Vulnerabilidades em misp
114 resultadosAnálise Vexday
MISP apresenta 37 vulnerabilidades catalogadas, todas publicadas nos últimos 90 dias, com 5 classificadas como críticas (CVSS alto). Não há registros de exploração ativa em campo (KEV), mas o volume recente e a dominância de falhas de autorização (CWE-863) indicam exposição significativa em ambientes de compartilhamento de inteligência de ameaças. Recomenda-se priorizar patches críticos e revisar controles de acesso.
CVE-2026-86441LOWMISP Dashboard Organisation Widgets Bypass Organisation-Index Restrictions and Expose Hidden Organisation DataEPSS 0.2%CVE-2026-86418LOWMISP Dashboard Organisation Picker Exposes Hidden Organisation Metadata to Unauthorized UsersEPSS 0.2%CVE-2026-86417MEDIUMMISP Dashboard Template REST API Exposes Template Owner Email Addresses to Unauthorized UsersEPSS 0.2%CVE-2026-91819MEDIUMMISP: HTTP Method Override Bypasses CSRF and Form Validation in BetterSecurityComponentEPSS 0.2%CVE-2026-85227MEDIUMReflected Cross-Site Scripting in MISP Event Filtering via taggedAttributes and galaxyAttachedAttributes ParametersEPSS 0.2%CVE-2026-10855MEDIUMMISP Event template importer authorization bypassEPSS 0.2%CVE-2026-90895HIGHMISP Interactive CLI Shell: Authorization Bypass, Credential Exposure, and Terminal InjectionEPSS 0.2%CVE-2026-85226MEDIUMMISP OnDemand Correlation Engine Missing Access Control Allows Disclosure of Restricted CorrelationsEPSS 0.2%CVE-2026-10856MEDIUMOpen redirect in MISP dashboard button widget URL handlingEPSS 0.1%CVE-2026-85221HIGHMISP CurlClient TLS Peer Verification Disabled by Default Enables Man-in-the-Middle AttacksEPSS 0.1%CVE-2026-8080MEDIUMMISP core - Stored XSS in MISP template (old engine) element attribute typeEPSS 0.1%CVE-2026-86440MEDIUMMISP Dashboard Button Widget Allows Stored XSS via Unsafe javascript: and Backslash URLsEPSS 0.1%CVE-2026-90955MEDIUMMISP CLI Shell Audit Logs Lose User Identity and CLI Marker After First Lazy Model LoadEPSS 0.1%CVE-2026-44363MEDIUMUnsafe remote resource fetching in expansion misp-modulesEPSS 0.1%