CVE-2026-35212
- EPSS 0.15%
- Veröffentlicht 02.06.2026 21:28:59
- Zuletzt bearbeitet 05.06.2026 13:07:04
OpenCTI is an open source platform for managing cyber threat intelligence knowledge and observables. Versions prior to 7.260227.0 are vulnerable to XSS in the rendering of email-message observable body data. The content of the body field isn't approp...
CVE-2026-44730
- EPSS 0.32%
- Veröffentlicht 26.05.2026 17:03:55
- Zuletzt bearbeitet 27.05.2026 15:40:38
OpenCTI is an open source platform for managing cyber threat intelligence knowledge and observables. Prior to 6.9.7, an organization admin can escalate their privileges by adding a user from a different organization with higher privileges, to their o...
CVE-2026-27960
- EPSS 0.48%
- Veröffentlicht 05.05.2026 18:35:41
- Zuletzt bearbeitet 12.05.2026 13:45:07
OpenCTI is an open source platform for managing cyber threat intelligence knowledge and observables. In versions 6.6.0 through 6.9.12, there is a privilege escalation vulnerability that can be exploited by unauthenticated attackers to query the API a...
CVE-2026-39980
- EPSS 0.52%
- Veröffentlicht 09.04.2026 18:17:02
- Zuletzt bearbeitet 22.04.2026 00:27:12
OpenCTI is an open source platform for managing cyber threat intelligence knowledge and observables. Prior to 6.9.5, the safeEjs.ts file does not properly sanitize EJS templates. Users with the Manage customization capability can run arbitrary JavaSc...
CVE-2026-21886
- EPSS 0.23%
- Veröffentlicht 17.03.2026 15:26:30
- Zuletzt bearbeitet 19.03.2026 19:33:27
OpenCTI is an open source platform for managing cyber threat intelligence knowledge and observables. Prior to version 6.9.1, the GraphQL mutations "IndividualDeletionDeleteMutation" is intended to allow users to delete individual entity objects respe...
CVE-2026-21887
- EPSS 0.21%
- Veröffentlicht 12.03.2026 17:16:36
- Zuletzt bearbeitet 19.03.2026 17:39:31
OpenCTI is an open source platform for managing cyber threat intelligence knowledge and observables. Prior to 6.8.16, the OpenCTI platform’s data ingestion feature accepts user-supplied URLs without validation and uses the Axios HTTP client with its ...
CVE-2020-37044
- EPSS 0.35%
- Veröffentlicht 30.01.2026 22:07:16
- Zuletzt bearbeitet 13.02.2026 17:55:30
OpenCTI 3.3.1 is vulnerable to a reflected cross-site scripting (XSS) attack via the /graphql endpoint. An attacker can inject arbitrary JavaScript code by sending a crafted GET request with a malicious payload in the query string, leading to executi...
CVE-2020-37041
- EPSS 0.98%
- Veröffentlicht 30.01.2026 22:07:15
- Zuletzt bearbeitet 13.02.2026 17:56:55
OpenCTI 3.3.1 is vulnerable to a directory traversal attack via the static/css endpoint. An unauthenticated attacker can read arbitrary files from the filesystem by sending crafted GET requests with path traversal sequences (e.g., '../') in the URL. ...
CVE-2025-61782
- EPSS 0.22%
- Veröffentlicht 07.01.2026 17:28:53
- Zuletzt bearbeitet 20.01.2026 18:50:03
OpenCTI is an open source platform for managing cyber threat intelligence knowledge and observables. Prior to version 6.8.3, an open redirect vulnerability exists in the OpenCTI platform's SAML authentication endpoint (/auth/saml/callback). By manipu...
CVE-2025-61781
- EPSS 0.2%
- Veröffentlicht 05.01.2026 17:53:23
- Zuletzt bearbeitet 30.01.2026 01:18:17
OpenCTI is an open source platform for managing cyber threat intelligence knowledge and observables. Prior to version 6.8.1, the GraphQL mutation "WorkspacePopoverDeletionMutation" allows users to delete workspace-related objects such as dashboards a...