Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2855▼ 333 respecto a la semana anterior
Críticas / altas1381▼ 36 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)296▼ 213 respecto a la semana anterior
255 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Alta (7) | 0.42% | — | Misp-project Misp | 7/9/2026 | 9/9/2026 | Affected versions of MISP contain insufficient validation of server-side outbound HTTP destinations in feed retrieval and TAXII discovery functionality. In feed processing, redirects were followed without validating the redirect scheme or destination. The original request headers were reused across redirect hops,… | |
| Modificada | Baja (2.3) | 0.27% | — | Misp-project Misp | 7/9/2026 | 14/9/2026 | Affected versions of MISP expose organisation metadata through the dashboard organisation picker without applying the same visibility restrictions enforced by the normal organisation index and per-organisation view. The affected endpoint returned fields including: - name. When… | |
| Analizada | Media (5.3) | 0.27% | — | Misp-project Misp | 7/9/2026 | 9/9/2026 | Affected versions of MISP inconsistently enforced email-address visibility in DashboardsController::listTemplates(). The query always fetched User.email, while redaction happened only inside the non-REST rendering branch. As a result, the same authenticated user who saw redacted data in the normal HTML interface could… | |
| Analizada | Alta (7.1) | 0.34% | — | Misp-project Misp | 7/9/2026 | 9/9/2026 | Affected versions of MISP do not enforce parent-event visibility when serving cryptographic keys through CryptographicKeysController::view(). The vulnerable handler queried CryptographicKey directly using the supplied key ID and selected sensitive fields such as: but did not fetch or authorize the associated parent… | |
| Analizada | Media (5.1) | 0.26% | — | Misp-project Misp | 7/9/2026 | 9/9/2026 | Affected versions of MISP validate the user-configurable homepage by checking only whether the supplied path begins with /. That check is insufficient because protocol-relative URLs such as //attacker.example also begin with / but resolve to an external origin in browsers. The vulnerable homepage value can be stored… | |
| Analizada | Alta (7.1) | 0.43% | — | Misp-project Misp | 7/9/2026 | 9/9/2026 | Affected versions of MISP allow any authenticated user to access TemplatesController::uploadFile() because the ACL entry for templates/uploadFile used the wildcard *. This bypasses the intended role restrictions applied to neighboring template-management operations. The upload handler accepts arbitrary content with… | |
| Analizada | Media (5.3) | 0.34% | — | Misp-project Misp | 7/9/2026 | 9/9/2026 | Affected versions of MISP contain improper authorization checks in the freetext feed preview functionality. The preview performed correlation lookups against attributes from events without applying the requesting user's ACL, allowing restricted event correlations and associated event information to be exposed to users… | |
| Pendiente de análisis | Alta (7.1) | 0.37% | 💥 PoC | MispAI | 6/9/2026 | 8/9/2026 | MISP's UiBeta theme collection view (app/View/Themed/UiBeta/Collections/view.ctp) performed a secondary query of member events by UUID without applying the caller's access control list (ACL). The CollectionsController::view() action correctly resolved collection element UUIDs through Event::fetchSimpleEvents($user,… | |
| Pendiente de análisis | Media (6.2) | 0.36% | — | MispAI | 4/9/2026 | 8/9/2026 | A cross-site request forgery (CSRF) vulnerability exists in MISP due to form-security and CSRF protections being disabled based on whether an incoming request was identified as a REST request. MISP's REST detection can be influenced by request properties such as the URL suffix or the HTTP Accept header. Because… | |
| Pendiente de análisis | Alta (8.6) | 0.21% | — | MispAI | 4/9/2026 | 10/9/2026 | MISP contains a cross-site request forgery (CSRF) vulnerability in the sharing group quick-edit functionality. The addOrg, removeOrg, addServer, and removeServer actions share the __initialiseSGQuickEdit() helper, where the HTTP method validation intended to restrict these operations to POST requests was commented… | |
| Pendiente de análisis | Alta (8.3) | 0.41% | — | MispAI | 4/9/2026 | 8/9/2026 | An incorrect authorization vulnerability in MISP allowed authenticated users to delete attributes from events despite lacking the required perm_modify or perm_modify_org permissions. The affected attribute deletion paths relied on organization membership checks performed by MispAttribute::deleteAttribute() but did not… | |
| Pendiente de análisis | Alta (7.6) | 0.37% | — | Misp-project MispAI | 4/9/2026 | 8/9/2026 | An authorization flaw in MISP allowed an authenticated user to submit a sharing_group_id without verifying that the user was authorized to use the referenced Sharing Group. In several attribute and Galaxy Cluster creation and editing workflows, validation of the submitted Sharing Group was performed only when the… | |
