Vulnerability index

Browse CVEs

107 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

CRITICAL 9.8 CVE-2023-48659 An issue was discovered in MISP before 2.4.176. app/Controller/AppController.php mishandles parameter parsing. Misp 2.4.176+ Fix from $2,3002023-11-17 MEDIUM 6.1 CVE-2023-41098 An issue was discovered in MISP 2.4.174. In app/Controller/DashboardsController.php, a reflected XSS issue exists via the id parameter upon a dashboa… Misp Patch available Fix from $1,6002023-08-23 MEDIUM 6.1 CVE-2023-40224 MISP 2.4.174 allows XSS in app/View/Events/index.ctp. Misp Patch available Fix from $1,6002023-08-10 HIGH 7.5 CVE-2023-37306 MISP 2.4.172 mishandles different certificate file extensions in server sync. An attacker can obtain sensitive information because of the nature of t… Misp Patch available Fix from $1,9502023-06-30 MEDIUM 5.4 CVE-2023-37307 In MISP before 2.4.172, title_for_layout is not properly sanitized in Correlations, CorrelationExclusions, and Layouts. Misp 2.4.172+ Fix from $1,6002023-06-30 MEDIUM 6.1 CVE-2023-28884 In MISP 2.4.169, app/Lib/Tools/CustomPaginationTool.php allows XSS in the community index. Misp Patch available Fix from $1,6002023-03-27 MEDIUM 6.1 CVE-2023-28606 js/event-graph.js in MISP before 2.4.169 allows XSS via event-graph node tooltips. Misp 2.4.169+ Fix from $1,6002023-03-18 MEDIUM 6.1 CVE-2023-28607 js/event-graph.js in MISP before 2.4.169 allows XSS via the event-graph relationship tooltip. Misp 2.4.169+ Fix from $1,6002023-03-18 CRITICAL 9.8 CVE-2022-48328 app/Controller/Component/IndexFilterComponent.php in MISP before 2.4.167 mishandles ordered_url_params and additional_delimiters. Misp 2.4.167+ Fix from $2,3002023-02-20 CRITICAL 9.8 CVE-2022-48329 MISP before 2.4.166 unsafely allows users to use the order parameter, related to app/Model/Attribute.php, app/Model/GalaxyCluster.php, app/Model/Work… Misp 2.4.166+ Fix from $2,3002023-02-20 MEDIUM 6.1 CVE-2023-24070 app/View/AuthKeys/authkey_display.ctp in MISP through 2.4.167 has an XSS in authkey add via a Referer field. Misp after 2.4.167 Fix from $1,6002023-01-23 CRITICAL 9.8 CVE-2023-24028 In MISP 2.4.167, app/Controller/Component/ACLComponent.php has incorrect access control for the decaying import function. Misp Patch available Fix from $2,3002023-01-20 MEDIUM 6.1 CVE-2023-24026 In MISP 2.4.167, app/webroot/js/event-graph.js has an XSS vulnerability via an event-graph preview payload. Misp Patch available Fix from $1,6002023-01-20 MEDIUM 6.1 CVE-2023-24027 In MISP 2.4.167, app/webroot/js/action_table.js allows XSS via a network history name. Misp Patch available Fix from $1,6002023-01-20 MEDIUM 6.1 CVE-2022-47928 In MISP before 2.4.167, there is XSS in the template file uploads in app/View/Templates/upload_file.ctp. Misp 2.4.167+ Fix from $1,6002022-12-22 CRITICAL 9.8 CVE-2022-29528 An issue was discovered in MISP before 2.4.158. PHAR deserialization can occur. Misp 2.4.158+ Fix from $2,3002022-04-20 HIGH 7.5 CVE-2022-29534 An issue was discovered in MISP before 2.4.158. In UsersController.php, password confirmation can be bypassed via vectors involving an "Accept: appli… Misp 2.4.158+ Fix from $1,9502022-04-20 MEDIUM 6.1 CVE-2022-29533 An issue was discovered in MISP before 2.4.158. There is XSS in app/Controller/OrganisationsController.php in a situation with a "weird single checkb… Misp 2.4.158+ Fix from $1,6002022-04-20 MEDIUM 5.4 CVE-2022-29529 An issue was discovered in MISP before 2.4.158. There is stored XSS via the LinOTP login field. Misp 2.4.158+ Fix from $1,6002022-04-20 MEDIUM 5.4 CVE-2022-29530 An issue was discovered in MISP before 2.4.158. There is stored XSS in the galaxy clusters. Misp 2.4.158+ Fix from $1,6002022-04-20 MEDIUM 5.4 CVE-2022-29531 An issue was discovered in MISP before 2.4.158. There is stored XSS in the event graph via a tag name. Misp 2.4.158+ Fix from $1,6002022-04-20 HIGH 8.8 CVE-2022-27245 An issue was discovered in MISP before 2.4.156. app/Model/Server.php does not restrict generateServerSettings to the CLI. This could lead to SSRF. Misp 2.4.156+ Fix from $1,9502022-03-18 HIGH 7.8 CVE-2022-27243 An issue was discovered in MISP before 2.4.156. app/View/Users/terms.ctp allows Local File Inclusion via the custom terms file setting. Misp 2.4.156+ Fix from $1,9502022-03-18 MEDIUM 6.1 CVE-2022-27246 An issue was discovered in MISP before 2.4.156. An SVG org logo (which may contain JavaScript) is not forbidden by default. Misp 2.4.156+ Fix from $1,6002022-03-18 CRITICAL 9.8 CVE-2021-41326 In MISP before 2.4.148, app/Lib/Export/OpendataExport.php mishandles parameter data that is used in a shell_exec call. Misp 2.4.148+ Fix from $2,3002021-09-17 CRITICAL 9.8 CVE-2021-39302 MISP 2.4.148, in certain configurations, allows SQL injection via the app/Model/Log.php $conditions['org'] value. Misp Patch available Fix from $2,3002021-08-19 MEDIUM 5.4 CVE-2021-37742 app/View/Elements/GalaxyClusters/view_relation_tree.ctp in MISP 2.4.147 allows Stored XSS when viewing galaxy cluster relationships. Misp Patch available Fix from $1,6002021-07-30 MEDIUM 5.4 CVE-2021-37743 app/View/GalaxyElements/ajax/index.ctp in MISP 2.4.147 allows Stored XSS when viewing galaxy cluster elements in JSON format. Misp Patch available Fix from $1,6002021-07-30 MEDIUM 5.4 CVE-2021-37534 app/View/GalaxyClusters/add.ctp in MISP 2.4.146 allows Stored XSS when forking a galaxy cluster. Misp Patch available Fix from $1,6002021-07-26 MEDIUM 6.1 CVE-2021-36212 app/View/SharingGroups/view.ctp in MISP before 2.4.146 allows stored XSS in the sharing groups view. Misp 2.4.146+ Fix from $1,6002021-07-07