Vulnerability index

Browse CVEs

107 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

MEDIUM 6.1 CVE-2019-11813 An issue was discovered in app/View/Elements/Events/View/value_field.ctp in MISP before 2.4.107. There is persistent XSS via link type attributes wit… Misp 2.4.107+ Fix from $1,6002019-05-08 MEDIUM 6.1 CVE-2019-11814 An issue was discovered in app/webroot/js/misp.js in MISP before 2.4.107. There is persistent XSS via image names in titles, as demonstrated by a scr… Misp 2.4.107+ Fix from $1,6002019-05-08 MEDIUM 6.1 CVE-2019-10254 In MISP before 2.4.105, the app/View/Layouts/default.ctp default layout template has a Reflected XSS vulnerability. Misp 2.4.105+ Fix from $1,6002019-03-28 MEDIUM 5.3 CVE-2019-9482 In MISP 2.4.102, an authenticated user can view sightings that they should not be eligible for. Exploiting this requires access to the event that has… Misp Patch available Fix from $1,6002019-03-01 HIGH 8.8 CVE-2018-19908EPSS 17% An issue was discovered in MISP 2.4.9x before 2.4.99. In app/Model/Event.php (the STIX 1 import code), an unescaped filename string is used to constr… Misp 2.4.99+ Fix from $1,9502018-12-06 CRITICAL 9.8 CVE-2018-12649 An issue was discovered in app/Controller/UsersController.php in MISP 2.4.92. An adversary can bypass the brute-force protection by using a PUT HTTP … Misp Patch available Fix from $2,3002018-06-22 MEDIUM 6.1 CVE-2018-11562 An issue was discovered in MISP 2.4.91. A vulnerability in app/View/Elements/eventattribute.ctp allows reflected XSS if a user clicks on a malicious … Misp Patch available Fix from $1,6002018-05-30 MEDIUM 6.1 CVE-2018-11245 app/webroot/js/misp.js in MISP 2.4.91 has a DOM based XSS with cortex type attributes. Misp Patch available Fix from $1,6002018-05-18 MEDIUM 6.1 CVE-2018-8948 In MISP before 2.4.89, app/View/Events/resolved_attributes.ctp has multiple XSS issues via a malicious MISP module. Misp 2.4.89+ Fix from $1,6002018-03-23 HIGH 7.2 CVE-2018-6926 In app/Controller/ServersController.php in MISP 2.4.87, a server setting permitted the override of a path variable on certain Red Hed Enterprise Linu… Misp Patch available Fix from $1,9502018-02-12 MEDIUM 5.4 CVE-2017-16802 In the sharingGroupPopulateOrganisations function in app/webroot/js/misp.js in MISP 2.4.82, there is XSS via a crafted organisation name that is manu… Misp Patch available Fix from $1,6002017-11-13 MEDIUM 6.1 CVE-2017-15216 MISP before 2.4.81 has a potential reflected XSS in a quickDelete action that is used to delete a sighting, related to app/View/Sightings/ajax/quickD… Misp after 2.4.80 Fix from $1,6002017-10-10 HIGH 8.1 CVE-2017-14337 When MISP before 2.4.80 is configured with X.509 certificate authentication (CertAuth) in conjunction with a non-MISP external user management ReST A… Misp after 2.4.79 Fix from $1,9502017-09-12 MEDIUM 6.1 CVE-2017-13671 app/View/Helper/CommandHelper.php in MISP before 2.4.79 has persistent XSS via comments. It only impacts the users of the same instance because the c… Misp after 2.4.78 Fix from $1,6002017-08-24 CRITICAL 9.8 CVE-2015-5721 Malware Information Sharing Platform (MISP) before 2.3.90 allows remote attackers to conduct PHP object injection attacks via crafted serialized data… Misp after 2.3.89 Fix from $2,3002016-09-03 MEDIUM 6.1 CVE-2015-5720 Multiple cross-site scripting (XSS) vulnerabilities in the template-creation feature in Malware Information Sharing Platform (MISP) before 2.3.90 all… Misp after 2.3.89 Fix from $1,6002016-09-03 CRITICAL 9.8 CVE-2015-5719 app/Controller/TemplatesController.php in Malware Information Sharing Platform (MISP) before 2.3.92 does not properly restrict filenames under the tm… Misp after 2.3.91 Fix from $2,3002016-09-03