OpenC3 kayıtları
openc3 üreticisine ait 15 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 0 · %0
- Silahlaştırılmış
- 0 · %0
- Pre-auth RCE
- 2
- Düzeltme kaydı olan
- %53,3
- Yayından KEV’e ortanca
- KEV’e giren kayıt yok
Tekrar eden sınıflar
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')3
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')3
- CWE-250 Execution with Unnecessary Privileges1
- CWE-312 Cleartext Storage of Sensitive Information1
- CWE-521 Weak Password Requirements1
- CWE-526 Cleartext Storage of Sensitive Information in an Environment Variable1
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWETüm kayıtlar
15 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
39İzleyin | CVE-2025-28386İstismar yok | A remote code execution (RCE) vulnerability in the Plugin Management component of OpenC3 COSMOS v6.0.0 allows attackers to execute arbitraryopenc3 · cosmos · CWE-94 | Kritik9,8 | — | %1,1 | 13 Haz 2025 |
39İzleyin | CVE-2025-28388İstismar yok | OpenC3 COSMOS before v6.0.2 was discovered to contain hardcoded credentials for the Service Account.openc3 · cosmos · CWE-798 | Kritik9,8 | — | %0,6 | 13 Haz 2025 |
39İzleyin | CVE-2025-28389İstismar yok | Weak password requirements in OpenC3 COSMOS v6.0.0 allow attackers to bypass authentication via a brute force attack.openc3 · cosmos · CWE-521 | Kritik9,8 | — | %0,6 | 13 Haz 2025 |
38İzleyin | CVE-2026-42087İstismar yok | OpenC3 COSMOS: SQL Injection in QuestDB Time-Series Data Baseopenc3 · cosmos · CWE-89 | Kritik9,6 | — | %0,4 | 4 May 2026 |
36İzleyin | CVE-2025-28384İstismar yok | An issue in the /script-api/scripts/ endpoint of OpenC3 COSMOS before 6.1.0 allows attackers to execute a directory traversal.openc3 · cosmos · CWE-22 | Kritik9,1 | — | %0,9 | 13 Haz 2025 |
32İzleyin | CVE-2026-42088İstismar yok | OpenC3 COSMOS: Administrative Actions via the Script Runner Toolopenc3 · cosmos · CWE-250 | Yüksek8,1 | — | %0,5 | 4 May 2026 |
32İzleyin | CVE-2026-42084İstismar yok | OpenC3 COSMOS: Hijacked session token can be used to reset password for persistenceopenc3 · cosmos · CWE-620 | Yüksek8,1 | — | %0,4 | 4 May 2026 |
30İzleyin | CVE-2025-28382İstismar yok | An issue in the openc3-api/tables endpoint of OpenC3 COSMOS before 6.1.0 allows attackers to execute a directory traversal.openc3 · cosmos · CWE-22 | Yüksek7,5 | — | %0,9 | 13 Haz 2025 |
30İzleyin | CVE-2025-28381İstismar yok | A credential leak in OpenC3 COSMOS before v6.0.2 allows attackers to access service credentials as environment variables stored in all contaopenc3 · cosmos · CWE-526 | Yüksek7,5 | — | %0,5 | 13 Haz 2025 |
24İzleyin | CVE-2025-28380İstismar yok | A cross-site scripting (XSS) vulnerability in OpenC3 COSMOS before v6.0.2 allows attackers to execute arbitrary web scripts or HTML via injeopenc3 · cosmos · CWE-79 | Orta6,1 | — | %0,3 | 13 Haz 2025 |
21İzleyin | CVE-2024-46977İstismar yok | OpenC3 COSMOS allows a path traversal via screen controller (`GHSL-2024-127`)openc3 · cosmos · CWE-22 | Orta5,3 | — | %0,9 | 2 Eki 2024 |
20İzleyin | CVE-2024-43795İstismar yok | OpenC3 COSMOS vulnerable to cross-site scripting in Login functionality (`GHSL-2024-128`)openc3 · cosmos · CWE-79 | Orta5,1 | — | %0,5 | 2 Eki 2024 |
19İzleyin | CVE-2024-47529İstismar yok | OpenC3 COSMOS uses clear text storage of password/token (`GHSL-2024-129`)openc3 · cosmos · CWE-312 | Orta4,8 | — | %0,4 | 2 Eki 2024 |
18İzleyin | CVE-2026-42086İstismar yok | OpenC3 COSMOS: Self-XSS in the Command Senderopenc3 · cosmos · CWE-79 | Orta4,6 | — | %0,3 | 4 May 2026 |
17İzleyin | CVE-2026-42085İstismar yok | OpenC3 COSMOS: Arbitrary write to plugins directory via path-traversed config filenamesopenc3 · cosmos · CWE-23 | Orta4,3 | — | %0,4 | 4 May 2026 |
- CVE-2025-2838639İzleyin
A remote code execution (RCE) vulnerability in the Plugin Management component of OpenC3 COSMOS v6.0.0 allows attackers to execute arbitrary
KritikCVSS 9,8İstismar yokEPSS %1openc3 · cosmos13 Haz 2025
- CVE-2025-2838839İzleyin
OpenC3 COSMOS before v6.0.2 was discovered to contain hardcoded credentials for the Service Account.
