Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2703▼ 615 respecto a la semana anterior
Críticas / altas1293▼ 208 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)291▼ 219 respecto a la semana anterior
255 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (7.1) | 0.27% | — | Misp-project MispAI | 12/6/2026 | 17/6/2026 | MISP contains an insecure default configuration in which the Security.check_sec_fetch_site_header control is disabled. When this setting is disabled, state-changing requests such as POST, PUT, or AJAX requests are not restricted based on the browser-provided Sec-Fetch-Site header. A remote unauthenticated attacker… | |
| Aplazada | Alta (7.5) | 0.39% | — | MispAI | 12/6/2026 | 17/6/2026 | An incorrect authorization vulnerability in MISP allows an organization administrator to target site administrator accounts belonging to the same organization through the administrative email functionality. The affected code restricted organization administrators to users within their own organization, but did not… | |
| Aplazada | Media (5.1) | 0.43% | — | MispAI | 12/6/2026 | 17/6/2026 | An improper authorization vulnerability in MISP allowed an authenticated organization administrator to access or modify user settings belonging to site administrator accounts within the same organization. The affected access-control checks scoped administrative actions by organization membership but did not exclude… | |
| Aplazada | Media (6.9) | 0.44% | — | Misp BsimvisAI | 10/6/2026 | 17/6/2026 | A stored cross-site scripting vulnerability existed in MISP BSimVis tag rendering code. Several client-side rendering paths interpolated tag names, collection names, entity identifiers, cluster names, and tag metadata directly into HTML, HTML attributes, inline JavaScript event handlers, and CSS style values without… | |
| Aplazada | Crítica (9) | 0.24% | — | MispAI | 4/6/2026 | 22/7/2026 | A mass assignment vulnerability exists in the MISP user edit functionality due to insufficient filtering of user-supplied fields in UsersController::edit(). When processing edit requests, the application accepted a user-controlled User.id value from request data. An authenticated attacker could craft a modified… | |
| Analizada | Media (5.3) | 0.18% | — | Misp-project Misp | 4/6/2026 | 22/7/2026 | A vulnerability in the MISP dashboard widgets allowed an authenticated user to manipulate the fields option and influence which fields were returned by the New Users and New Organisations widgets. In some cases, requesting a field set that became empty after validation or redaction could cause the underlying query to… | |
| Analizada | Media (6.4) | 0.22% | — | Misp-project Misp | 4/6/2026 | 22/7/2026 | A security issue was fixed in the correlations over-correlation endpoint where the order query parameter was accepted from user-controlled named request parameters. This allowed an authenticated user to override the server-defined ordering of over-correlating values. Depending on how the value was processed by the… | |
| Analizada | Alta (7.9) | 0.20% | — | Misp-project Misp | 4/6/2026 | 22/7/2026 | A logic error in the MISP CRUD component delete handler allowed validation failures to be bypassed when requests used the HTTP DELETE method. Due to missing parentheses in the delete condition, the expression was evaluated as ($validationError === null && POST) || DELETE, meaning a DELETE request could proceed even… | |
| Analizada | Media (5.1) | 0.22% | — | Misp-project Misp | 4/6/2026 | 22/7/2026 | An open redirect vulnerability existed in MISP UsersController::routeafterlogin() because the value stored in the pre_login_requested_url session key was used as the post-login redirect destination without sufficiently enforcing that it was a local application path. An unauthenticated remote attacker could craft a… | |
| Analizada | Media (5.1) | 0.15% | — | Misp-project Misp | 4/6/2026 | 22/7/2026 | A URL validation flaw in the MISP dashboard button widget allowed a crafted relative-looking URL to be accepted as a local path while being interpreted by browsers as an external URL. The validation rejected URLs containing an explicit scheme, host, or user component, but did not reject paths beginning with a slash… | |
| Analizada | Media (5.1) | 0.15% | — | Misp-project Misp | 4/6/2026 | 22/7/2026 | An authorization flaw existed in the MISP Event Template Importer overwrite workflow. When importing an event template in overwrite mode, the application checked whether a matching template already existed but did not verify that the importing user belonged to the organization that owned the existing template. As a… | |
| Analizada | Media (5.3) | 0.18% | — | Misp-project Misp | 4/6/2026 | 22/7/2026 | A visibility control issue in the event template creation workflow allowed non-site-admin users to access private galaxies belonging to other organisations. The event template builder loaded all enabled galaxies without applying organisation or distribution-based access restrictions, potentially exposing private… | |
