Vulnerability index

Browse CVEs

107 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

HIGH 8.8 CVE-2026-56424 MISP core contained multiple broken access-control flaws where authorization checks were performed against the wrong entity, or where ownership/edita… Misp 2.5.42+ Fix from $1,9502026-06-22 HIGH 8.8 CVE-2026-56425 The Azure Active Directory (AAD) authentication implementation contained multiple weaknesses in its OAuth 2.0 authorization flow that could allow att… Misp 2.5.42+ Fix from $1,9502026-06-22 HIGH 7.2 CVE-2026-56446 MISP allowed a site administrator to configure an arbitrary filesystem path for the NDJSON error log used by JsonLogTool. Because log entries can inc… Misp 2.5.42+ Fix from $1,9502026-06-22 HIGH 7.2 CVE-2026-56447 MISP allowed an authenticated site administrator to set the Kafka_rdkafka_config setting to an arbitrary filesystem path. MISP subsequently parsed th… Misp 2.5.42+ Fix from $1,9502026-06-22 HIGH 8.8 CVE-2026-56423 MISP Core contained broken access-control checks in the bulk deletion flows for Event Reports and Sharing Groups. The affected deleteSelection handle… Misp 2.5.42+ Fix from $1,9502026-06-22 HIGH 8.1 CVE-2026-10863 A security issue was fixed in the correlations over-correlation endpoint where the order query parameter was accepted from user-controlled named requ… Misp 2.5.39+ Fix from $1,9502026-06-04 MEDIUM 6.5 CVE-2026-10860 A logic error in the MISP CRUD component delete handler allowed validation failures to be bypassed when requests used the HTTP DELETE method. Due to … Misp 2.5.39+ Fix from $1,6002026-06-04 MEDIUM 6.1 CVE-2026-10861 An open redirect vulnerability existed in MISP UsersController::routeafterlogin() because the value stored in the pre_login_requested_url session key… Misp 2.5.39+ Fix from $1,6002026-06-04 MEDIUM 6.1 CVE-2026-10856 A URL validation flaw in the MISP dashboard button widget allowed a crafted relative-looking URL to be accepted as a local path while being interpret… Misp 2.5.39+ Fix from $1,6002026-06-04 CRITICAL 10.0 CVE-2026-10611 An authentication bypass vulnerability exists in MISP when LDAP mixed authentication is enabled with OTP enforcement. In deployments configured with … Misp 2.5.39+ Fix from $2,3002026-06-02 HIGH 7.5 CVE-2026-9137 The CSP report endpoint in MISP intended to limit logged CSP reports to 1 KB but incorrectly allowed reports up to 1 MB before truncation. On deploym… Misp 2.5.38+ Fix from $1,9502026-05-20 MEDIUM 6.5 CVE-2026-9136 A vulnerability was identified in the ShadowAttribute proposal creation workflow. The add action accepted user-controlled ShadowAttribute request dat… Misp 2.5.38+ Fix from $1,6002026-05-20 HIGH 7.2 CVE-2026-44380 MISP is an open source threat intelligence and sharing platform. Prior to 2.5.37, an improper access control vulnerability in the authentication key … Misp 2.5.37+ Fix from $1,9502026-05-13 MEDIUM 5.3 CVE-2026-44379 MISP is an open source threat intelligence and sharing platform. Prior to 2.5.37, MISP Collections did not enforce RFC 4122 UUID validation on the uu… Misp 2.5.37+ Fix from $1,6002026-05-13 MEDIUM 5.3 CVE-2026-44381 MISP is an open source threat intelligence and sharing platform. Prior to 2.5.37, a SQL injection vulnerability existed in the handling of user-contr… Misp 2.5.37+ Fix from $1,6002026-05-13 MEDIUM 5.4 CVE-2026-8080 Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in misp allows Stored XSS. This issue… Misp 2.5.37+ Fix from $1,6002026-05-07 CRITICAL 9.6 CVE-2026-39962 MISP is an open source threat intelligence and sharing platform. Prior to 2.5.36, improper neutralization of special elements in an LDAP query in Apa… Misp 2.5.36+ Fix from $2,3002026-04-09 CRITICAL 9.0 CVE-2025-67906 In MISP before 2.5.28, app/View/Elements/Workflows/executionPath.ctp allows XSS in the workflow execution path. Misp 2.5.28+ Fix from $2,3002025-12-15 MEDIUM 6.1 CVE-2024-58130 In app/Controller/Component/RestResponseComponent.php in MISP before 2.4.193, REST endpoints have a lack of sanitization for non-JSON responses. Misp 2.4.193+ Fix from $1,6002025-03-28 MEDIUM 6.5 CVE-2024-45509 In MISP through 2.4.196, app/Controller/BookmarksController.php does not properly restrict access to bookmarks data in the case where the user is not… Misp 2.4.197+ Fix from $1,6002024-09-01 CRITICAL 9.8 CVE-2024-29858 In MISP before 2.4.187, __uploadLogo in app/Controller/OrganisationsController.php does not properly check for a valid logo upload. Misp 2.4.187+ Fix from $2,3002024-03-21 CRITICAL 9.8 CVE-2024-29859 In MISP before 2.4.187, add_misp_export in app/Controller/EventsController.php does not properly check for a valid file upload. Misp 2.4.187+ Fix from $2,3002024-03-21 CRITICAL 9.8 CVE-2024-25674 An issue was discovered in MISP before 2.4.184. Organisation logo upload is insecure because of a lack of checks for the file extension and MIME type. Misp 2.4.184+ Fix from $2,3002024-02-09 CRITICAL 9.8 CVE-2024-25675 An issue was discovered in MISP before 2.4.184. A client does not need to use POST to start an export generation process. This is related to app/Cont… Misp 2.4.184+ Fix from $2,3002024-02-09 CRITICAL 9.8 CVE-2023-50918 app/Controller/AuditLogsController.php in MISP before 2.4.182 mishandles ACLs for audit logs. Misp 2.4.182+ Fix from $2,3002023-12-15 MEDIUM 6.1 CVE-2023-49926 app/Lib/Tools/EventTimelineTool.php in MISP before 2.4.179 allows XSS in the event timeline widget. Misp 2.4.179+ Fix from $1,6002023-12-03 CRITICAL 9.8 CVE-2023-48655 An issue was discovered in MISP before 2.4.176. app/Controller/Component/IndexFilterComponent.php does not properly filter out query parameters. Misp 2.4.176+ Fix from $2,3002023-11-17 CRITICAL 9.8 CVE-2023-48656 An issue was discovered in MISP before 2.4.176. app/Model/AppModel.php mishandles order clauses. Misp 2.4.176+ Fix from $2,3002023-11-17 CRITICAL 9.8 CVE-2023-48657 An issue was discovered in MISP before 2.4.176. app/Model/AppModel.php mishandles filters. Misp 2.4.176+ Fix from $2,3002023-11-17 CRITICAL 9.8 CVE-2023-48658 An issue was discovered in MISP before 2.4.176. app/Model/AppModel.php lacks a checkParam function for alphanumerics, underscore, dash, period, and s… Misp 2.4.176+ Fix from $2,3002023-11-17