Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2676▼ 422 respecto a la semana anterior
Críticas / altas1295▼ 73 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)244▼ 274 respecto a la semana anterior
253 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (5.1) | 0.76% | — | MispAI | 22/9/2026 | 22/9/2026 | In MISP, the __statisticsOrgs method in UsersController.php used the organization name directly as a file-system path component when checking for the existence of an organization logo image. The original code called file_exists() with a path constructed as APP . 'webroot' . DS . 'img' . DS . 'orgs' . DS . $k . '.png',… | |
| Aplazada | Media (5.3) | 0.72% | — | MispAI | 22/9/2026 | 22/9/2026 | The findOrgImage method in MISP's OrgImgHelper constructs a filesystem path by concatenating a user-supplied organization identifier with a fixed image directory and a file extension, then calls file_exists() on the resulting path. The organization name field is attacker-controllable through event import, which sets… | |
| Aplazada | Media (5.3) | 0.38% | — | MispAI | 22/9/2026 | 22/9/2026 | MISP contains an authorization flaw in the Organisation model's captureOrg method. When the $force parameter is set to true, the method unconditionally overwrites organization metadata fields without verifying that the invoking user holds sufficient privileges. A user with a sharing group (SG) editor role can trigger… | |
| Aplazada | Media (5.3) | 0.51% | — | MispAI | 22/9/2026 | 22/9/2026 | In MISP, the EventReport::uploadPicture method in processed a caller-supplied tmp_name field by invoking file_exists(), mime_content_type(), and exif_imagetype() on the supplied path before verifying that the value was a genuine PHP upload via is_uploaded_file(). An authenticated user holding the perm_add permission… | |
| Aplazada | Media (5.3) | 0.35% | — | MispAI | 22/9/2026 | 22/9/2026 | MISP contains an access control flaw in the EventReports functionality. The replaceSuggestionInReport action, which allows modification of suggestion content within an event report, was incorrectly mapped to the wildcard permission ('*') in the ACLComponent, making it accessible to any authenticated user regardless of… | |
| Aplazada | Media (5.3) | 0.39% | — | MispAI | 22/9/2026 | 22/9/2026 | In MISP, the Overmind event view enriches an event with its most recent attached report for preview purposes. The enrichment logic fetched the report using only the event ID as the lookup condition, without applying the report's own distribution/ACL constraints. Because MISP reports carry an independent distribution… | |
| Aplazada | Media (4.8) | 0.42% | — | MispAI | 22/9/2026 | 22/9/2026 | MISP contains a stored cross-site scripting (XSS) vulnerability in the admin email composition screen. The MISP.org organization name setting was interpolated directly into a JavaScript string literal using an unescaped PHP echo: var org = "<?php echo $org;?>";. Because the value was placed inside a double-quoted… | |
| Aplazada | Media (6.9) | 0.60% | — | MispAI | 22/9/2026 | 22/9/2026 | MISP's RequestHandlerComponent automatically decodes XML request bodies on all write requests. The underlying Xml::build() library contains a logic error in its readFile guard condition (readFile && http || https), where PHP operator precedence causes the https branch to bypass the readFile check entirely. As a… | |
| Aplazada | Media (5.3) | 0.41% | — | MispAI | 22/9/2026 | 22/9/2026 | In MISP, the queryEnrichment method in EventsController.php accepted a module name parameter and iterated over the list of enabled modules to find a match. If the specified module was not present in the enabled modules list, the code silently continued processing using default parameters (format set to 'simplified'… | |
| Aplazada | Media (5.3) | 0.37% | — | MispAI | 22/9/2026 | 22/9/2026 | In MISP, the CollectionsController add() method enforced the sharing-group usability authorization check and element capture only when the HTTP request method was POST. However, the underlying CRUDComponent::add() method persists data on both POST and PUT requests. As a result, an authenticated user could issue a PUT… | |
| Aplazada | Media (6.9) | 0.18% | — | MispAI | 22/9/2026 | 22/9/2026 | The MISP installer scripts (for Debian 12, Debian 13, Ubuntu 24.04, and RHEL 9.4) create a log file at /var/log/misp_install.log and a named pipe (FIFO) at /var/log/misp_install.log.pipe to capture all installer output. The log captures highly sensitive data including the generated admin password, database passwords,… | |
| Aplazada | Media (5.1) | 0.54% | — | MispAI | 22/9/2026 | 22/9/2026 | MISP contains a reflected cross-site scripting (XSS) vulnerability in the event REST search export confirmation form. The view template app/View/Events/ajax/eventRestSearchExportConfirmationForm.ctp renders a URL-supplied event ID list into a single-quoted JavaScript string literal using PHP's json_encode() without… | |