| Analizada | Alta (8.2) | 0.35% | — | Misp-project Misp | 2/6/2026 | 22/7/2026 | An authentication bypass vulnerability exists in MISP when LDAP mixed authentication is enabled with OTP enforcement. In deployments configured with LdapAuth.mixedAuth=true and Security.require_otp=true, users authenticated through an authentication plugin, such as LDAP, may have their authenticated session… | |
| Analizada | Media (5.1) | 0.46% | — | Misp-project Misp | 20/5/2026 | 23/7/2026 | The CSP report endpoint in MISP intended to limit logged CSP reports to 1 KB but incorrectly allowed reports up to 1 MB before truncation. On deployments where the endpoint is reachable by untrusted clients, this could allow attackers to generate excessive log volume and contribute to resource exhaustion or log… | |
| Analizada | Alta (8.3) | 0.30% | — | Misp-project Misp | 20/5/2026 | 23/7/2026 | A vulnerability was identified in the ShadowAttribute proposal creation workflow. The add action accepted user-controlled ShadowAttribute request data without removing the id field before saving the record. Because the underlying framework treats a supplied primary key as an instruction to update an existing record,… | |
| Pendiente de análisis | Media (6) | 0.22% | — | MispAI | 20/5/2026 | 23/7/2026 | MISP’s OIDC authentication plugin allowed automatic linking of an OIDC identity to an existing local user account based on the email claim when the local account had no stored sub value. Under insecure or untrusted IdP configurations where email ownership is not enforced, an attacker with a valid OIDC token could… | |
| Analizada | Crítica (9.3) | 0.76% | 💥 Exploit | Misp-project Misp | 13/5/2026 | 22/6/2026 | MISP is an open source threat intelligence and sharing platform. Prior to 2.5.37, a SQL injection vulnerability existed in the handling of user-controlled ordering parameters in the event and shadow attribute listing endpoints. The affected code accepted order or sort values from request parameters and incorporated… | |
| Analizada | Alta (8.6) | 0.58% | — | Misp-project Misp | 13/5/2026 | 22/6/2026 | MISP is an open source threat intelligence and sharing platform. Prior to 2.5.37, an improper access control vulnerability in the authentication key reset functionality allowed an authenticated organization administrator to reset authentication keys belonging to site administrator accounts within the same… | |
| Analizada | Media (5.3) | 0.29% | — | Misp-project Misp | 13/5/2026 | 22/6/2026 | MISP is an open source threat intelligence and sharing platform. Prior to 2.5.37, MISP Collections did not enforce RFC 4122 UUID validation on the uuid field. As a result, a user able to create or modify Collection records could submit malformed UUID values, potentially causing integrity issues or unexpected behaviour… | |
| Aplazada | Crítica (9.3) | 0.21% | — | Misp ModulesAI | 13/5/2026 | 17/6/2026 | MISP modules are autonomous modules that can be used to extend MISP for new services. In 3.0.7 and earlier, a Cross-Site Request Forgery vulnerability in the MISP Modules website allowed an attacker to cause an authenticated user to submit unintended requests to the home endpoint. The vulnerability was due to the home… | |
| Aplazada | Media (5.8) | 0.13% | — | Misp ModulesAI | 13/5/2026 | 17/6/2026 | MISP modules are autonomous modules that can be used to extend MISP for new services. Prior to 3.0.7, an unsafe remote resource fetching vulnerability existed in MISP Modules expansion modules. The html_to_markdown module accepted arbitrary HTTP(S) URLs without sufficient validation, which could allow Server-Side… | |
| Analizada | Media (6.8) | 0.24% | 💥 PoC | Misp-project Misp | 7/5/2026 | 22/6/2026 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in misp allows Stored XSS. This issue affects MISP before 2.5.37. A stored cross-site scripting vulnerability exists in the template element attribute handling logic. The application accepted arbitrary values for… | |
| Analizada | Alta (8.8) | 0.66% | — | Misp-project Misp | 9/4/2026 | 22/6/2026 | MISP is an open source threat intelligence and sharing platform. Prior to 2.5.36, improper neutralization of special elements in an LDAP query in ApacheAuthenticate.php allows LDAP injection via an unsanitized username value when ApacheAuthenticate.apacheEnv is configured to use a user-controlled server variable… | |
| Modificada | Crítica (9) | 0.33% | 💥 PoC | Misp-project Misp | 15/12/2025 | 22/6/2026 | In MISP before 2.5.28, app/View/Elements/Workflows/executionPath.ctp allows XSS in the workflow execution path. | |
| Aplazada | Media (4.1) | 0.31% | — | MispAI | 28/11/2025 | 17/6/2026 | app/Model/EventReport.php in MISP before 2.5.27 allows path traversal in view picture for a site-admin. |