Vulnerability index

Browse CVEs

107 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Misp MEDIUM 6.1
CVE-2019-11813

An issue was discovered in app/View/Elements/Events/View/value_field.ctp in MISP before 2.4.107. There is persistent XSS via link type attributes wit…

Fix: 2.4.107+
Fix from $1,600 2019-05-08
Misp MEDIUM 6.1
CVE-2019-11814

An issue was discovered in app/webroot/js/misp.js in MISP before 2.4.107. There is persistent XSS via image names in titles, as demonstrated by a scr…

Fix: 2.4.107+
Fix from $1,600 2019-05-08
Misp MEDIUM 6.1
CVE-2019-10254

In MISP before 2.4.105, the app/View/Layouts/default.ctp default layout template has a Reflected XSS vulnerability.

Fix: 2.4.105+
Fix from $1,600 2019-03-28
Misp MEDIUM 5.3
CVE-2019-9482

In MISP 2.4.102, an authenticated user can view sightings that they should not be eligible for. Exploiting this requires access to the event that has…

Patch available
Fix from $1,600 2019-03-01
Misp HIGH 8.8
CVE-2018-19908EPSS 17%

An issue was discovered in MISP 2.4.9x before 2.4.99. In app/Model/Event.php (the STIX 1 import code), an unescaped filename string is used to constr…

Fix: 2.4.99+
Fix from $1,950 2018-12-06
Misp CRITICAL 9.8
CVE-2018-12649

An issue was discovered in app/Controller/UsersController.php in MISP 2.4.92. An adversary can bypass the brute-force protection by using a PUT HTTP …

Patch available
Fix from $2,300 2018-06-22
Misp MEDIUM 6.1
CVE-2018-11562

An issue was discovered in MISP 2.4.91. A vulnerability in app/View/Elements/eventattribute.ctp allows reflected XSS if a user clicks on a malicious …

Patch available
Fix from $1,600 2018-05-30
Misp MEDIUM 6.1
CVE-2018-11245

app/webroot/js/misp.js in MISP 2.4.91 has a DOM based XSS with cortex type attributes.

Patch available
Fix from $1,600 2018-05-18
Misp MEDIUM 6.1
CVE-2018-8948

In MISP before 2.4.89, app/View/Events/resolved_attributes.ctp has multiple XSS issues via a malicious MISP module.

Fix: 2.4.89+
Fix from $1,600 2018-03-23
Misp HIGH 7.2
CVE-2018-6926

In app/Controller/ServersController.php in MISP 2.4.87, a server setting permitted the override of a path variable on certain Red Hed Enterprise Linu…

Patch available
Fix from $1,950 2018-02-12
Misp MEDIUM 5.4
CVE-2017-16802

In the sharingGroupPopulateOrganisations function in app/webroot/js/misp.js in MISP 2.4.82, there is XSS via a crafted organisation name that is manu…

Patch available
Fix from $1,600 2017-11-13
Misp MEDIUM 6.1
CVE-2017-15216

MISP before 2.4.81 has a potential reflected XSS in a quickDelete action that is used to delete a sighting, related to app/View/Sightings/ajax/quickD…

Fix: after 2.4.80
Fix from $1,600 2017-10-10
Misp HIGH 8.1
CVE-2017-14337

When MISP before 2.4.80 is configured with X.509 certificate authentication (CertAuth) in conjunction with a non-MISP external user management ReST A…

Fix: after 2.4.79
Fix from $1,950 2017-09-12
Misp MEDIUM 6.1
CVE-2017-13671

app/View/Helper/CommandHelper.php in MISP before 2.4.79 has persistent XSS via comments. It only impacts the users of the same instance because the c…

Fix: after 2.4.78
Fix from $1,600 2017-08-24
Misp CRITICAL 9.8
CVE-2015-5721

Malware Information Sharing Platform (MISP) before 2.3.90 allows remote attackers to conduct PHP object injection attacks via crafted serialized data…

Fix: after 2.3.89
Fix from $2,300 2016-09-03
Misp MEDIUM 6.1
CVE-2015-5720

Multiple cross-site scripting (XSS) vulnerabilities in the template-creation feature in Malware Information Sharing Platform (MISP) before 2.3.90 all…

Fix: after 2.3.89
Fix from $1,600 2016-09-03
Misp CRITICAL 9.8
CVE-2015-5719

app/Controller/TemplatesController.php in Malware Information Sharing Platform (MISP) before 2.3.92 does not properly restrict filenames under the tm…

Fix: after 2.3.91
Fix from $2,300 2016-09-03