Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2741▲ 13 respecto a la semana anterior
Críticas / altas1459▲ 323 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)85▼ 441 respecto a la semana anterior
–

37 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaCrítica (9.9)0.57%—Openc3 CosmosAI23/9/202629/9/2026
OpenC3 COSMOS provides the functionality needed to send commands to and receive data from one or more embedded systems. From 5.1.0 until 7.3.0, authenticated non-administrator users can write content under targets_modified/ that is later executed by multiple configuration paths below the intended code-execution…
AplazadaAlta (8.8)0.58%—Openc3 CosmosAI23/9/202623/9/2026
OpenC3 COSMOS provides the functionality needed to send commands to and receive data from one or more embedded systems. From 5.12.0 until 7.3.0, an authenticated actor can write the pypi_url setting through set_setting at POST /openc3-api/api, then cause OpenC3::PluginModel.install_phase2 in…
AplazadaAlta (7.6)0.39%—Openc3 CosmosAI23/9/202623/9/2026
OpenC3 COSMOS provides the functionality needed to send commands to and receive data from one or more embedded systems. From 5.0.6 until 7.3.0, an authenticated actor with system_set permission can store a shared screen through POST /openc3-api/screen whose BUTTON widget action is evaluated by…
AnalizadaCrítica (9.6)0.79%—Microsoft Azure Cosmos DB17/9/202629/9/2026
Improper neutralization of special elements in output used by a downstream component ('injection') in Azure Cosmos DB allows an authorized attacker to elevate privileges over a network.
AplazadaMedia (6.1)0.30%—Openc3 CosmosAI15/9/202630/9/2026
Cosmos provides users the ability self-host a home server by acting as a secure gateway to your application, as well as a server manager. Prior to 0.22.19, tokenMiddleware in src/proxy/routerGen.go can return through the Constellation tunnel bypass before removing x-cosmos-user, x-cosmos-role, x-cosmos-user-role, and…
AnalizadaAlta (8.8)0.63%—Microsoft Azure Cosmos DB3/9/20269/9/2026
Authorization bypass through user-controlled key in Azure Cosmos DB allows an authorized attacker to perform spoofing over a network.
AnalizadaCrítica (10)0.90%—Microsoft Azure Cosmos DB30/7/20264/8/2026
Improper access control in Azure Cosmos DB allows an unauthorized attacker to execute code over a network.
AplazadaMedia (5.3)0.38%—Openc3 CosmosAI28/7/202630/7/2026
Cosmos provides users the ability self-host a home server by acting as a secure gateway to your application, as well as a server manager. In 0.22.18, `GET /cosmos/api/constellation/public-devices` discloses Constellation device metadata to a requester that supplies any non-empty Authorization header. The handler…
AnalizadaAlta (8.1)0.49%—Openc3 Cosmos4/5/202617/6/2026
OpenC3 COSMOS provides the functionality needed to send commands to and receive data from one or more embedded systems. Prior to version 7.0.0-rc3, the Script Runner widget allows users to execute Python and Ruby scripts directly from the openc3-COSMOS-script-runner-api container. Because all the docker containers…
AnalizadaCrítica (9.6)0.45%—Openc3 Cosmos4/5/202617/6/2026
OpenC3 COSMOS provides the functionality needed to send commands to and receive data from one or more embedded systems. From version 6.7.0 to before version 7.0.0-rc3, a SQL injection vulnerability exists in the Time-Series Database (TSDB) component of COSMOS. The tsdb_lookup function in the cvt_model.rb file directly…
AnalizadaMedia (4.6)0.29%—Openc3 Cosmos4/5/202617/6/2026
OpenC3 COSMOS provides the functionality needed to send commands to and receive data from one or more embedded systems. Prior to version 7.0.0, the Command Sender UI uses an unsafe eval() function on array-like command parameters, which allows a user-supplied payload to execute in the browser when sending a command.…
