openc3
Security Risk Profile
Security Risk Score
Comprehensive risk assessment based on 21 vulnerabilities, EPSS scores, exploitation status, and remediation availability.
📅 Data spans from October 2, 2024 to present
Threat Assessment
Severity Distribution
Exploit Likelihood
Age Distribution
Common Weaknesses (CWE)
Most Affected Products
Recent Vulnerabilities
See more →OpenC3 COSMOS: Authenticated remote code execution via the user-writable config overlay (table definitions, cmd/tlm definitions, and script suites)
OpenC3 COSMOS: Stored, cross-user XSS via Telemetry screen BUTTON widget
OpenC3 COSMOS: Authenticated OS command injection via the `pypi_url` setting
OpenC3 COSMOS: Administrative Actions via the Script Runner Tool
OpenC3 COSMOS: SQL Injection in QuestDB Time-Series Data Base
OpenC3 COSMOS: Self-XSS in the Command Sender
OpenC3 COSMOS: Arbitrary write to plugins directory via path-traversed config filenames
OpenC3 COSMOS: Hijacked session token can be used to reset password for persistence
Unauthenticated Remote Code Execution in openc3-api
Monitor openc3 in Real-Time
Get instant alerts when new vulnerabilities are discovered. Stay ahead of security threats with SecAlerts.