| Analizada | Alta (7.1) | 0.45% | — | Misp-project Misp | 3/9/2026 | 11/9/2026 | A vulnerability in MISP's event template handling allowed an authenticated user with permission to create or modify event templates to bypass validation of the template definition field. The EventTemplate::beforeValidate() method only performed semantic validation when the supplied definition was already represented… | |
| Analizada | Alta (7.6) | 0.34% | — | Misp-project Misp | 3/9/2026 | 11/9/2026 | MISP contains a session fixation vulnerability in the CustomAuth authentication (a custom configuration) flow. When a user was successfully authenticated through CustomAuth, MISP stored the authenticated user identity in the existing session without first rotating the session identifier. As a result, if an attacker… | |
| Analizada | Alta (8.6) | 0.46% | — | Misp-project Misp | 3/9/2026 | 11/9/2026 | A vulnerability in MISP's email-based one-time password (OTP) authentication flow allowed an attacker to perform an unrestricted number of OTP verification attempts. The email_otp() endpoint did not apply brute-force protection when validating submitted OTP values. An attacker who had reached the OTP verification… | |
| Analizada | Alta (8.8) | 0.25% | — | Misp-project Misp | 3/9/2026 | 11/9/2026 | A cross-site request forgery (CSRF) vulnerability existed in the cullEmptyEvents action of MISP. The endpoint performed a state-changing and irreversible operation while accepting HTTP GET requests. Because bodyless GET requests are not subject to CakePHP's CSRF validation, an attacker could cause an authenticated… | |
| Analizada | Media (5.3) | 0.29% | — | Misp-project Misp | 3/9/2026 | 10/9/2026 | A persistent unsafe URL injection vulnerability exists in the MISP dashboard ButtonWidget configuration. Dashboard widget URLs were validated only when the widget was rendered and were not validated when the configuration was saved. As a result, an authenticated user able to modify dashboard widget settings could… | |
| Analizada | Media (6.1) | 0.25% | — | Misp-project Misp | 3/9/2026 | 10/9/2026 | MISP contains a reflected Cross-Site Scripting (XSS) vulnerability in the event attribute filtering query builder. The taggedAttributes and galaxyAttachedAttributes URL parameters were inserted into the query-builder rules without HTML escaping before being serialized as JSON and embedded inside a <script> element.… | |
| Analizada | Media (5.3) | 0.25% | — | Misp-project Misp | 3/9/2026 | 10/9/2026 | MISP contains an authorization flaw in the OnDemand correlation engine where correlations were calculated solely from matching attribute values without applying the distribution, sharing group, organization, or other access-control restrictions associated with the correlated attributes and events. As a result, an… | |
| Analizada | Alta (7.6) | 0.27% | — | Misp-project Misp | 3/9/2026 | 10/9/2026 | MISP contains an improper TLS certificate validation vulnerability in CurlClient. The CurlClient::$verifyPeer property was not explicitly initialized and therefore defaulted to null. When passed to cURL, this value effectively disabled TLS peer verification unless the calling code explicitly enabled it. As a result,… | |
| Analizada | Crítica (9.5) | 0.87% | — | Misp-project Misp | 3/9/2026 | 10/9/2026 | MISP contains an authentication bypass vulnerability in its LDAP and LinOTP authentication components due to insufficient validation of user-supplied credentials. The custom LdapAuthenticate and LinOTPAuthenticate components replace CakePHP's FormAuthenticate implementation but did not replicate its credential… | |
| Aplazada | Alta (8.7) | 0.45% | — | RansomlookAIRocket.chatAIBlueskyAIJoinmastodon MastodonAI+1 | 24/8/2026 | 26/8/2026 | RansomLook fails to enforce the privacy status of ransomware groups and markets when distributing newly collected victim posts to external notification channels. The post-processing logic checks whether an individual post is marked private but does not verify whether the group or market to which the post belongs is… | |
| Aplazada | Media (6.3) | 0.61% | — | Misp-stixAI | 21/8/2026 | 26/8/2026 | A parser state isolation vulnerability in misp-stix could cause data from a previously processed STIX document to be retained and incorporated into the MISP event generated from a subsequent document when the same parser instance is reused. Several STIX 1 and STIX 2 parser components maintained per-document state that… | |
| Aplazada | Alta (8.7) | 0.47% | — | Misp-project Misp StixAI | 21/8/2026 | 26/8/2026 | A denial-of-service vulnerability was identified in misp-stix when processing attacker-controlled STIX 1 or STIX 2 documents. The STIX import code used sys.exit() to handle several parsing and loading failures. Because SystemExit inherits from BaseException rather than Exception, these failures bypassed the exception… | |
| Aplazada | Alta (8.8) | 0.66% | — | MispAIPymispAI | 21/8/2026 | 26/8/2026 | A path traversal vulnerability existed in the handling of MISP object template names during STIX 2 import and MISP-to-STIX 2 export. MISP object names are passed to PyMISP's object-template resolution mechanism, which constructs a filesystem path by joining the configured MISP object-template directory, the object… |