| Aplazada | Media (5.1) | 0.44% | — | Misp-project MispAI | 22/9/2026 | 22/9/2026 | MISP contains a reflected cross-site scripting (XSS) vulnerability in the attribute histogram view. The $selectedTypes variable, which is derived from the URL path segment , was interpolated directly into a JavaScript array literal inside an onClick HTML attribute without any encoding or escaping. An attacker who can… | |
| Aplazada | Media (4.8) | 0.39% | — | MispAI | 22/9/2026 | 22/9/2026 | MISP contains a reflected cross-site scripting (XSS) vulnerability in the AnalystDataController::viewForObject action. The method accepted a parent object type parameter from the URL without validation and passed it to the Overmind-themed AnalystData thread view element, where it was interpolated into two translated… | |
| Aplazada | Media (6.9) | 0.27% | — | MispAICakephpAI | 22/9/2026 | 22/9/2026 | MISP's WorkflowsController exposed the moduleStatelessExecution action in the Security component's unlockedActions list. In CakePHP, listing an action in unlockedActions disables both the CSRF token check and the field hash validation for that action. Because moduleStatelessExecution executes a workflow module's… | |
| Aplazada | Alta (7.1) | 0.21% | — | MispAI | 21/9/2026 | 21/9/2026 | MISP has a security issue that could let an attacker change threat-intelligence data through a logged-in user’s browser without that user knowingly approving the change. The affected function did not properly enforce MISP’s usual protection against forged requests. Because of this, an attacker could create a malicious… | |
| Aplazada | Alta (8.3) | 0.38% | — | MispAI | 21/9/2026 | 21/9/2026 | MISP has a file-handling vulnerability that could let certain authenticated users make the server read files or access internal network services. When importing an XML file, MISP did not properly verify that the uploaded content was actually XML. Because of this, a user with permission to modify data could upload a… | |
| Aplazada | Media (6.3) | 0.35% | — | MispAI | 21/9/2026 | 21/9/2026 | When a regular user adds a reference between objects or attributes, MISP checks whether the user can access the overall event, but it does not always check whether the individual pieces of data are also allowed for that user. Because of this, someone who can view an event could potentially access attributes or objects… | |
| Aplazada | Media (6.4) | 0.37% | — | MispAI | 21/9/2026 | 21/9/2026 | When a user creates or edits a report inside an event, MISP can identify an existing report using its UUID without properly checking whether that report actually belongs to the same event. As a result, a user who has editing rights on one event could potentially move a report from another event into their own event,… | |
| Aplazada | Alta (8.6) | 0.51% | — | MispAI | 21/9/2026 | 21/9/2026 | The MISP blocklist workflow module accepted a user-supplied blocklist filename parameter without validating the file extension. The only sanitization applied was basename() to strip path components and a check for empty or dot values. A site administrator could specify a filename with an arbitrary extension that would… | |
| Aplazada | Alta (8.7) | 0.37% | — | MispAI | 21/9/2026 | 21/9/2026 | MISP has a security issue that can let a user gain more access than their API key is supposed to allow. A read-only API key should only let someone view information. However, after logging in with such a key, a specific MISP function could accidentally restore the user’s normal account permissions. This means someone… | |
| Aplazada | Media (6.9) | 0.58% | — | MispAI | 21/9/2026 | 21/9/2026 | The login() function in MISP's UsersController.php contained insufficient HTTP method validation for several security-critical code paths. The original code used an allowlist approach, checking only for specific HTTP methods (POST and PUT) before enforcing bruteforce protection, email one-time-password (OTP)… | |
| Aplazada | Alta (8.3) | 0.37% | — | MispAI | 21/9/2026 | 21/9/2026 | MISP contains an insecure direct object reference vulnerability in the processModuleResultsData method of the Event model. When processing module results, the code iterates over EventReport entries supplied in the resolved data and saves each one. Unlike the adjacent attribute and object processing loops, the report… | |
| Aplazada | Media (6.3) | 0.39% | — | MispAI | 21/9/2026 | 21/9/2026 | MISP contains a DOM-based cross-site scripting (XSS) vulnerability in the contextual menu JavaScript component. The ContextualMenu class populates HTML <option> elements by assigning user-controllable values to the innerHTML property. Because innerHTML parses and renders HTML markup, any untrusted string supplied as… | |
| Aplazada | Media (6.3) | 0.39% | — | MispAI | 21/9/2026 | 21/9/2026 | MISP contains a stored cross-site scripting (XSS) vulnerability in the default theme's Galaxies index page. When a MISP instance detects unknown custom or default galaxy clusters during synchronization, it renders sample tag names in an informational notice directed at site administrators. In the default theme, these… |