Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2783▼ 434 respecto a la semana anterior
Críticas / altas1335▼ 118 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)265▼ 243 respecto a la semana anterior
–

259 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaCrítica (9.8)1.8%—Misp-project Misp17/9/202122/6/2026
In MISP before 2.4.148, app/Lib/Export/OpendataExport.php mishandles parameter data that is used in a shell_exec call.
ModificadaCrítica (9.8)0.95%—Misp-project Misp19/8/202122/6/2026
MISP 2.4.148, in certain configurations, allows SQL injection via the app/Model/Log.php $conditions['org'] value.
ModificadaMedia (5.4)0.68%—Misp-project Misp30/7/202122/6/2026
app/View/GalaxyElements/ajax/index.ctp in MISP 2.4.147 allows Stored XSS when viewing galaxy cluster elements in JSON format.
ModificadaMedia (5.4)0.59%—Misp-project Misp30/7/202122/6/2026
app/View/Elements/GalaxyClusters/view_relation_tree.ctp in MISP 2.4.147 allows Stored XSS when viewing galaxy cluster relationships.
ModificadaMedia (5.4)0.51%—Misp-project Misp26/7/202122/6/2026
app/View/GalaxyClusters/add.ctp in MISP 2.4.146 allows Stored XSS when forking a galaxy cluster.
ModificadaMedia (6.1)0.63%—Misp-project Misp7/7/202122/6/2026
app/View/SharingGroups/view.ctp in MISP before 2.4.146 allows stored XSS in the sharing groups view.
ModificadaCrítica (9.8)1.1%—Misp-project Misp25/6/202122/6/2026
app/View/Elements/genericElements/IndexTable/Fields/generic_field.ctp in MISP 2.4.144 does not sanitize certain data related to generic-template:index.
ModificadaAlta (7.5)1.0%—Misp-project Misp23/4/202122/6/2026
In app/Model/MispObject.php in MISP 2.4.141, an incorrect sharing group association could lead to information disclosure on an event edit. When an object has a sharing group associated with an event edit, the sharing group object is ignored and instead the passed local ID is reused.
ModificadaMedia (5.5)0.29%—Misp-project Misp2/3/202122/6/2026
An issue was discovered in app/Model/SharingGroupServer.php in MISP 2.4.139. In the implementation of Sharing Groups, the "all org" flag sometimes provided view access to unintended actors.
ModificadaMedia (6.1)0.83%—Misp-project Misp26/1/202122/6/2026
A cross-site scripting (XSS) vulnerability exists in MISP v2.4.128 in app/Controller/UserSettingsController.php at SetHomePage() function. Due to a lack of controller validation in "path" parameter, an attacker can execute malicious JavaScript code.
ModificadaMedia (6.1)0.77%—Misp-project Misp19/1/202122/6/2026
MISP 2.4.136 has XSS via a crafted URL to the app/View/Elements/global_menu.ctp user homepage favourite button.
ModificadaMedia (6.1)0.80%—Misp-project Misp19/1/202122/6/2026
MISP 2.4.136 has XSS via galaxy cluster element values to app/View/GalaxyElements/ajax/index.ctp. Reference types could contain javascript: URLs.
ModificadaMedia (6.1)0.80%—Misp-project Misp19/1/202122/6/2026
MISP 2.4.136 has Stored XSS in the galaxy cluster view via a cluster name to app/View/GalaxyClusters/view.ctp.
ModificadaCrítica (9.1)1.3%—Misp-project Misp19/1/202122/6/2026
The default setting of MISP 2.4.136 did not enable the requirements (aka require_password_confirmation) to provide the previous password when changing a password.
ModificadaMedia (6.1)0.78%—Misp-project Misp6/12/202022/6/2026
app/View/Elements/genericElements/SingleViews/Fields/genericField.ctp in MISP 2.4.135 has XSS via the authkey comment field.
ModificadaCrítica (9.8)1.3%—Misp-project Misp24/11/202022/6/2026
MISP before 2.4.135 lacks an ACL check, related to app/Controller/GalaxyElementsController.php and app/Model/GalaxyElement.php.
ModificadaMedia (6.1)0.82%—Misp-project Misp19/11/202022/6/2026
In MISP 2.4.134, XSS exists in the template element index view because the id parameter is mishandled.
ModificadaAlta (7.5)1.3%—Misp-project Misp2/11/202022/6/2026
MISP through 2.4.133 allows SSRF in the REST client via the use_full_path parameter with an arbitrary URL.
ModificadaAlta (7.5)1.2%—Misp-project Misp18/9/202022/6/2026
An issue was discovered in MISP before 2.4.132. It can perform an unwanted action because of a POST operation on a form that is not linked to the login page.
ModificadaAlta (8.8)0.49%—Misp-project Misp14/7/202022/6/2026
In MISP before 2.4.129, setting a favourite homepage was not CSRF protected.
ModificadaMedia (4.3)0.69%—Misp-project Misp30/6/202022/6/2026
An issue was discovered in MISP 2.4.128. app/Controller/EventsController.php lacks an event ACL check before proceeding to allow a user to send an event contact form.
ModificadaCrítica (9.8)1.5%—Misp-project Misp30/6/202022/6/2026
An issue was discovered in MISP 2.4.128. app/Controller/AttributesController.php has insufficient ACL checks in the attachment downloader.
ModificadaAlta (7.5)1.3%—Misp-project Misp22/6/202022/6/2026
app/Model/Attribute.php in MISP 2.4.127 lacks an ACL lookup on attribute correlations. This occurs when querying the attribute restsearch API, revealing metadata about a correlating but unreachable attribute.
ModificadaMedia (6.1)0.86%—Misp-project Misp18/5/202022/6/2026
app/View/Events/resolved_attributes.ctp in MISP before 2.4.126 has XSS in the resolved attributes view.
ModificadaCrítica (9.8)1.2%—Misp-maltego15/5/202017/6/2026
MISP MISP-maltego 1.4.4 incorrectly shares a MISP connection across users in a remote-transform use case.
Orbitaley — Vulnerabilidades