Vulnerabilidades em misp

67 resultados
Análise Vexday

MISP apresenta 37 vulnerabilidades catalogadas, todas publicadas nos últimos 90 dias, com 5 classificadas como críticas (CVSS alto). Não há registros de exploração ativa em campo (KEV), mas o volume recente e a dominância de falhas de autorização (CWE-863) indicam exposição significativa em ambientes de compartilhamento de inteligência de ameaças. Recomenda-se priorizar patches críticos e revisar controles de acesso.

CVE-2026-54361HIGHMISP mass assignment vulnerabilities allow unauthorized modification of ownership and delegation recordsEPSS 0.3%CVE-2026-56425CRITICALMISP AAD authentication plugin - Improper OAuth State Handling, Missing Session Rotation, Insecure Redirect URI Validation, and Log InjectionEPSS 0.3%CVE-2026-9806MEDIUMStored Cross-Site Scripting (XSS) in CTI Transmute Notification Panel via Malicious Convert NamesEPSS 0.3%CVE-2026-54395MEDIUMMISP UiBeta event index reflected XSS in advanced filter popupEPSS 0.3%CVE-2026-54357MEDIUMMISP improper authorization allows organization administrators to modify site administrator user settingsEPSS 0.3%CVE-2026-54396MEDIUMMISP AuthKey edit endpoint allows authenticated user email enumerationEPSS 0.2%CVE-2024-57969MEDIUMapp/Model/Attribute.php in MISP before 2.4.198 ignores an ACL during a GUI attribute search.EPSS 0.2%CVE-2026-61474MEDIUMMISP: Improper sharing group authorization check when adding attributesEPSS 0.2%CVE-2026-10868CRITICALMISP user edit endpoint mass assignment vulnerability allows unauthorized user account modificationEPSS 0.2%CVE-2026-62143HIGHServer-Side Request Forgery protection bypass in misp-modules html_to_markdown via IPv4-mapped IPv6 addressesEPSS 0.2%CVE-2026-9136HIGHUnauthorized ShadowAttribute modification in MISP via client-supplied identifierEPSS 0.2%CVE-2026-54358HIGHMISP organization administrators can target site administrator accounts for password resetEPSS 0.2%CVE-2026-54360HIGHMISP sharing group creation mass assignment allows unauthorized takeover of existing sharing groupsEPSS 0.2%CVE-2026-54397MEDIUMMISP event editing allows unauthorized assignment to undisclosed sharing groupsEPSS 0.2%CVE-2026-10863MEDIUMMISP User-controlled order parameter in correlations over-correlation endpointEPSS 0.2%CVE-2026-10861MEDIUMMISP post-login open redirect via pre_login_requested_urlEPSS 0.2%CVE-2026-60124MEDIUMMISP importModule missing authorization allows read-only users to modify events via misp_standard importsEPSS 0.2%CVE-2026-54398MEDIUMMISP object edit authorization bypass allows unauthorized sharing group assignmentEPSS 0.2%CVE-2024-58130HIGHIn app/Controller/Component/RestResponseComponent.php in MISP before 2.4.193, REST endpoints have a lack of sanitization for non-JSON responEPSS 0.2%CVE-2026-69082HIGHCross-Site Request Forgery in the Administrative User Deletion EndpointEPSS 0.2%