VYPR
Vendor

Helloxz

Products
3
CVEs
5
Across products
5
Status
Private

Products

3

Recent CVEs

5
  • CVE-2023-23314HigJan 23, 2023
    risk 0.57cvss 8.8epss 0.01

    An arbitrary file upload vulnerability in the /api/upload component of zdir v3.2.0 allows attackers to execute arbitrary code via a crafted .ssh file.

  • CVE-2021-38712HigAug 16, 2021
    risk 0.49cvss 7.5epss 0.01

    OneNav 0.9.12 allows Information Disclosure of the onenav.db3 contents. NOTE: the vendor's recommended solution is to block the access via an NGINX configuration file.

  • CVE-2023-7210HigJan 7, 2024
    risk 0.48cvss 7.3epss 0.01

    A vulnerability was found in OneNav up to 0.9.33. It has been classified as critical. This affects an unknown part of the file /index.php?c=api of the component API. The manipulation of the argument X-Token leads to improper authentication. It is possible to initiate the attack…

  • CVE-2024-33832MedApr 30, 2024
    risk 0.41cvss 6.3epss 0.01

    OneNav v0.9.35-20240318 was discovered to contain a Server-Side Request Forgery (SSRF) via the component /index.php?c=api&method=get_link_info.

  • CVE-2022-26276MedMar 12, 2022
    risk 0.35cvss 5.3epss 0.01

    An issue in index.php of OneNav v0.9.14 allows attackers to perform directory traversal.