OpenC3 records
15 published records for vendor openc3.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 2
- With a fix record
- 53.3%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')3
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')3
- CWE-250 Execution with Unnecessary Privileges1
- CWE-312 Cleartext Storage of Sensitive Information1
- CWE-521 Weak Password Requirements1
- CWE-526 Cleartext Storage of Sensitive Information in an Environment Variable1
The weakness classes this vendor ships most often: where to look.
CWEAll records
15 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
39Monitor | CVE-2025-28386No exploit | A remote code execution (RCE) vulnerability in the Plugin Management component of OpenC3 COSMOS v6.0.0 allows attackers to execute arbitraryopenc3 · cosmos · CWE-94 | Critical9.8 | — | 1.1% | Jun 13, 2025 |
39Monitor | CVE-2025-28388No exploit | OpenC3 COSMOS before v6.0.2 was discovered to contain hardcoded credentials for the Service Account.openc3 · cosmos · CWE-798 | Critical9.8 | — | 0.6% | Jun 13, 2025 |
39Monitor | CVE-2025-28389No exploit | Weak password requirements in OpenC3 COSMOS v6.0.0 allow attackers to bypass authentication via a brute force attack.openc3 · cosmos · CWE-521 | Critical9.8 | — | 0.6% | Jun 13, 2025 |
38Monitor | CVE-2026-42087No exploit | OpenC3 COSMOS: SQL Injection in QuestDB Time-Series Data Baseopenc3 · cosmos · CWE-89 | Critical9.6 | — | 0.4% | May 4, 2026 |
36Monitor | CVE-2025-28384No exploit | An issue in the /script-api/scripts/ endpoint of OpenC3 COSMOS before 6.1.0 allows attackers to execute a directory traversal.openc3 · cosmos · CWE-22 | Critical9.1 | — | 0.9% | Jun 13, 2025 |
32Monitor | CVE-2026-42088No exploit | OpenC3 COSMOS: Administrative Actions via the Script Runner Toolopenc3 · cosmos · CWE-250 | High8.1 | — | 0.5% | May 4, 2026 |
32Monitor | CVE-2026-42084No exploit | OpenC3 COSMOS: Hijacked session token can be used to reset password for persistenceopenc3 · cosmos · CWE-620 | High8.1 | — | 0.4% | May 4, 2026 |
30Monitor | CVE-2025-28382No exploit | An issue in the openc3-api/tables endpoint of OpenC3 COSMOS before 6.1.0 allows attackers to execute a directory traversal.openc3 · cosmos · CWE-22 | High7.5 | — | 0.9% | Jun 13, 2025 |
30Monitor | CVE-2025-28381No exploit | A credential leak in OpenC3 COSMOS before v6.0.2 allows attackers to access service credentials as environment variables stored in all contaopenc3 · cosmos · CWE-526 | High7.5 | — | 0.5% | Jun 13, 2025 |
24Monitor | CVE-2025-28380No exploit | A cross-site scripting (XSS) vulnerability in OpenC3 COSMOS before v6.0.2 allows attackers to execute arbitrary web scripts or HTML via injeopenc3 · cosmos · CWE-79 | Medium6.1 | — | 0.3% | Jun 13, 2025 |
21Monitor | CVE-2024-46977No exploit | OpenC3 COSMOS allows a path traversal via screen controller (`GHSL-2024-127`)openc3 · cosmos · CWE-22 | Medium5.3 | — | 0.9% | Oct 2, 2024 |
20Monitor | CVE-2024-43795No exploit | OpenC3 COSMOS vulnerable to cross-site scripting in Login functionality (`GHSL-2024-128`)openc3 · cosmos · CWE-79 | Medium5.1 | — | 0.5% | Oct 2, 2024 |
19Monitor | CVE-2024-47529No exploit | OpenC3 COSMOS uses clear text storage of password/token (`GHSL-2024-129`)openc3 · cosmos · CWE-312 | Medium4.8 | — | 0.4% | Oct 2, 2024 |
18Monitor | CVE-2026-42086No exploit | OpenC3 COSMOS: Self-XSS in the Command Senderopenc3 · cosmos · CWE-79 | Medium4.6 | — | 0.3% | May 4, 2026 |
17Monitor | CVE-2026-42085No exploit | OpenC3 COSMOS: Arbitrary write to plugins directory via path-traversed config filenamesopenc3 · cosmos · CWE-23 | Medium4.3 | — | 0.4% | May 4, 2026 |
- CVE-2025-2838639Monitor
A remote code execution (RCE) vulnerability in the Plugin Management component of OpenC3 COSMOS v6.0.0 allows attackers to execute arbitrary
CriticalCVSS 9.8No exploitEPSS 1%openc3 · cosmosJun 13, 2025
- CVE-2025-2838839Monitor
OpenC3 COSMOS before v6.0.2 was discovered to contain hardcoded credentials for the Service Account.
