Vulmon
Recent Vulnerabilities
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
misp project misp vulnerabilities and exploits
(subscribe to this query)
NA
CVE-2022-47928
In MISP prior to 2.4.167, there is XSS in the template file uploads in app/View/Templates/upload_file.ctp.
Misp-project Malware Information Sharing Platform
NA
CVE-2023-48657
An issue exists in MISP prior to 2.4.176. app/Model/AppModel.php mishandles filters.
Misp-project Malware Information Sharing Platform
NA
CVE-2023-48659
An issue exists in MISP prior to 2.4.176. app/Controller/AppController.php mishandles parameter parsing.
Misp-project Malware Information Sharing Platform
NA
CVE-2023-24070
app/View/AuthKeys/authkey_display.ctp in MISP up to and including 2.4.167 has an XSS in authkey add via a Referer field.
Misp-project Malware Information Sharing Platform
10
CVSSv2
CVE-2015-5719
app/Controller/TemplatesController.php in Malware Information Sharing Platform (MISP) prior to 2.3.92 does not properly restrict filenames under the tmp/files/ directory, which has unspecified impact and attack vectors.
Misp-project Malware Information Sharing Platform
7.5
CVSSv2
CVE-2015-5721
Malware Information Sharing Platform (MISP) prior to 2.3.90 allows remote malicious users to conduct PHP object injection attacks via crafted serialized data, related to TemplatesController.php and populate_event_from_template_attributes.ctp.
Misp-project Malware Information Sharing Platform
NA
CVE-2023-37307
In MISP prior to 2.4.172, title_for_layout is not properly sanitized in Correlations, CorrelationExclusions, and Layouts.
Misp-project Malware Information Sharing Platform
NA
CVE-2023-28606
js/event-graph.js in MISP prior to 2.4.169 allows XSS via event-graph node tooltips.
Misp-project Malware Information Sharing Platform
NA
CVE-2023-28607
js/event-graph.js in MISP prior to 2.4.169 allows XSS via the event-graph relationship tooltip.
Misp-project Malware Information Sharing Platform
4.3
CVSSv2
CVE-2015-5720
Multiple cross-site scripting (XSS) vulnerabilities in the template-creation feature in Malware Information Sharing Platform (MISP) prior to 2.3.90 allow remote malicious users to inject arbitrary web script or HTML via vectors involving (1) add.ctp, (2) edit.ctp, and (3) ajaxifi...
Misp-project Malware Information Sharing Platform
CVSSv2
CVSSv2
CVSSv3
VMScore
Recommendations:
spoof
CVE-2024-34928
CVE-2024-5291
deserialization
CVE-2024-4471
CVE-2024-4956
CVE-2024-32002
CVE-2024-5227
unspecified
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
« PREV
1
2
3
NEXT »