Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2853▼ 343 respecto a la semana anterior
Críticas / altas1376▼ 50 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)339▼ 171 respecto a la semana anterior
255 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (6.3) | 0.39% | — | MispAI | 21/9/2026 | 21/9/2026 | MISP contains a DOM-based cross-site scripting (XSS) vulnerability in the contextual menu JavaScript component. The ContextualMenu class populates HTML <option> elements by assigning user-controllable values to the innerHTML property. Because innerHTML parses and renders HTML markup, any untrusted string supplied as… | |
| Aplazada | Media (6.3) | 0.39% | — | MispAI | 21/9/2026 | 21/9/2026 | MISP contains a stored cross-site scripting (XSS) vulnerability in the default theme's Galaxies index page. When a MISP instance detects unknown custom or default galaxy clusters during synchronization, it renders sample tag names in an informational notice directed at site administrators. In the default theme, these… | |
| Aplazada | Media (6.3) | 0.40% | — | MispAI | 21/9/2026 | 21/9/2026 | MISP's galaxy matrix statistics view (app/View/Users/statistics_galaxymatrix.ctp) renders the galaxy name directly into HTML output via sprintf() without any HTML encoding. An authenticated user holding the perm_galaxy_editor permission can create or modify a galaxy whose name contains arbitrary HTML or JavaScript… | |
| Aplazada | Alta (8.5) | 0.39% | — | MispAI | 17/9/2026 | 22/9/2026 | MISP contains a stored cross-site scripting (XSS) vulnerability in the Overmind theme's statistics views. The event General card and the server/feed preview card constructed donut chart legend labels by directly concatenating object name or category keys into an innerHTML string without HTML-encoding. Because MISP… | |
| Aplazada | Alta (8.7) | 0.64% | — | MispAICakephpAI | 17/9/2026 | 22/9/2026 | MISP contains a vulnerability in its background job dispatch mechanism that allows remote code execution as the web user. Background job arguments are passed directly as the argv of the CakePHP console process. CakePHP's ShellDispatcher::_parsePaths() scans the entire argv for path switches (-app, --app, -working,… | |
| Aplazada | Media (5.1) | 0.39% | — | Misp SachertortephpAI | 17/9/2026 | 18/9/2026 | In the MISP sachertortephp library, the Xml::build() static method in lib/Cake/Utility/Xml.php contains a logic error in the conditional that gates network-based XML fetching. The original condition was written as: $options['readFile'] && strpos($input, 'http://') === 0 || strpos($input, 'https://') === 0. Because… | |
| Aplazada | Media (6.9) | 0.57% | — | MispAI | 15/9/2026 | 16/9/2026 | Affected versions of MISP do not consistently apply the existing authentication-failure logging throttle. Two API authentication failure branches wrote directly to the Log model: Unlike other authentication failures, these paths bypassed _shouldLog(), so every request could create another durable auth_fail entry.… | |
| Aplazada | Media (5.1) | 0.53% | — | MispAIRedisAI | 15/9/2026 | 16/9/2026 | Affected versions of MISP use Redis to throttle repeated authentication-failure log entries. The intent is to avoid excessive duplicate logs while still recording failed authentication activity. However, User->setupRedis() returns false when Redis cannot be reached. The vulnerable _shouldLog() logic only returned true… | |
| Aplazada | Media (5.3) | 0.47% | — | MispAI | 15/9/2026 | 16/9/2026 | Affected versions of MISP can record incorrect access-log data for requests that terminate in an exception. Because CakeErrorController extends AppController, exception rendering runs the application startup path a second time. As a result, __accessMonitor() calls AccessLog::logRequest() twice for one HTTP request.… | |
| Aplazada | Media (5.3) | 0.21% | — | MispAI | 15/9/2026 | 16/9/2026 | Affected versions of MISP expose several state-changing controller actions without restricting them to POST. The affected actions are: - EventReportsController::purgeUnusedPictures() - NoticelistsController::enableNoticelist() - ServersController::removeOrphanedCorrelations() - WorkflowsController::rebuildRedis() The… | |
| Aplazada | Media (5.3) | 0.35% | — | MispAI | 15/9/2026 | 16/9/2026 | Affected versions of MISP incorrectly filter dashboard templates that are restricted to a specific permission flag. DashboardsController::listTemplates() allowed a template when either: - its restrict_to_permission_flag matched one of the current user’s permission flags, or - restrict_to_permission_flag equaled… | |
| Aplazada | Alta (7.1) | 0.35% | — | MispAI | 15/9/2026 | 16/9/2026 | Affected versions of MISP allow a collection element to be created from a bare UUID without consistently checking whether the acting user is allowed to access the referenced object. The commit explains that collection elements themselves only store UUIDs, while the collection view later resolves those UUIDs into their… | |
