vciy

CVEs we hold for Ox

Records whose assigning authority named Ox as the affected vendor. Newest identifiers first, capped at 200.

CVE-2026-42882oxyno-zeta/s3-proxy: Security Issues in Resource Path Matchingoxyno-zeta s3-proxy
CVE-2026-40946Oxia: OIDC token audience validation bypass via SkipClientIDCheckoxia-db oxia
CVE-2026-40945Oxia: Bearer token exposed in debug log messages on authentication failureoxia-db oxia
CVE-2026-40944Oxia: TLS CA certificate chain validation fails with multi-certificate PEM bundlesoxia-db oxia
CVE-2026-40943Oxia: Server crash via race condition in session heartbeat handlingoxia-db oxia
CVE-2025-9275Oxford Instruments Imaris Viewer IMS File Parsing Out-Of-Bounds Write Remote Code Execution VulnerabilityOxford Instruments Imaris Viewer
CVE-2025-9274Oxford Instruments Imaris Viewer IMS File Parsing Uninitialized Pointer Remote Code Execution VulnerabilityOxford Instruments Imaris Viewer
CVE-2025-66432no title heldOxide Omicron
CVE-2025-54808Oxford Nanopore Technologies MinKNOW Insufficiently Protected CredentialsOxford Nanopore Technologies MinKNOW
CVE-2025-32631WordPress Oxygen MyData for WooCommerce plugin <= 1.0.64 - Arbitrary File Deletion vulnerabilityoxygensuite Oxygen MyData for WooCommerce
CVE-2025-27590no title heldOxidized Web
CVE-2025-27088Reflected Cross-site Scripting (XSS) in template implementation in oxyno-zeta/s3-proxyoxyno-zeta s3-proxy
CVE-2025-10937Oxford Nanopore Technologies MinKNOW Improper Check for Unusual or Exceptional ConditionsOxford Nano Technologies MinKNOW
CVE-2024-6688Oxygen Builder <= 4.8.3 - Missing Authorization to Authenticated (Subscriber+) Stylesheet UpdateOxygen Builder
CVE-2024-4662Oxygen Builder <= 4.8.2 - Authenticated (Contributor+) Remote Code ExecutionOxygen Builder
CVE-2024-35585no title heldOxford Nanopore MinKNOW
CVE-2023-6938Oxygen Builder <= 4.8 - Authenticated (Contributor+) Stored Cross-Site Scripting via Custom FieldOxygen Builder
CVE-2023-29047no title heldOX App Suite
CVE-2023-29046no title heldOX App Suite
CVE-2023-29045no title heldOX App Suite
CVE-2023-29044no title heldOX App Suite
CVE-2023-29043no title heldOX App Suite
CVE-2023-26456no title heldOX App Suite
CVE-2023-26455no title heldOX App Suite
CVE-2023-26454no title heldOX App Suite
CVE-2023-26453no title heldOX App Suite
CVE-2023-26452no title heldOX App Suite
CVE-2023-26451no title heldOX App Suite
CVE-2023-26450no title heldOX App Suite
CVE-2023-26449no title heldOX App Suite
CVE-2023-26448no title heldOX App Suite
CVE-2023-26447no title heldOX App Suite
CVE-2023-26446no title heldOX App Suite
CVE-2023-26445no title heldOX App Suite
CVE-2023-26443no title heldOX App Suite
CVE-2023-26442no title heldOX App Suite
CVE-2023-26441no title heldOX App Suite
CVE-2023-26440no title heldOX App Suite
CVE-2023-26439no title heldOX App Suite
CVE-2023-26438no title heldOX App Suite
CVE-2023-26436no title heldOX App Suite
CVE-2023-26435no title heldOX App Suite
CVE-2023-26434no title heldOX App Suite
CVE-2023-26433no title heldOX App Suite
CVE-2023-26432no title heldOX App Suite
CVE-2023-26431no title heldOX App Suite
CVE-2023-26430no title heldOX App Suite
CVE-2023-26429no title heldOX App Suite
CVE-2023-26428no title heldOX App Suite
CVE-2023-26427no title heldOX App Suite
CVE-2022-36010Arbitrary code execution via function parsing in react-editable-json-treeoxyno-zeta react-editable-json-tree
CVE-2021-36888WordPress Image Hover Effects Ultimate plugin <= 9.6.1 - Unauthenticated Arbitrary Options Update leading to full…Oxilab Image Hover Effects Ultimate (WordPress plugin)
CVE-2021-22400no title heldn/a OxfordS-AN00A
CVE-2020-9066no title heldn/a OxfordP-AN10B
CVE-2020-1878no title heldn/a OxfordS-AN00A
CVE-2019-25260OXID eShop 6.3.4 - 'sorting' SQL InjectionOXID-eSales OXID eShop
CVE-2016-5072no title heldn/a OXID eShop before 2016-06-13
CVE-2016-15008oxguy3 coebot-www channel.js showChannelBoir cross site scriptingoxguy3 coebot-www

58 records, read from the index as it stood on 20 Sep 2026. Every row opens the record it names, and every value on that record opens its own receipt.

Everything on this page is free. Public data. Withholding it protects nothing.