İçeriğe atla
Noroxi

OpenC3 kayıtları

openc3 üreticisine ait 15 yayımlanmış kayıt.

Tüm kayıtlar

15 kayıt
  • CVE-2025-28386
    39İzleyin

    A remote code execution (RCE) vulnerability in the Plugin Management component of OpenC3 COSMOS v6.0.0 allows attackers to execute arbitrary

    KritikCVSS 9,8İstismar yokEPSS %1

    openc3 · cosmos13 Haz 2025

  • CVE-2025-28388
    39İzleyin

    OpenC3 COSMOS before v6.0.2 was discovered to contain hardcoded credentials for the Service Account.

    KritikCVSS 9,8İstismar yokEPSS %1

    openc3 · cosmos13 Haz 2025

  • CVE-2025-28389
    39İzleyin

    Weak password requirements in OpenC3 COSMOS v6.0.0 allow attackers to bypass authentication via a brute force attack.

    KritikCVSS 9,8İstismar yokEPSS %1

    openc3 · cosmos13 Haz 2025

  • CVE-2026-42087
    38İzleyin

    OpenC3 COSMOS: SQL Injection in QuestDB Time-Series Data Base

    KritikCVSS 9,6İstismar yokEPSS %0

    openc3 · cosmos4 May 2026

  • CVE-2025-28384
    36İzleyin

    An issue in the /script-api/scripts/ endpoint of OpenC3 COSMOS before 6.1.0 allows attackers to execute a directory traversal.

    KritikCVSS 9,1İstismar yokEPSS %1

    openc3 · cosmos13 Haz 2025

  • CVE-2026-42088
    32İzleyin

    OpenC3 COSMOS: Administrative Actions via the Script Runner Tool

    YüksekCVSS 8,1İstismar yokEPSS %0

    openc3 · cosmos4 May 2026

  • CVE-2026-42084
    32İzleyin

    OpenC3 COSMOS: Hijacked session token can be used to reset password for persistence

    YüksekCVSS 8,1İstismar yokEPSS %0

    openc3 · cosmos4 May 2026

  • CVE-2025-28382
    30İzleyin

    An issue in the openc3-api/tables endpoint of OpenC3 COSMOS before 6.1.0 allows attackers to execute a directory traversal.

    YüksekCVSS 7,5İstismar yokEPSS %1

    openc3 · cosmos13 Haz 2025

  • CVE-2025-28381
    30İzleyin

    A credential leak in OpenC3 COSMOS before v6.0.2 allows attackers to access service credentials as environment variables stored in all conta

    YüksekCVSS 7,5İstismar yokEPSS %1

    openc3 · cosmos13 Haz 2025

  • CVE-2025-28380
    24İzleyin

    A cross-site scripting (XSS) vulnerability in OpenC3 COSMOS before v6.0.2 allows attackers to execute arbitrary web scripts or HTML via inje

    OrtaCVSS 6,1İstismar yokEPSS %0

    openc3 · cosmos13 Haz 2025

  • CVE-2024-46977
    21İzleyin

    OpenC3 COSMOS allows a path traversal via screen controller (`GHSL-2024-127`)

    OrtaCVSS 5,3İstismar yokEPSS %1

    openc3 · cosmos2 Eki 2024

  • CVE-2024-43795
    20İzleyin

    OpenC3 COSMOS vulnerable to cross-site scripting in Login functionality (`GHSL-2024-128`)

    OrtaCVSS 5,1İstismar yokEPSS %0

    openc3 · cosmos2 Eki 2024

  • CVE-2024-47529
    19İzleyin

    OpenC3 COSMOS uses clear text storage of password/token (`GHSL-2024-129`)

    OrtaCVSS 4,8İstismar yokEPSS %0

    openc3 · cosmos2 Eki 2024

  • CVE-2026-42086
    18İzleyin

    OpenC3 COSMOS: Self-XSS in the Command Sender

    OrtaCVSS 4,6İstismar yokEPSS %0

    openc3 · cosmos4 May 2026

  • CVE-2026-42085
    17İzleyin

    OpenC3 COSMOS: Arbitrary write to plugins directory via path-traversed config filenames

    OrtaCVSS 4,3İstismar yokEPSS %0

    openc3 · cosmos4 May 2026