CriticalCVSS 9.8No exploitEPSS 1%openc3 · cosmosJun 13, 2025
- CVE-2025-2838939Monitor
Weak password requirements in OpenC3 COSMOS v6.0.0 allow attackers to bypass authentication via a brute force attack.
CriticalCVSS 9.8No exploitEPSS 1%openc3 · cosmosJun 13, 2025
- CVE-2026-4208738Monitor
OpenC3 COSMOS: SQL Injection in QuestDB Time-Series Data Base
CriticalCVSS 9.6No exploitEPSS 0%openc3 · cosmosMay 4, 2026
- CVE-2025-2838436Monitor
An issue in the /script-api/scripts/ endpoint of OpenC3 COSMOS before 6.1.0 allows attackers to execute a directory traversal.
CriticalCVSS 9.1No exploitEPSS 1%openc3 · cosmosJun 13, 2025
- CVE-2026-4208832Monitor
OpenC3 COSMOS: Administrative Actions via the Script Runner Tool
HighCVSS 8.1No exploitEPSS 0%openc3 · cosmosMay 4, 2026
- CVE-2026-4208432Monitor
OpenC3 COSMOS: Hijacked session token can be used to reset password for persistence
HighCVSS 8.1No exploitEPSS 0%openc3 · cosmosMay 4, 2026
- CVE-2025-2838230Monitor
An issue in the openc3-api/tables endpoint of OpenC3 COSMOS before 6.1.0 allows attackers to execute a directory traversal.
HighCVSS 7.5No exploitEPSS 1%openc3 · cosmosJun 13, 2025
- CVE-2025-2838130Monitor
A credential leak in OpenC3 COSMOS before v6.0.2 allows attackers to access service credentials as environment variables stored in all conta
HighCVSS 7.5No exploitEPSS 1%openc3 · cosmosJun 13, 2025
- CVE-2025-2838024Monitor
A cross-site scripting (XSS) vulnerability in OpenC3 COSMOS before v6.0.2 allows attackers to execute arbitrary web scripts or HTML via inje
MediumCVSS 6.1No exploitEPSS 0%openc3 · cosmosJun 13, 2025
- CVE-2024-4697721Monitor
OpenC3 COSMOS allows a path traversal via screen controller (`GHSL-2024-127`)
MediumCVSS 5.3No exploitEPSS 1%openc3 · cosmosOct 2, 2024
- CVE-2024-4379520Monitor
OpenC3 COSMOS vulnerable to cross-site scripting in Login functionality (`GHSL-2024-128`)
MediumCVSS 5.1No exploitEPSS 0%openc3 · cosmosOct 2, 2024
- CVE-2024-4752919Monitor
OpenC3 COSMOS uses clear text storage of password/token (`GHSL-2024-129`)
MediumCVSS 4.8No exploitEPSS 0%openc3 · cosmosOct 2, 2024
- CVE-2026-4208618Monitor
OpenC3 COSMOS: Self-XSS in the Command Sender
MediumCVSS 4.6No exploitEPSS 0%openc3 · cosmosMay 4, 2026
- CVE-2026-4208517Monitor
OpenC3 COSMOS: Arbitrary write to plugins directory via path-traversed config filenames
MediumCVSS 4.3No exploitEPSS 0%openc3 · cosmosMay 4, 2026