Known Vulnerabilities for products from Onenav
Listed below are 3 of the newest known vulnerabilities associated with the vendor "Onenav".
These CVEs are retrieved based on exact matches on listed vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed vendor information are still displayed.
Data on known vulnerable products is also displayed based on information from known CPEs, each product links to its respective vulnerability page.
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2022-26276 json | An issue in index.php of OneNav v0.9.14 allows attackers to perform directory traversal. | 5.3 - MEDIUM | 2022-03-12 | 2022-09-28 |
| CVE-2021-38712 json | OneNav 0.9.12 allows Information Disclosure of the onenav.db3 contents. NOTE: the vendor's recommended solution is to block t... | 7.5 - HIGH | 2021-08-16 | 2021-08-24 |
| CVE-2021-38138 json | OneNav beta 0.9.12 allows XSS via the Add Link feature. NOTE: the vendor's position is that there intentionally is not any XS... | 5.4 - MEDIUM | 2021-08-05 | 2022-09-28 |