Products: 1
    Vulnerabilities: 6
    Known Exploited: 0
    0
    Critical Level Threats
    2
    High Level Threats
    4
    Medium Level Threats
    0
    Low Level Threats

    Vulnerabilities

    100806040200
    JanFebMarAprMayJunJulAugSepOctNovDec
    Critical Level Threats
    High Level Threats
    Medium Level Threats
    Low Level Threats

    Products Security index

    Actions
    Items Per Page

    Vulnerabilities

    CVE-2025-28096

    OneNav 1.1.0 is vulnerable to Server-Side Request Forgery (SSRF) in custom headers.

    Last Modified: Apr 07, 2025
    Published: Mar 28, 2025

    CVE-2025-28097

    OneNav 1.1.0 is vulnerable to Cross Site Scripting (XSS) in custom headers.

    Last Modified: Apr 07, 2025
    Published: Mar 28, 2025

    CVE-2023-7210

    OneNav API improper authentication

    Last Modified: Nov 21, 2024
    Published: Jan 07, 2024

    CVE-2022-26276

    An issue in index.php of OneNav v0.9.14 allows attackers to perform directory traversal.

    Last Modified: Nov 21, 2024
    Published: Mar 12, 2022

    CVE-2021-38712

    OneNav 0.9.12 allows Information Disclosure of the onenav.db3 contents. NOTE: the vendor's recommended solution is to block the access via an NGINX configuration file.

    Last Modified: Nov 21, 2024
    Published: Aug 16, 2021
    Items Per Page
    Onenav Vulnerabilities & Security CVEs | CVE-DB