Vulnerability index

Browse CVEs

21 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Opencti HIGH 7.1
CVE-2026-35210

OpenCTI is an open source platform for managing cyber threat intelligence knowledge and observables. Prior to 7.260326.0, an authorization bypass vul…

Fix: 7.260326.0+
Fix from $1,950 2026-07-08
Opencti MEDIUM 6.5
CVE-2026-35211

OpenCTI is an open source platform for managing cyber threat intelligence knowledge and observables. Prior to 7.260401.0, the OpenCTI GraphQL API exp…

Fix: 7.260401.0+
Fix from $1,600 2026-07-08
Opencti MEDIUM 6.1
CVE-2026-35212

OpenCTI is an open source platform for managing cyber threat intelligence knowledge and observables. Versions prior to 7.260227.0 are vulnerable to X…

Fix: 7.260227.0+
Fix from $1,600 2026-06-02
Opencti HIGH 7.2
CVE-2026-44730

OpenCTI is an open source platform for managing cyber threat intelligence knowledge and observables. Prior to 6.9.7, an organization admin can escala…

Fix: 6.9.7+
Fix from $1,950 2026-05-26
Opencti CRITICAL 9.8
CVE-2026-27960

OpenCTI is an open source platform for managing cyber threat intelligence knowledge and observables. In versions 6.6.0 through 6.9.12, there is a pri…

Fix: 6.9.13+
Fix from $2,300 2026-05-05
Opencti HIGH 7.2
CVE-2026-39980

OpenCTI is an open source platform for managing cyber threat intelligence knowledge and observables. Prior to 6.9.5, the safeEjs.ts file does not pro…

Fix: 6.9.5+
Fix from $1,950 2026-04-09
Opencti HIGH 8.1
CVE-2026-21886

OpenCTI is an open source platform for managing cyber threat intelligence knowledge and observables. Prior to version 6.9.1, the GraphQL mutations "I…

Fix: 6.9.1+
Fix from $1,950 2026-03-17
Opencti HIGH 7.7
CVE-2026-21887

OpenCTI is an open source platform for managing cyber threat intelligence knowledge and observables. Prior to 6.8.16, the OpenCTI platform’s data ing…

Fix: 6.8.16+
Fix from $1,950 2026-03-12
Opencti MEDIUM 6.1
CVE-2020-37044

OpenCTI 3.3.1 is vulnerable to a reflected cross-site scripting (XSS) attack via the /graphql endpoint. An attacker can inject arbitrary JavaScript c…

No fix yet
Fix from $1,600 2026-01-30
Opencti HIGH 7.5
CVE-2020-37041

OpenCTI 3.3.1 is vulnerable to a directory traversal attack via the static/css endpoint. An unauthenticated attacker can read arbitrary files from th…

No fix yet
Fix from $1,950 2026-01-30
Opencti MEDIUM 6.1
CVE-2025-61782

OpenCTI is an open source platform for managing cyber threat intelligence knowledge and observables. Prior to version 6.8.3, an open redirect vulnera…

Fix: 6.8.3+
Fix from $1,600 2026-01-07
Opencti CRITICAL 9.1
CVE-2025-61781

OpenCTI is an open source platform for managing cyber threat intelligence knowledge and observables. Prior to version 6.8.1, the GraphQL mutation "Wo…

Fix: 6.8.1+
Fix from $2,300 2026-01-05
Opencti MEDIUM 5.4
CVE-2025-46732

OpenCTI is an open source platform for managing cyber threat intelligence knowledge and observables. Prior to version 6.6.6, an IDOR vulnerability in…

Fix: 6.6.6+
Fix from $1,600 2025-07-18
Opencti MEDIUM 6.8
CVE-2025-26621

OpenCTI is an open source platform for managing cyber threat intelligence knowledge and observables. Prior to version 6.5.2, any user with the capabi…

Fix: 6.5.2+
Fix from $1,600 2025-05-19
Opencti CRITICAL 9.1
CVE-2025-24977

OpenCTI is an open cyber threat intelligence (CTI) platform. Prior to version 6.4.11 any user with the capability `manage customizations` can execute…

Fix: 6.4.11+
Fix from $2,300 2025-05-05
Opencti MEDIUM 6.3
CVE-2025-24887

OpenCTI is an open-source cyber threat intelligence platform. In versions starting from 6.4.8 to before 6.4.10, the allow/deny lists can be bypassed,…

Fix: after 6.4.10
Fix from $1,600 2025-04-30
Opencti HIGH 8.1
CVE-2024-45404

OpenCTI is an open-source cyber threat intelligence platform. In versions below 6.2.18, because the function to limit the rate of OTP does not exist,…

Fix: 6.2.18+
Fix from $1,950 2024-12-12
Opencti HIGH 8.2
CVE-2024-37155

OpenCTI is an open source platform allowing organizations to manage their cyber threat intelligence knowledge and observables. Prior to version 6.1.9…

Fix: 6.1.9+
Fix from $1,950 2024-11-18
Opencti HIGH 8.1
CVE-2024-26139

OpenCTI is an open source platform allowing organizations to manage their cyber threat intelligence knowledge and observables. Due to lack of certain…

Fix: after 5.12.31
Fix from $1,950 2024-05-23
Opencti HIGH 7.5
CVE-2022-30290

In OpenCTI through 5.2.4, a broken access control vulnerability has been identified in the profile endpoint. An attacker can abuse the identified vul…

Fix: after 5.2.4
Fix from $1,950 2022-07-05
Opencti MEDIUM 5.4
CVE-2022-30289

A stored Cross-site Scripting (XSS) vulnerability was identified in the Data Import functionality of OpenCTI through 5.2.4. An attacker can abuse the…

Fix: after 5.2.4
Fix from $1,600 2022-07-05