AnalizadaMedia (4.3)0.41%—Openc3 Cosmos4/5/202617/6/2026
OpenC3 COSMOS provides the functionality needed to send commands to and receive data from one or more embedded systems. Prior to versions 6.10.5 and 7.0.0-rc3, OpenC3 COSMOS contains a design flaw in the save_tool_config() function that allows saving tool configuration files at arbitrary locations inside the shared…
AnalizadaAlta (8.1)0.44%—Openc3 Cosmos4/5/202617/6/2026
OpenC3 COSMOS provides the functionality needed to send commands to and receive data from one or more embedded systems. Prior to versions 6.10.5 and 7.0.0-rc3, the OpenC3 password change functionality allows a user to change their password without providing the old password, by accepting a valid session token instead.…
AplazadaCrítica (10)0.63%—Openc3 CosmosAI13/1/202617/6/2026
OpenC3 COSMOS provides the functionality needed to send commands to and receive data from one or more embedded systems. From 5.0.0 to 6.10.1, OpenC3 COSMOS contains a critical remote code execution vulnerability reachable through the JSON-RPC API. When a JSON-RPC request uses the string form of certain APIs,…
AnalizadaCrítica (9.6)0.71%—Microsoft Azure Cosmos DB19/12/202517/6/2026
Improper neutralization of input during web page generation ('cross-site scripting') in Azure Cosmos DB allows an unauthorized attacker to perform spoofing over a network.
AnalizadaCrítica (9.8)0.60%—Openc3 Cosmos13/6/202517/6/2026
Weak password requirements in OpenC3 COSMOS v6.0.0 allow attackers to bypass authentication via a brute force attack.
ModificadaCrítica (9.8)0.61%—Openc3 Cosmos13/6/202517/6/2026
OpenC3 COSMOS before v6.0.2 was discovered to contain hardcoded credentials for the Service Account.
AnalizadaCrítica (9.8)1.1%—Openc3 Cosmos13/6/202517/6/2026
A remote code execution (RCE) vulnerability in the Plugin Management component of OpenC3 COSMOS v6.0.0 allows attackers to execute arbitrary code via uploading a crafted .txt file.
ModificadaCrítica (9.1)0.89%—Openc3 Cosmos13/6/202517/6/2026
An issue in the /script-api/scripts/ endpoint of OpenC3 COSMOS before 6.1.0 allows attackers to execute a directory traversal.
ModificadaAlta (7.5)0.89%—Openc3 Cosmos13/6/202517/6/2026
An issue in the openc3-api/tables endpoint of OpenC3 COSMOS before 6.1.0 allows attackers to execute a directory traversal.
ModificadaAlta (7.5)0.52%—Openc3 Cosmos13/6/202517/6/2026
A credential leak in OpenC3 COSMOS before v6.0.2 allows attackers to access service credentials as environment variables stored in all containers.
ModificadaMedia (6.1)0.34%—Openc3 Cosmos13/6/202517/6/2026
A cross-site scripting (XSS) vulnerability in OpenC3 COSMOS before v6.0.2 allows attackers to execute arbitrary web scripts or HTML via injecting a crafted payload into the URL parameter.
AplazadaMedia (6.9)0.63%—Openc3 CosmosAI20/1/202517/6/2026
Cosmos provides users the ability self-host a home server by acting as a secure gateway to your application, as well as a server manager. By monitoring the error code returned in the login, it is possible to figure out whether a user exist or not in the database. Patched in 0.17.7.
AplazadaMedia (6.5)0.29%—Cosmosfarm-share-buttonsAI1/12/202417/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in 코스모스팜 – Cosmosfarm 소셜 공유 버튼 By 코스모스팜 cosmosfarm-share-buttons allows Stored XSS.This issue affects 소셜 공유 버튼 By 코스모스팜: from n/a through <= 1.9.
AnalizadaMedia (4.8)0.35%—Openc3 Cosmos2/10/202417/6/2026
OpenC3 COSMOS provides the functionality needed to send commands to and receive data from one or more embedded systems. OpenC3 COSMOS stores the password of a user unencrypted in the LocalStorage of a web browser. This makes the user password susceptible to exfiltration via Cross-site scripting (see GHSL-2024-128).…