Onyx
This hub aggregates every CVE we track for Onyx, a product in the hardware firmware space. Use it to gauge the current risk picture and drill into individual advisories.
13
CVEs tracked
1
Critical
4
High
0
In CISA KEV
Severity distribution
MEDIUM8HIGH4CRITICAL1
Monthly trend
0
0
0
0
0
0
2
0
0
0
2
0
0
0
0
0
0
0
0
0
2
0
0
2
2024-092026-08
Latest CVEs
The 13 most recently published vulnerabilities affecting Onyx.
- CVE-2026-63178Onyx Curator-scope IDOR: any curator can modify membership of arbitrary user groups via unscoped PATCH /manage/admin/user-group/{id} and /add-users leading to cross-group document disclosure6.5
- CVE-2026-71424Onyx: Cross-user OAuth-token leak via /api/mcp/servers* for per-user MCP servers9.6
- CVE-2026-42277Onyx: IDOR in /chat/file/{file_id} allows any authenticated user to download other users files6.5
- CVE-2026-42276Onyx: IDOR in /chat/stop-chat-session allows any authenticated user to interrupt other users chat sessions4.3
- CVE-2025-51479Authorization bypass in update_user_group in onyx-dot-app Onyx Enterprise Edition 0.27.0 allows remote authenticated attackers to modify arbitrary user groups via crafted PATCH requests to the /api...5.4
- CVE-2025-7894Onyx Chat Interface a3_generate_simple_sql.py generate_simple_sql sql injection6.3
- CVE-2024-7767Improper Access Control in danswer-ai/danswer8.1
- CVE-2024-9612Unauthorized Access in danswer-ai/danswer6.5
- CVE-2024-0113NVIDIA Mellanox OS, ONYX, Skyway, and MetroX-3 XCC contain a vulnerability in the web support, where an attacker can cause a CGI path traversal by a specially crafted URI. A successful exploit of t...7.5
- CVE-2024-0104NVIDIA Mellanox OS, ONYX, Skyway, MetroX-2 and MetroX-3 XC contain a vulnerability in the LDAP AAA component, where a user can cause improper access. A successful exploit of this vulnerability migh...4.2
- CVE-2024-0101NVIDIA Mellanox OS, ONYX, Skyway, MetroX-2 and MetroX-3 XC contain a vulnerability in ipfilter, where improper ipfilter definitions could enable an attacker to cause a failure by attacking the swit...7.5
- CVE-2023-43784Plesk Onyx 17.8.11 has accessKeyId and secretAccessKey fields that are related to an Amazon AWS Firehose component. NOTE: the vendor's position is that there is no security threat.7.5
- CVE-2020-11584A GET-based XSS reflected vulnerability in Plesk Onyx 17.8.11 allows remote unauthenticated users to inject arbitrary JavaScript, HTML, or CSS via a GET parameter.6.1
Product normalization is registry-driven with AI assist and human review. How it works