| Aplazada | Alta (7.1) | 0.39% | — | MispAI | 15/9/2026 | 16/9/2026 | Affected versions of MISP fail to authorize a submitted sharing group in a specific event-edit path. The vulnerable logic checked whether the acting user could use a sharing_group_id only when the request explicitly supplied distribution = 4. If the attacker instead omitted distribution but supplied a different… | |
| Aplazada | Media (6.9) | 0.20% | — | MispAICakephpAI | 15/9/2026 | 16/9/2026 | Affected versions of MISP rely on CakePHP request-method override processing in a way that can disable CSRF and form-security validation. CakePHP honors a _method field or X-HTTP-Method-Override header by rewriting the effective request method. For override values outside the normal write verbs POST, PUT, PATCH, and… | |
| Aplazada | Crítica (9.3) | 0.64% | — | MispAICakephpAI | 14/9/2026 | 16/9/2026 | The LdapAuth and LinOTPAuth authentication plugins in MISP contain an authentication bypass vulnerability. Both LdapAuthenticate and LinOTPAuthenticate replace CakePHP's FormAuthenticate class but fail to replicate its _checkFields() input validation guard. As a result, the email and password fields extracted from the… | |
| Aplazada | Media (5.1) | 0.40% | — | MispAI | 14/9/2026 | 16/9/2026 | Affected versions of MISP serve uploaded SVG images inline without a restrictive browser sandbox. The commit explains that SVG files are XML documents rather than passive bitmap images. While scripts inside SVG do not execute when the SVG is rendered through a normal <img>, they can execute when the SVG is navigated… | |
| Aplazada | Media (4.6) | 0.16% | — | MispAI | 14/9/2026 | 16/9/2026 | Affected versions of MISP’s interactive CLI shell do not reliably preserve the identity of the impersonated MISP user across audit logging. The shell is designed to run actions as a supplied MISP user ID. However, the legacy SysLogLogable behavior stored that identity in behavior-instance state that could be… | |
| Aplazada | Alta (8.4) | 0.15% | — | MispAI | 14/9/2026 | 16/9/2026 | Affected versions of MISP’s interactive CLI shell implement access control independently from the normal web application, causing several authorization inconsistencies. The patch shows that CLI access could differ from the web application in multiple security-sensitive areas: The commit additionally hardens pagination… | |
| Aplazada | Media (5.1) | 0.26% | — | MispAI | 14/9/2026 | 16/9/2026 | MISP contains a Cross-Site Request Forgery (CSRF) vulnerability in the UserSettingsController. The actions setTheme, setHomePage, and eventIndexColumnToggle were explicitly added to the Security component's unlockedActions list, which disabled all CSRF validation (both token and field-hash checks) for those endpoints.… | |
| Aplazada | Media (5.1) | 0.49% | — | MispAI | 10/9/2026 | 10/9/2026 | MISP contains an HTML injection vulnerability in the MISPElementHTMLFormatterTool component, which is responsible for rendering MISP element references (attributes, objects, and tags) into inline HTML during PDF report export via the convert_markdown_to_pdf module. The attribute(), objectAttribute(), object(), and… | |
| Aplazada | Alta (7.1) | 0.35% | — | MispAI | 10/9/2026 | 10/9/2026 | Affected versions of MISP do not consistently enforce the acting user's authorization when instantiating event templates. For templates using distribution = 4, the template can specify a sharing_group_id. The instantiation path passed that value into event creation without verifying that the user instantiating the… | |
| Modificada | Alta (8.7) | 0.54% | — | Misp-project Misp | 7/9/2026 | 14/9/2026 | Affected versions of MISP permit unauthenticated or weakly constrained request paths to perform persistent work without adequate input bounds or rate limiting. The users/forgot password-reset endpoint accepted an attacker-controlled email value without first imposing a reasonable length bound or validating its format.… | |
| Analizada | Media (5.3) | 0.27% | — | Misp-project Misp | 7/9/2026 | 9/9/2026 | Affected versions of MISP allow authenticated users to retrieve object-reference records by UUID through EventGraphTool::get_reference_data() without first checking whether the requester is authorized to view the object the reference belongs to. The vulnerable code queried ObjectReference.uuid directly and returned… | |
| Analizada | Baja (2.3) | 0.28% | — | Misp-project Misp | 7/9/2026 | 9/9/2026 | Affected versions of MISP contain inconsistent authorization checks across dashboard widgets that display organisation information. Several organisation-related widgets did not honor Security.hide_organisation_index_from_users. As a result, authenticated users without the perm_sharing_group permission could enumerate… | |
| Analizada | Media (5.1) | 0.24% | — | Misp-project Misp | 7/9/2026 | 9/9/2026 | Affected versions of MISP insufficiently validate URLs used by dashboard widgets, particularly the Button widget. The widget's URL is stored configuration controlled by a user. The previous renderer considered a URL safe if it appeared relative or if its parsed hostname matched the configured MISP hostname. That logic… |