF) in custom headers.
MediumCVSS 5.4No exploitEPSS 0%onenav · onenavMar 28, 2025