Vulnerabilities in misp

144 results
Vexday analysis

MISP apresenta 37 vulnerabilidades catalogadas, todas publicadas nos últimos 90 dias, com 5 classificadas como críticas (CVSS alto). Não há registros de exploração ativa em campo (KEV), mas o volume recente e a dominância de falhas de autorização (CWE-863) indicam exposição significativa em ambientes de compartilhamento de inteligência de ameaças. Recomenda-se priorizar patches críticos e revisar controles de acesso.

CVE-2026-95661MEDIUMMISP Reflected Cross-Site Scripting in Attribute Histogram via Unescaped URL-Supplied Type ListEPSS 0.4%CVE-2026-71502MEDIUMUnauthenticated Stored Vue Template Injection Leads to Cross-Site Scripting in CTI-TransmuteEPSS 0.4%CVE-2026-95682MEDIUMMISP Stored Cross-Site Scripting via Unescaped Organization Name in Admin Email ViewEPSS 0.4%CVE-2026-95805MEDIUMMISP ACLComponent: Typo in previewEventAttributes ACL key bypasses intended access restrictionEPSS 0.4%CVE-2026-61474MEDIUMMISP: Improper sharing group authorization check when adding attributesEPSS 0.4%CVE-2026-95674MEDIUMMISP EventsController queryEnrichment allows querying unavailable or legacy modules without validationEPSS 0.4%CVE-2026-62143HIGHServer-Side Request Forgery protection bypass in misp-modules html_to_markdown via IPv4-mapped IPv6 addressesEPSS 0.4%CVE-2026-44380HIGHMISP: Improper access control in auth key reset allows privilege escalation to site administratorEPSS 0.4%CVE-2026-69079HIGHUnauthenticated Denial of Service via Unbounded Activity-Timeline Range in CTI-TransmuteEPSS 0.4%CVE-2026-95806HIGHMISP: PHP phar stream wrapper enables deserialization and code execution via caller-influenced filesystem pathsEPSS 0.4%CVE-2026-95659MEDIUMMISP Reflected XSS via Unvalidated Object Type in AnalystData Overmind ThreadEPSS 0.4%CVE-2026-95683MEDIUMMISP Overmind Event View Discloses Report Content Bypassing Report-Level ACLEPSS 0.4%CVE-2026-92002MEDIUMMISP: Authentication failure logging suppressed during Redis unavailabilityEPSS 0.4%CVE-2026-95697MEDIUMMISP: Insufficient Authorization Allows Sharing Group Editors to Overwrite Organization MetadataEPSS 0.4%CVE-2026-54393MEDIUMMISP Overmind theme stored XSS via unvalidated homepage settingEPSS 0.4%CVE-2026-94373MEDIUMMISP DOM-based Cross-Site Scripting via innerHTML in Contextual MenuEPSS 0.4%CVE-2026-60124MEDIUMMISP importModule missing authorization allows read-only users to modify events via misp_standard importsEPSS 0.4%CVE-2026-95671MEDIUMMISP Collections: Missing Authorization Check for Sharing Group on PUT Request in collections/addEPSS 0.4%CVE-2026-77761MEDIUMCross-Document Parser State Contamination in misp-stixEPSS 0.4%CVE-2026-9137MEDIUMCSP Report Endpoint Log Flooding in MISP via Incorrect Size LimitEPSS 0.4%