Vulnerability index

Browse CVEs

13 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Cosmos HIGH 8.1
CVE-2026-42088

OpenC3 COSMOS provides the functionality needed to send commands to and receive data from one or more embedded systems. Prior to version 7.0.0-rc3, t…

Fix: 7.0.0+
Fix from $1,950 2026-05-04
Cosmos CRITICAL 9.6
CVE-2026-42087

OpenC3 COSMOS provides the functionality needed to send commands to and receive data from one or more embedded systems. From version 6.7.0 to before …

Fix: 7.0.0+
Fix from $2,300 2026-05-04
Cosmos HIGH 8.1
CVE-2026-42084

OpenC3 COSMOS provides the functionality needed to send commands to and receive data from one or more embedded systems. Prior to versions 6.10.5 and …

Fix: 6.10.5+
Fix from $1,950 2026-05-04
Cosmos CRITICAL 9.8
CVE-2025-28389

Weak password requirements in OpenC3 COSMOS v6.0.0 allow attackers to bypass authentication via a brute force attack.

Mitigation only
Fix from $2,300 2025-06-13
Cosmos CRITICAL 9.8
CVE-2025-28386

A remote code execution (RCE) vulnerability in the Plugin Management component of OpenC3 COSMOS v6.0.0 allows attackers to execute arbitrary code via…

Mitigation only
Fix from $2,300 2025-06-13
Cosmos CRITICAL 9.8
CVE-2025-28388

OpenC3 COSMOS before v6.0.2 was discovered to contain hardcoded credentials for the Service Account.

Patch available
Fix from $2,300 2025-06-13
Cosmos CRITICAL 9.1
CVE-2025-28384

An issue in the /script-api/scripts/ endpoint of OpenC3 COSMOS before 6.1.0 allows attackers to execute a directory traversal.

Patch available
Fix from $2,300 2025-06-13
Cosmos HIGH 7.5
CVE-2025-28381

A credential leak in OpenC3 COSMOS before v6.0.2 allows attackers to access service credentials as environment variables stored in all containers.

Patch available
Fix from $1,950 2025-06-13
Cosmos HIGH 7.5
CVE-2025-28382

An issue in the openc3-api/tables endpoint of OpenC3 COSMOS before 6.1.0 allows attackers to execute a directory traversal.

Patch available
Fix from $1,950 2025-06-13
Cosmos MEDIUM 6.1
CVE-2025-28380

A cross-site scripting (XSS) vulnerability in OpenC3 COSMOS before v6.0.2 allows attackers to execute arbitrary web scripts or HTML via injecting a c…

Patch available
Fix from $1,600 2025-06-13
Cosmos MEDIUM 6.5
CVE-2024-46977

OpenC3 COSMOS provides the functionality needed to send commands to and receive data from one or more embedded systems. A path traversal vulnerabilit…

Fix: 5.19.0+
Fix from $1,600 2024-10-02
Cosmos MEDIUM 6.5
CVE-2024-47529

OpenC3 COSMOS provides the functionality needed to send commands to and receive data from one or more embedded systems. OpenC3 COSMOS stores the pass…

Fix: 5.19.0+
Fix from $1,600 2024-10-02
Cosmos MEDIUM 6.1
CVE-2024-43795

OpenC3 COSMOS provides the functionality needed to send commands to and receive data from one or more embedded systems. The login functionality conta…

Fix: 5.19.0+
Fix from $1,600 2024-10-02