OpenCTI
Security Risk Profile
Security Risk Score
Comprehensive risk assessment based on 18 vulnerabilities, EPSS scores, exploitation status, and remediation availability.
📅 Data spans from May 23, 2024 to present
Threat Assessment
Severity Distribution
Exploit Likelihood
Age Distribution
Common Weaknesses (CWE)
Most Affected Products
Recent Vulnerabilities
See more →OpenCTI: Synchronizer SSRF: stream fetch has no URL validation
OpenCTI: Elasticsearch Painless Script Injection via GraphQL `script` filter operator allows authenticated user to exfiltrate data and cause DoS
OpenCTI: Authorization Bypass via `synchronized-upsert` HTTP Header Injection
OpenCTI has XSS in the rendering of email-message observable body data
OpenCTI: Privilege escalation via graphQL API abusable by organization admins, due to incorrect ACL on userEdit relationAdd
OpenCTI privilege escalation and unauthenticated access via default admin account
OpenCTI affected by RCE via notifier template
OpenCTI's GraphQL Mutations Allow Deletion of Unrelated Entities
OpenCTI 3.3.1 - Cross Site Scripting
Open Redirect in OpenCTI's SAML Authentication Flow
Monitor OpenCTI in Real-Time
Get instant alerts when new vulnerabilities are discovered. Stay ahead of security threats with SecAlerts.