Vulnerabilities in MISP

145 results
Vexday analysis

O MISP apresenta 13 vulnerabilidades catalogadas, sendo 5 divulgadas nos últimos 90 dias, o que indica atividade contínua de descoberta de falhas. Embora nenhuma esteja sob ataque ativo no momento, 2 vulnerabilidades críticas e a predominância de injeção de conteúdo (CWE-79) requerem atenção, especialmente considerando o papel estratégico da plataforma em ecossistemas de compartilhamento de inteligência de ameaças.

CVE-2026-95754MEDIUMMISP: Disabled-user check ineffective in pre-authentication TOTP login branchEPSS 0.5%CVE-2026-86452HIGHMISP Unauthenticated Mail Endpoints Allow Unbounded Storage Consumption and Request FloodingEPSS 0.5%CVE-2026-95665MEDIUMMISP Reflected Cross-Site Scripting in Event Export Confirmation Form via Unescaped JSONEPSS 0.5%CVE-2026-92002MEDIUMMISP: Authentication failure logging suppressed during Redis unavailabilityEPSS 0.5%CVE-2026-56424HIGHBroken access control in MISP core allows cross-organization unauthorized modification or deletion of analyst data, event reports, collections, templates, and decaying modelsEPSS 0.5%CVE-2026-95693MEDIUMMISP Information Disclosure via Forged Upload PathEPSS 0.5%CVE-2026-94383HIGHMISP Blocklist Workflow Module: Arbitrary Script Execution via Unrestricted File ExtensionEPSS 0.5%CVE-2026-95703MEDIUMMISP OrganisationsController File Existence and Image-Type Oracle via Forged Upload tmp_nameEPSS 0.5%CVE-2026-77710MEDIUMSTIX2 Parser Confusion and Mass Assignment Allow Unauthorized MISP Attribute Metadata Injection in misp-stix libraryEPSS 0.5%CVE-2026-88921MEDIUMMISP: Unescaped HTML Injection in PDF Report Element RenderingEPSS 0.5%CVE-2026-72759MEDIUMcti-transmute Conversion History Authorization Bypass Leads to Sensitive Data Disclosure After Conversion DeletionEPSS 0.5%CVE-2026-91859MEDIUMMISP Access Log Entry Overwritten by Error Controller's Second beforeFilter PassEPSS 0.5%CVE-2026-77755HIGHDenial of Service in MISP-STIX Import via Malformed or Oversized STIX Documents in misp-stix libraryEPSS 0.5%CVE-2026-56423CRITICALMISP Core: Broken access control allows instance-wide unauthorized deletion of event reports and sharing groups via bulk deletion endpointsEPSS 0.5%CVE-2026-56425CRITICALMISP AAD authentication plugin - Improper OAuth State Handling, Missing Session Rotation, Insecure Redirect URI Validation, and Log InjectionEPSS 0.5%CVE-2026-9137MEDIUMCSP Report Endpoint Log Flooding in MISP via Incorrect Size LimitEPSS 0.5%CVE-2026-85237HIGHMissing Rate Limiting in Email OTP Verification Allows Brute-Force Authentication BypassEPSS 0.5%CVE-2026-72751MEDIUMStored Cross-Site Scripting in CTI-Transmute Conversion Graph via Malicious STIX/MISP ContentEPSS 0.5%CVE-2026-85239HIGHMISP Event Template Definition Validation Bypass Allows Persistent Denial of ServiceEPSS 0.4%CVE-2026-73156MEDIUMcti-transmute Sunburst and Treemap Tooltips Allow Cross-Site Scripting via Crafted Conversion DataEPSS 0.4%