citeum
Security Risk Profile
Security Risk Score
Comprehensive risk assessment based on 22 vulnerabilities, EPSS scores, exploitation status, and remediation availability.
📅 Data spans from July 5, 2022 to present
Threat Assessment
Severity Distribution
Exploit Likelihood
Age Distribution
Common Weaknesses (CWE)
Most Affected Products
Recent Vulnerabilities
See more →OpenCTI: Elasticsearch Painless Script Injection via GraphQL `script` filter operator allows authenticated user to exfiltrate data and cause DoS
OpenCTI: Authorization Bypass via `synchronized-upsert` HTTP Header Injection
OpenCTI has XSS in the rendering of email-message observable body data
OpenCTI: Privilege escalation via graphQL API abusable by organization admins, due to incorrect ACL on userEdit relationAdd
OpenCTI privilege escalation and unauthenticated access via default admin account
OpenCTI affected by RCE via notifier template
OpenCTI's GraphQL Mutations Allow Deletion of Unrelated Entities
OpenCTI has a Semi-Blind SSRF via Unvalidated External URL in Data Ingestion Feature
OpenCTI 3.3.1 - Cross Site Scripting
OpenCTI 3.3.1 - Directory Traversal
Monitor citeum in Real-Time
Get instant alerts when new vulnerabilities are discovered. Stay ahead of security threats with SecAlerts.