Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2741▲ 13 respecto a la semana anterior
Críticas / altas1459▲ 323 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)85▼ 441 respecto a la semana anterior
37 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Crítica (9.9) | 0.57% | — | Openc3 CosmosAI | 23/9/2026 | 29/9/2026 | OpenC3 COSMOS provides the functionality needed to send commands to and receive data from one or more embedded systems. From 5.1.0 until 7.3.0, authenticated non-administrator users can write content under targets_modified/ that is later executed by multiple configuration paths below the intended code-execution… | |
| Aplazada | Alta (8.8) | 0.58% | — | Openc3 CosmosAI | 23/9/2026 | 23/9/2026 | OpenC3 COSMOS provides the functionality needed to send commands to and receive data from one or more embedded systems. From 5.12.0 until 7.3.0, an authenticated actor can write the pypi_url setting through set_setting at POST /openc3-api/api, then cause OpenC3::PluginModel.install_phase2 in… | |
| Aplazada | Alta (7.6) | 0.39% | — | Openc3 CosmosAI | 23/9/2026 | 23/9/2026 | OpenC3 COSMOS provides the functionality needed to send commands to and receive data from one or more embedded systems. From 5.0.6 until 7.3.0, an authenticated actor with system_set permission can store a shared screen through POST /openc3-api/screen whose BUTTON widget action is evaluated by… | |
| Analizada | Crítica (9.6) | 0.79% | — | Microsoft Azure Cosmos DB | 17/9/2026 | 29/9/2026 | Improper neutralization of special elements in output used by a downstream component ('injection') in Azure Cosmos DB allows an authorized attacker to elevate privileges over a network. | |
| Aplazada | Media (6.1) | 0.30% | — | Openc3 CosmosAI | 15/9/2026 | 30/9/2026 | Cosmos provides users the ability self-host a home server by acting as a secure gateway to your application, as well as a server manager. Prior to 0.22.19, tokenMiddleware in src/proxy/routerGen.go can return through the Constellation tunnel bypass before removing x-cosmos-user, x-cosmos-role, x-cosmos-user-role, and… | |
| Analizada | Alta (8.8) | 0.63% | — | Microsoft Azure Cosmos DB | 3/9/2026 | 9/9/2026 | Authorization bypass through user-controlled key in Azure Cosmos DB allows an authorized attacker to perform spoofing over a network. | |
| Analizada | Crítica (10) | 0.90% | — | Microsoft Azure Cosmos DB | 30/7/2026 | 4/8/2026 | Improper access control in Azure Cosmos DB allows an unauthorized attacker to execute code over a network. | |
| Aplazada | Media (5.3) | 0.38% | — | Openc3 CosmosAI | 28/7/2026 | 30/7/2026 | Cosmos provides users the ability self-host a home server by acting as a secure gateway to your application, as well as a server manager. In 0.22.18, `GET /cosmos/api/constellation/public-devices` discloses Constellation device metadata to a requester that supplies any non-empty Authorization header. The handler… | |
| Analizada | Alta (8.1) | 0.49% | — | Openc3 Cosmos | 4/5/2026 | 17/6/2026 | OpenC3 COSMOS provides the functionality needed to send commands to and receive data from one or more embedded systems. Prior to version 7.0.0-rc3, the Script Runner widget allows users to execute Python and Ruby scripts directly from the openc3-COSMOS-script-runner-api container. Because all the docker containers… | |
| Analizada | Crítica (9.6) | 0.45% | — | Openc3 Cosmos | 4/5/2026 | 17/6/2026 | OpenC3 COSMOS provides the functionality needed to send commands to and receive data from one or more embedded systems. From version 6.7.0 to before version 7.0.0-rc3, a SQL injection vulnerability exists in the Time-Series Database (TSDB) component of COSMOS. The tsdb_lookup function in the cvt_model.rb file directly… | |
| Analizada | Media (4.6) | 0.29% | — | Openc3 Cosmos | 4/5/2026 | 17/6/2026 | OpenC3 COSMOS provides the functionality needed to send commands to and receive data from one or more embedded systems. Prior to version 7.0.0, the Command Sender UI uses an unsafe eval() function on array-like command parameters, which allows a user-supplied payload to execute in the browser when sending a command.… | |
