Ox Guard
11 CVEs tracked. None of them is in CISA KEV.
This hub aggregates every CVE we track for Ox Guard, a product in the communications space. Use it to gauge the current risk picture and drill into individual advisories.
Ox Guard CVEs per month
| Month | CVEs |
|---|---|
| 2024-10 | 0 |
| 2024-11 | 0 |
| 2024-12 | 0 |
| 2025-01 | 0 |
| 2025-02 | 0 |
| 2025-03 | 0 |
| 2025-04 | 0 |
| 2025-05 | 0 |
| 2025-06 | 0 |
| 2025-07 | 0 |
| 2025-08 | 0 |
| 2025-09 | 0 |
| 2025-10 | 0 |
| 2025-11 | 0 |
| 2025-12 | 0 |
| 2026-01 | 0 |
| 2026-02 | 0 |
| 2026-03 | 0 |
| 2026-04 | 0 |
| 2026-05 | 0 |
| 2026-06 | 0 |
| 2026-07 | 0 |
| 2026-08 | 0 |
| 2026-09 | 0 |
Severity
How the 11 CVEs score on CVSS. Severity is not exploitation: KEV is counted above.
- High4
- Medium7
Latest CVEs
The 11 most recently published vulnerabilities affecting Ox Guard.
- CVE-2023-26456Users were able to set an arbitrary "product name" for OX Guard. The chosen value was not sufficiently sanitized before processing it at the user interface, allowing for indirect cross-site scripti...5.4
- CVE-2020-28944OX Guard 2.10.4 and earlier allows a Denial of Service via a WKS server that responds slowly or with a large amount of data.7.5
- CVE-2020-9426OX Guard 2.10.3 and earlier allows XSS.6.1
- CVE-2020-9427OX Guard 2.10.3 and earlier allows SSRF.5.0
- CVE-2018-10986OX Guard 2.8.0 has CSRF.8.8
- CVE-2016-4028An issue was discovered in Open-Xchange OX Guard before 2.4.0-rev8. OX Guard uses an authentication token to identify and transfer guest users' credentials. The OX Guard API acts as a padding orac...7.5
- CVE-2016-6853An issue was discovered in Open-Xchange OX Guard before 2.4.2-rev5. Script code and references to external websites can be injected to the names of PGP public keys. When requesting that key later o...6.1
- CVE-2016-6851An issue was discovered in Open-Xchange OX Guard before 2.4.2-rev5. Script code can be provided as parameter to the OX Guard guest reader web application. This allows cross-site scripting attacks a...6.1
- CVE-2016-6854An issue was discovered in Open-Xchange OX Guard before 2.4.2-rev5. Script code which got injected to a mail with inline PGP signature gets executed when verifying the signature. Malicious script c...6.1
- CVE-2015-8542An issue was discovered in Open-Xchange Guard before 2.2.0-rev8. The "getprivkeybyid" API call is used to download a PGP Private Key for a specific user after providing authentication credentials. ...8.8
- CVE-2015-7385Cross-site scripting (XSS) vulnerability in Open-Xchange OX Guard before 2.0.0-rev11 allows remote attackers to inject arbitrary web script or HTML via the uid field in a PGP public key, which is n...4.3
Product grouping is registry-driven, with AI assist and human review. How it works