KritikCVSS 9,8İstismar yokEPSS %1openc3 · cosmos13 Haz 2025
- CVE-2025-2838939İzleyin
Weak password requirements in OpenC3 COSMOS v6.0.0 allow attackers to bypass authentication via a brute force attack.
KritikCVSS 9,8İstismar yokEPSS %1openc3 · cosmos13 Haz 2025
- CVE-2026-4208738İzleyin
OpenC3 COSMOS: SQL Injection in QuestDB Time-Series Data Base
KritikCVSS 9,6İstismar yokEPSS %0openc3 · cosmos4 May 2026
- CVE-2025-2838436İzleyin
An issue in the /script-api/scripts/ endpoint of OpenC3 COSMOS before 6.1.0 allows attackers to execute a directory traversal.
KritikCVSS 9,1İstismar yokEPSS %1openc3 · cosmos13 Haz 2025
- CVE-2026-4208832İzleyin
OpenC3 COSMOS: Administrative Actions via the Script Runner Tool
YüksekCVSS 8,1İstismar yokEPSS %0openc3 · cosmos4 May 2026
- CVE-2026-4208432İzleyin
OpenC3 COSMOS: Hijacked session token can be used to reset password for persistence
YüksekCVSS 8,1İstismar yokEPSS %0openc3 · cosmos4 May 2026
- CVE-2025-2838230İzleyin
An issue in the openc3-api/tables endpoint of OpenC3 COSMOS before 6.1.0 allows attackers to execute a directory traversal.
YüksekCVSS 7,5İstismar yokEPSS %1openc3 · cosmos13 Haz 2025
- CVE-2025-2838130İzleyin
A credential leak in OpenC3 COSMOS before v6.0.2 allows attackers to access service credentials as environment variables stored in all conta
YüksekCVSS 7,5İstismar yokEPSS %1openc3 · cosmos13 Haz 2025
- CVE-2025-2838024İzleyin
A cross-site scripting (XSS) vulnerability in OpenC3 COSMOS before v6.0.2 allows attackers to execute arbitrary web scripts or HTML via inje
OrtaCVSS 6,1İstismar yokEPSS %0openc3 · cosmos13 Haz 2025
- CVE-2024-4697721İzleyin
OpenC3 COSMOS allows a path traversal via screen controller (`GHSL-2024-127`)
OrtaCVSS 5,3İstismar yokEPSS %1openc3 · cosmos2 Eki 2024
- CVE-2024-4379520İzleyin
OpenC3 COSMOS vulnerable to cross-site scripting in Login functionality (`GHSL-2024-128`)
OrtaCVSS 5,1İstismar yokEPSS %0openc3 · cosmos2 Eki 2024
- CVE-2024-4752919İzleyin
OpenC3 COSMOS uses clear text storage of password/token (`GHSL-2024-129`)
OrtaCVSS 4,8İstismar yokEPSS %0openc3 · cosmos2 Eki 2024
- CVE-2026-4208618İzleyin
OpenC3 COSMOS: Self-XSS in the Command Sender
OrtaCVSS 4,6İstismar yokEPSS %0openc3 · cosmos4 May 2026
- CVE-2026-4208517İzleyin
OpenC3 COSMOS: Arbitrary write to plugins directory via path-traversed config filenames
OrtaCVSS 4,3İstismar yokEPSS %0openc3 · cosmos4 May 2026