Vulmon
Recent Vulnerabilities
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
misp vulnerabilities and exploits
(subscribe to this query)
9.8
CVSSv3
CVE-2023-48658
An issue exists in MISP prior to 2.4.176. app/Model/AppModel.php lacks a checkParam function for alphanumerics, underscore, dash, period, and space.
Misp-project Malware Information Sharing Platform
9.8
CVSSv3
CVE-2023-48659
An issue exists in MISP prior to 2.4.176. app/Controller/AppController.php mishandles parameter parsing.
Misp-project Malware Information Sharing Platform
6.1
CVSSv3
CVE-2023-24070
app/View/AuthKeys/authkey_display.ctp in MISP up to and including 2.4.167 has an XSS in authkey add via a Referer field.
Misp-project Malware Information Sharing Platform
5.4
CVSSv3
CVE-2023-37307
In MISP prior to 2.4.172, title_for_layout is not properly sanitized in Correlations, CorrelationExclusions, and Layouts.
Misp-project Malware Information Sharing Platform
9.8
CVSSv3
CVE-2015-5719
app/Controller/TemplatesController.php in Malware Information Sharing Platform (MISP) prior to 2.3.92 does not properly restrict filenames under the tmp/files/ directory, which has unspecified impact and attack vectors.
Misp-project Malware Information Sharing Platform
9.8
CVSSv3
CVE-2015-5721
Malware Information Sharing Platform (MISP) prior to 2.3.90 allows remote malicious users to conduct PHP object injection attacks via crafted serialized data, related to TemplatesController.php and populate_event_from_template_attributes.ctp.
Misp-project Malware Information Sharing Platform
4.3
CVSSv3
CVE-2022-42724
app/Controller/UsersController.php in MISP prior to 2.4.164 allows malicious users to discover role names (this is information that only the site admin should have).
Misp-project Malware Information Sharing Platform
9.8
CVSSv3
CVE-2023-48656
An issue exists in MISP prior to 2.4.176. app/Model/AppModel.php mishandles order clauses.
Misp-project Malware Information Sharing Platform
6.1
CVSSv3
CVE-2015-5720
Multiple cross-site scripting (XSS) vulnerabilities in the template-creation feature in Malware Information Sharing Platform (MISP) prior to 2.3.90 allow remote malicious users to inject arbitrary web script or HTML via vectors involving (1) add.ctp, (2) edit.ctp, and (3) ajaxifi...
Misp-project Malware Information Sharing Platform
6.1
CVSSv3
CVE-2023-28606
js/event-graph.js in MISP prior to 2.4.169 allows XSS via event-graph node tooltips.
Misp-project Malware Information Sharing Platform
CVSSv3
CVSSv2
CVSSv3
VMScore
Recommendations:
CVE-2024-4671
unauthorized
CVE-2024-4776
CVE-2024-3407
CVE-2024-26026
CVE-2024-32888
wireless
CVE-2024-4656
template injection
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
« PREV
4
5
6
7
8
9
10
NEXT »