Vulnerabilidades en misp
145 resultadosAnálisis Vexday
MISP apresenta 37 vulnerabilidades catalogadas, todas publicadas nos últimos 90 dias, com 5 classificadas como críticas (CVSS alto). Não há registros de exploração ativa em campo (KEV), mas o volume recente e a dominância de falhas de autorização (CWE-863) indicam exposição significativa em ambientes de compartilhamento de inteligência de ameaças. Recomenda-se priorizar patches críticos e revisar controles de acesso.
CVE-2026-85216CRITICALMISP LDAP and LinOTP Authentication Bypass via Empty or Invalid CredentialsEPSS 0.9%CVE-2026-95701MEDIUMMISP Path Traversal via Organization Name in Org-Statistics Logo CheckEPSS 0.8%CVE-2026-44381CRITICALMISP: SQL injection via unvalidated ordering parameters in event and shadow attribute listingsEPSS 0.8%CVE-2026-71502MEDIUMUnauthenticated Stored Vue Template Injection Leads to Cross-Site Scripting in CTI-TransmuteEPSS 0.7%CVE-2026-95698MEDIUMMISP Path Traversal in OrgImgHelper findOrgImage via Crafted Organization NameEPSS 0.7%CVE-2026-56446HIGHAuthenticated Remote Code Execution via Arbitrary NDJSON Error Log Path in MISPEPSS 0.7%CVE-2026-67178HIGHOpen Redirect in MISP Installer-Generated Apache ConfigurationEPSS 0.7%CVE-2026-77751HIGHPath Traversal in MISP Object Template Resolution During STIX Import and Export in misp-stix libraryEPSS 0.7%CVE-2026-39962HIGHLDAP injection in MISP ApacheAuthenticate when using a user-controlled Apache environment variableEPSS 0.7%CVE-2026-90961CRITICALMISP LdapAuth and LinOTPAuth Authentication Bypass via Empty or Non-String CredentialsEPSS 0.6%CVE-2026-93295HIGHMISP Background Job Argument Injection via Console Path Switches Enables Remote Code ExecutionEPSS 0.6%CVE-2026-54393MEDIUMMISP Overmind theme stored XSS via unvalidated homepage settingEPSS 0.6%CVE-2026-56447CRITICALMISP remote code execution via arbitrary rdkafka configuration pathEPSS 0.6%CVE-2026-77761MEDIUMCross-Document Parser State Contamination in misp-stixEPSS 0.6%CVE-2026-56422CRITICALMISP Core: Mass Assignment and Object Re-ownership via Unvalidated Request FieldsEPSS 0.6%CVE-2026-95679MEDIUMMISP Unauthenticated Blind SSRF via XML Body ProcessingEPSS 0.6%CVE-2026-44380HIGHMISP: Improper access control in auth key reset allows privilege escalation to site administratorEPSS 0.6%CVE-2026-94379MEDIUMMISP: HTTP Method Bypass of Login Security Controls (Bruteforce Protection and Email OTP)EPSS 0.6%CVE-2026-92003MEDIUMMISP Unthrottled Authentication Failure Log Writes Enable Resource ExhaustionEPSS 0.6%CVE-2026-69079HIGHUnauthenticated Denial of Service via Unbounded Activity-Timeline Range in CTI-TransmuteEPSS 0.5%