Vulnerabilidades em misp
67 resultadosAnálise Vexday
MISP apresenta 37 vulnerabilidades catalogadas, todas publicadas nos últimos 90 dias, com 5 classificadas como críticas (CVSS alto). Não há registros de exploração ativa em campo (KEV), mas o volume recente e a dominância de falhas de autorização (CWE-863) indicam exposição significativa em ambientes de compartilhamento de inteligência de ameaças. Recomenda-se priorizar patches críticos e revisar controles de acesso.
CVE-2024-58129MEDIUMIn MISP before 2.4.193, menu_custom_right_link_html parameters can be set via the UI (i.e., without using the CLI) and thus attackers with aEPSS 0.2%CVE-2024-58128MEDIUMIn MISP before 2.4.193, menu_custom_right_link parameters can be set via the UI (i.e., without using the CLI) and thus attackers with admin EPSS 0.2%CVE-2026-54362MEDIUMMISP template builder exposes non-visible custom galaxies across organisationsEPSS 0.2%CVE-2026-60125MEDIUMimportModule function in MISP ignores per-organisation import module restrictionsEPSS 0.2%CVE-2026-10860HIGHMISP CRUDComponent delete validation bypass via operator precedence errorEPSS 0.2%CVE-2026-54359HIGHMISP automation endpoints may be exposed to CSRF when Sec-Fetch-Site protection is disabled by defaultEPSS 0.2%CVE-2026-44364CRITICALmisp-modules website - Missing CSRF protection in the website home blueprintEPSS 0.2%CVE-2026-9084MEDIUMMISP OIDC authentication bypass via automatic email-based account linking under insecure IdP configurationsEPSS 0.2%CVE-2026-44379MEDIUMMISP: Improper UUID validation in MISP CollectionsEPSS 0.2%CVE-2026-10864MEDIUMMISP Dashboard widget field selection may expose restricted user and organisation dataEPSS 0.2%CVE-2026-10854MEDIUMUnauthorized exposure of private galaxies in MISP event template creationEPSS 0.2%CVE-2026-10855MEDIUMMISP Event template importer authorization bypassEPSS 0.2%CVE-2026-10856MEDIUMOpen redirect in MISP dashboard button widget URL handlingEPSS 0.1%CVE-2026-8080MEDIUMMISP core - Stored XSS in MISP template (old engine) element attribute typeEPSS 0.1%CVE-2026-44363MEDIUMUnsafe remote resource fetching in expansion misp-modulesEPSS 0.1%CVE-2026-73161MEDIUMcti-transmute Conversion Table Allows XSS via Unescaped Cell Content During Search HighlightingEPSS —CVE-2026-73162MEDIUMcti-transmute CSRF Allows Unauthorized Follow and Notification State ChangesEPSS —CVE-2026-73140MEDIUMcti-transmute Evaluation Report Exports Expose Private Comments and Author InformationEPSS —CVE-2026-72759MEDIUMcti-transmute Conversion History Authorization Bypass Leads to Sensitive Data Disclosure After Conversion DeletionEPSS —CVE-2026-73160HIGHcti-transmute Unauthenticated SSRF via Hostnames Resolving to Internal IP AddressesEPSS —