| Analizada | Media (4.3) | 0.41% | — | Openc3 Cosmos | 4/5/2026 | 17/6/2026 | OpenC3 COSMOS provides the functionality needed to send commands to and receive data from one or more embedded systems. Prior to versions 6.10.5 and 7.0.0-rc3, OpenC3 COSMOS contains a design flaw in the save_tool_config() function that allows saving tool configuration files at arbitrary locations inside the shared… | |
| Analizada | Alta (8.1) | 0.44% | — | Openc3 Cosmos | 4/5/2026 | 17/6/2026 | OpenC3 COSMOS provides the functionality needed to send commands to and receive data from one or more embedded systems. Prior to versions 6.10.5 and 7.0.0-rc3, the OpenC3 password change functionality allows a user to change their password without providing the old password, by accepting a valid session token instead.… | |
| Aplazada | Crítica (10) | 0.63% | — | Openc3 CosmosAI | 13/1/2026 | 17/6/2026 | OpenC3 COSMOS provides the functionality needed to send commands to and receive data from one or more embedded systems. From 5.0.0 to 6.10.1, OpenC3 COSMOS contains a critical remote code execution vulnerability reachable through the JSON-RPC API. When a JSON-RPC request uses the string form of certain APIs,… | |
| Analizada | Crítica (9.6) | 0.71% | — | Microsoft Azure Cosmos DB | 19/12/2025 | 17/6/2026 | Improper neutralization of input during web page generation ('cross-site scripting') in Azure Cosmos DB allows an unauthorized attacker to perform spoofing over a network. | |
| Analizada | Crítica (9.8) | 0.60% | — | Openc3 Cosmos | 13/6/2025 | 17/6/2026 | Weak password requirements in OpenC3 COSMOS v6.0.0 allow attackers to bypass authentication via a brute force attack. | |
| Modificada | Crítica (9.8) | 0.61% | — | Openc3 Cosmos | 13/6/2025 | 17/6/2026 | OpenC3 COSMOS before v6.0.2 was discovered to contain hardcoded credentials for the Service Account. | |
| Analizada | Crítica (9.8) | 1.1% | — | Openc3 Cosmos | 13/6/2025 | 17/6/2026 | A remote code execution (RCE) vulnerability in the Plugin Management component of OpenC3 COSMOS v6.0.0 allows attackers to execute arbitrary code via uploading a crafted .txt file. | |
| Modificada | Crítica (9.1) | 0.89% | — | Openc3 Cosmos | 13/6/2025 | 17/6/2026 | An issue in the /script-api/scripts/ endpoint of OpenC3 COSMOS before 6.1.0 allows attackers to execute a directory traversal. | |
| Modificada | Alta (7.5) | 0.89% | — | Openc3 Cosmos | 13/6/2025 | 17/6/2026 | An issue in the openc3-api/tables endpoint of OpenC3 COSMOS before 6.1.0 allows attackers to execute a directory traversal. | |
| Modificada | Alta (7.5) | 0.52% | — | Openc3 Cosmos | 13/6/2025 | 17/6/2026 | A credential leak in OpenC3 COSMOS before v6.0.2 allows attackers to access service credentials as environment variables stored in all containers. | |
| Modificada | Media (6.1) | 0.34% | — | Openc3 Cosmos | 13/6/2025 | 17/6/2026 | A cross-site scripting (XSS) vulnerability in OpenC3 COSMOS before v6.0.2 allows attackers to execute arbitrary web scripts or HTML via injecting a crafted payload into the URL parameter. | |
| Aplazada | Media (6.9) | 0.63% | — | Openc3 CosmosAI | 20/1/2025 | 17/6/2026 | Cosmos provides users the ability self-host a home server by acting as a secure gateway to your application, as well as a server manager. By monitoring the error code returned in the login, it is possible to figure out whether a user exist or not in the database. Patched in 0.17.7. | |
| Aplazada | Media (6.5) | 0.29% | — | Cosmosfarm-share-buttonsAI | 1/12/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in 코스모스팜 – Cosmosfarm 소셜 공유 버튼 By 코스모스팜 cosmosfarm-share-buttons allows Stored XSS.This issue affects 소셜 공유 버튼 By 코스모스팜: from n/a through <= 1.9. | |
| Analizada | Media (4.8) | 0.35% | — | Openc3 Cosmos | 2/10/2024 | 17/6/2026 | OpenC3 COSMOS provides the functionality needed to send commands to and receive data from one or more embedded systems. OpenC3 COSMOS stores the password of a user unencrypted in the LocalStorage of a web browser. This makes the user password susceptible to exfiltration via Cross-site scripting (see GHSL-2024-128).… |