Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2783▼ 434 respecto a la semana anterior
Críticas / altas1335▼ 118 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)265▼ 243 respecto a la semana anterior
259 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Crítica (9.8) | 1.8% | — | Misp-project Misp | 17/9/2021 | 22/6/2026 | In MISP before 2.4.148, app/Lib/Export/OpendataExport.php mishandles parameter data that is used in a shell_exec call. | |
| Modificada | Crítica (9.8) | 0.95% | — | Misp-project Misp | 19/8/2021 | 22/6/2026 | MISP 2.4.148, in certain configurations, allows SQL injection via the app/Model/Log.php $conditions['org'] value. | |
| Modificada | Media (5.4) | 0.68% | — | Misp-project Misp | 30/7/2021 | 22/6/2026 | app/View/GalaxyElements/ajax/index.ctp in MISP 2.4.147 allows Stored XSS when viewing galaxy cluster elements in JSON format. | |
| Modificada | Media (5.4) | 0.59% | — | Misp-project Misp | 30/7/2021 | 22/6/2026 | app/View/Elements/GalaxyClusters/view_relation_tree.ctp in MISP 2.4.147 allows Stored XSS when viewing galaxy cluster relationships. | |
| Modificada | Media (5.4) | 0.51% | — | Misp-project Misp | 26/7/2021 | 22/6/2026 | app/View/GalaxyClusters/add.ctp in MISP 2.4.146 allows Stored XSS when forking a galaxy cluster. | |
| Modificada | Media (6.1) | 0.63% | — | Misp-project Misp | 7/7/2021 | 22/6/2026 | app/View/SharingGroups/view.ctp in MISP before 2.4.146 allows stored XSS in the sharing groups view. | |
| Modificada | Crítica (9.8) | 1.1% | — | Misp-project Misp | 25/6/2021 | 22/6/2026 | app/View/Elements/genericElements/IndexTable/Fields/generic_field.ctp in MISP 2.4.144 does not sanitize certain data related to generic-template:index. | |
| Modificada | Alta (7.5) | 1.0% | — | Misp-project Misp | 23/4/2021 | 22/6/2026 | In app/Model/MispObject.php in MISP 2.4.141, an incorrect sharing group association could lead to information disclosure on an event edit. When an object has a sharing group associated with an event edit, the sharing group object is ignored and instead the passed local ID is reused. | |
| Modificada | Media (5.5) | 0.29% | — | Misp-project Misp | 2/3/2021 | 22/6/2026 | An issue was discovered in app/Model/SharingGroupServer.php in MISP 2.4.139. In the implementation of Sharing Groups, the "all org" flag sometimes provided view access to unintended actors. | |
| Modificada | Media (6.1) | 0.83% | — | Misp-project Misp | 26/1/2021 | 22/6/2026 | A cross-site scripting (XSS) vulnerability exists in MISP v2.4.128 in app/Controller/UserSettingsController.php at SetHomePage() function. Due to a lack of controller validation in "path" parameter, an attacker can execute malicious JavaScript code. | |
| Modificada | Media (6.1) | 0.77% | — | Misp-project Misp | 19/1/2021 | 22/6/2026 | MISP 2.4.136 has XSS via a crafted URL to the app/View/Elements/global_menu.ctp user homepage favourite button. | |
| Modificada | Media (6.1) | 0.80% | — | Misp-project Misp | 19/1/2021 | 22/6/2026 | MISP 2.4.136 has XSS via galaxy cluster element values to app/View/GalaxyElements/ajax/index.ctp. Reference types could contain javascript: URLs. | |
| Modificada | Media (6.1) | 0.80% | — | Misp-project Misp | 19/1/2021 | 22/6/2026 | MISP 2.4.136 has Stored XSS in the galaxy cluster view via a cluster name to app/View/GalaxyClusters/view.ctp. | |
| Modificada | Crítica (9.1) | 1.3% | — | Misp-project Misp | 19/1/2021 | 22/6/2026 | The default setting of MISP 2.4.136 did not enable the requirements (aka require_password_confirmation) to provide the previous password when changing a password. | |
| Modificada | Media (6.1) | 0.78% | — | Misp-project Misp | 6/12/2020 | 22/6/2026 | app/View/Elements/genericElements/SingleViews/Fields/genericField.ctp in MISP 2.4.135 has XSS via the authkey comment field. | |
| Modificada | Crítica (9.8) | 1.3% | — | Misp-project Misp | 24/11/2020 | 22/6/2026 | MISP before 2.4.135 lacks an ACL check, related to app/Controller/GalaxyElementsController.php and app/Model/GalaxyElement.php. | |
| Modificada | Media (6.1) | 0.82% | — | Misp-project Misp | 19/11/2020 | 22/6/2026 | In MISP 2.4.134, XSS exists in the template element index view because the id parameter is mishandled. | |
| Modificada | Alta (7.5) | 1.3% | — | Misp-project Misp | 2/11/2020 | 22/6/2026 | MISP through 2.4.133 allows SSRF in the REST client via the use_full_path parameter with an arbitrary URL. | |
| Modificada | Alta (7.5) | 1.2% | — | Misp-project Misp | 18/9/2020 | 22/6/2026 | An issue was discovered in MISP before 2.4.132. It can perform an unwanted action because of a POST operation on a form that is not linked to the login page. | |
| Modificada | Alta (8.8) | 0.49% | — | Misp-project Misp | 14/7/2020 | 22/6/2026 | In MISP before 2.4.129, setting a favourite homepage was not CSRF protected. | |
| Modificada | Media (4.3) | 0.69% | — | Misp-project Misp | 30/6/2020 | 22/6/2026 | An issue was discovered in MISP 2.4.128. app/Controller/EventsController.php lacks an event ACL check before proceeding to allow a user to send an event contact form. | |
| Modificada | Crítica (9.8) | 1.5% | — | Misp-project Misp | 30/6/2020 | 22/6/2026 | An issue was discovered in MISP 2.4.128. app/Controller/AttributesController.php has insufficient ACL checks in the attachment downloader. | |
| Modificada | Alta (7.5) | 1.3% | — | Misp-project Misp | 22/6/2020 | 22/6/2026 | app/Model/Attribute.php in MISP 2.4.127 lacks an ACL lookup on attribute correlations. This occurs when querying the attribute restsearch API, revealing metadata about a correlating but unreachable attribute. | |
| Modificada | Media (6.1) | 0.86% | — | Misp-project Misp | 18/5/2020 | 22/6/2026 | app/View/Events/resolved_attributes.ctp in MISP before 2.4.126 has XSS in the resolved attributes view. | |
| Modificada | Crítica (9.8) | 1.2% | — | Misp-maltego | 15/5/2020 | 17/6/2026 | MISP MISP-maltego 1.4.4 incorrectly shares a MISP connection across users in a remote-transform use case. |