CVE Tools

Onyx

14 CVEs tracked. None of them is in CISA KEV.

This hub aggregates every CVE we track for Onyx, a product in the hardware firmware space. Use it to gauge the current risk picture and drill into individual advisories.

Onyx CVEs per month

Oct 2024 to Sep 2026. Point at a month, or focus the strip and use the arrow keys.
Onyx CVEs per month
MonthCVEs
2024-100
2024-110
2024-120
2025-010
2025-020
2025-032
2025-040
2025-050
2025-060
2025-072
2025-080
2025-090
2025-100
2025-110
2025-120
2026-010
2026-020
2026-030
2026-040
2026-052
2026-060
2026-070
2026-082
2026-091

Severity

How the 14 CVEs score on CVSS. Severity is not exploitation: KEV is counted above.

  • Critical17%
  • High429%
  • Medium964%

Latest CVEs

The 14 most recently published vulnerabilities affecting Onyx.

  1. CVE-2026-85700Onyx 4.6.6 Custom Tool Secret Header Disclosure via Tool Endpoints6.5
  2. CVE-2026-63178Onyx Curator-scope IDOR: any curator can modify membership of arbitrary user groups via unscoped PATCH /manage/admin/user-group/{id} and /add-users leading to cross-group document disclosure6.5
  3. CVE-2026-71424Onyx: Cross-user OAuth-token leak via /api/mcp/servers* for per-user MCP servers9.6
  4. CVE-2026-42277Onyx: IDOR in /chat/file/{file_id} allows any authenticated user to download other users files6.5
  5. CVE-2026-42276Onyx: IDOR in /chat/stop-chat-session allows any authenticated user to interrupt other users chat sessions4.3
  6. CVE-2025-51479Authorization bypass in update_user_group in onyx-dot-app Onyx Enterprise Edition 0.27.0 allows remote authenticated attackers to modify arbitrary user groups via crafted PATCH requests to the /api...5.4
  7. CVE-2025-7894Onyx Chat Interface a3_generate_simple_sql.py generate_simple_sql sql injection6.3
  8. CVE-2024-7767Improper Access Control in danswer-ai/danswer8.1
  9. CVE-2024-9612Unauthorized Access in danswer-ai/danswer6.5
  10. CVE-2024-0113NVIDIA Mellanox OS, ONYX, Skyway, and MetroX-3 XCC contain a vulnerability in the web support, where an attacker can cause a CGI path traversal by a specially crafted URI. A successful exploit of t...7.5
  11. CVE-2024-0104NVIDIA Mellanox OS, ONYX, Skyway, MetroX-2 and MetroX-3 XC contain a vulnerability in the LDAP AAA component, where a user can cause improper access. A successful exploit of this vulnerability migh...4.2
  12. CVE-2024-0101NVIDIA Mellanox OS, ONYX, Skyway, MetroX-2 and MetroX-3 XC contain a vulnerability in ipfilter, where improper ipfilter definitions could enable an attacker to cause a failure by attacking the swit...7.5
  13. CVE-2023-43784Plesk Onyx 17.8.11 has accessKeyId and secretAccessKey fields that are related to an Amazon AWS Firehose component. NOTE: the vendor's position is that there is no security threat.7.5
  14. CVE-2020-11584A GET-based XSS reflected vulnerability in Plesk Onyx 17.8.11 allows remote unauthenticated users to inject arbitrary JavaScript, HTML, or CSS via a GET parameter.6.1

Product grouping is registry-driven, with AI assist and human review. How it works

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store