Vulnerabilidades em misp
145 resultadosAnálise Vexday
MISP apresenta 37 vulnerabilidades catalogadas, todas publicadas nos últimos 90 dias, com 5 classificadas como críticas (CVSS alto). Não há registros de exploração ativa em campo (KEV), mas o volume recente e a dominância de falhas de autorização (CWE-863) indicam exposição significativa em ambientes de compartilhamento de inteligência de ameaças. Recomenda-se priorizar patches críticos e revisar controles de acesso.
CVE-2026-73157LOWcti-transmute Remote MISP Event Browser Allows Cross-Site Scripting via Malicious Event MetadataEPSS 0.4%CVE-2026-53693MEDIUMMISP BSimVis stored cross-site scripting in tag and cluster rendering paths via unescaped tag metadata and UI labelsEPSS 0.4%CVE-2026-54394MEDIUMMISP organisation logo path traversal allows retrieval of arbitrary PNG/SVG filesEPSS 0.4%CVE-2026-9806MEDIUMStored Cross-Site Scripting (XSS) in CTI Transmute Notification Panel via Malicious Convert NamesEPSS 0.4%CVE-2026-95661MEDIUMMISP Reflected Cross-Site Scripting in Attribute Histogram via Unescaped URL-Supplied Type ListEPSS 0.4%CVE-2026-54357MEDIUMMISP improper authorization allows organization administrators to modify site administrator user settingsEPSS 0.4%CVE-2026-86347HIGHMISP Missing Authorization on Template File Upload Allows Authenticated Disk ExhaustionEPSS 0.4%CVE-2026-95682MEDIUMMISP Stored Cross-Site Scripting via Unescaped Organization Name in Admin Email ViewEPSS 0.4%CVE-2026-86419HIGHMISP Insufficient Outbound URL Validation Allows SSRF and Credential Disclosure via Feed Redirects and TAXII DiscoveryEPSS 0.4%CVE-2026-61474MEDIUMMISP: Improper sharing group authorization check when adding attributesEPSS 0.4%CVE-2026-95805MEDIUMMISP ACLComponent: Typo in previewEventAttributes ACL key bypasses intended access restrictionEPSS 0.4%CVE-2026-85538HIGHMISP Attribute Deletion Authorization Bypass Allows Users Without Modify Permissions to Delete AttributesEPSS 0.4%CVE-2026-69078HIGHServer-Side Request Forgery and Local File Disclosure in CTI-Transmute Evaluation PDF RenderingEPSS 0.4%CVE-2026-95674MEDIUMMISP EventsController queryEnrichment allows querying unavailable or legacy modules without validationEPSS 0.4%CVE-2026-73160HIGHcti-transmute Unauthenticated SSRF via Hostnames Resolving to Internal IP AddressesEPSS 0.4%CVE-2026-54361HIGHMISP mass assignment vulnerabilities allow unauthorized modification of ownership and delegation recordsEPSS 0.4%CVE-2026-62143HIGHServer-Side Request Forgery protection bypass in misp-modules html_to_markdown via IPv4-mapped IPv6 addressesEPSS 0.4%CVE-2026-54395MEDIUMMISP UiBeta event index reflected XSS in advanced filter popupEPSS 0.4%CVE-2026-73161MEDIUMcti-transmute Conversion Table Allows XSS via Unescaped Cell Content During Search HighlightingEPSS 0.4%CVE-2026-73158MEDIUMcti-transmute Saved Graph Configuration Allows Stored Cross-Site Scripting via svgIconEPSS 0.4%