misp-project kayıtları
misp-project üreticisine ait 141 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 0 · %0
- Silahlaştırılmış
- 0 · %0
- Pre-auth RCE
- 1
- Düzeltme kaydı olan
- %7,1
- Yayından KEV’e ortanca
- KEV’e giren kayıt yok
Tekrar eden sınıflar
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')49
- CWE-862 Missing Authorization8
- CWE-200 Exposure of Sensitive Information to an Unauthorized Actor6
- CWE-863 Incorrect Authorization6
- CWE-20 Improper Input Validation6
- CWE-639 Authorization Bypass Through User-Controlled Key4
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWETüm kayıtlar
141 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
40Planlayın | CVE-2018-19908Kavram kanıtı | An issue was discovered in MISP 2.4.9x before 2.4.99.misp-project · misp · CWE-78 | Yüksek8,8 | — | %17,3 | 6 Ara 2018 |
40Planlayın | CVE-2015-5721İstismar yok | Malware Information Sharing Platform (MISP) before 2.3.90 allows remote attackers to conduct PHP object injection attacks via crafted serialmisp-project · misp · CWE-94 | Kritik9,8 | — | %2,6 | 3 Eyl 2016 |
40Planlayın | CVE-2015-5719İstismar yok | app/Controller/TemplatesController.php in Malware Information Sharing Platform (MISP) before 2.3.92 does not properly restrict filenames undmisp-project · misp | Kritik9,8 | — | %2,3 | 3 Eyl 2016 |
40Planlayın | CVE-2022-29528İstismar yok | An issue was discovered in MISP before 2.4.158.misp-project · misp · CWE-502 | Kritik9,8 | — | %2,2 | 20 Nis 2022 |
40Planlayın | CVE-2021-41326İstismar yok | In MISP before 2.4.148, app/Lib/Export/OpendataExport.php mishandles parameter data that is used in a shell_exec call.misp-project · misp | Kritik9,8 | — | %1,8 | 17 Eyl 2021 |
39İzleyin | CVE-2018-12649İstismar yok | An issue was discovered in app/Controller/UsersController.php in MISP 2.4.92.misp-project · misp · CWE-307 | Kritik9,8 | — | %1,5 | 22 Haz 2018 |
39İzleyin | CVE-2020-15411İstismar yok | An issue was discovered in MISP 2.4.128.misp-project · misp | Kritik9,8 | — | %1,5 | 30 Haz 2020 |
39İzleyin | CVE-2022-48328İstismar yok | app/Controller/Component/IndexFilterComponent.php in MISP before 2.4.167 mishandles ordered_url_params and additional_delimiters.misp-project · misp · CWE-755 | Kritik9,8 | — | %1,3 | 20 Şub 2023 |
39İzleyin | CVE-2020-29006İstismar yok | MISP before 2.4.135 lacks an ACL check, related to app/Controller/GalaxyElementsController.php and app/Model/GalaxyElement.php.misp-project · misp · CWE-862 | Kritik9,8 | — | %1,3 | 24 Kas 2020 |
39İzleyin | CVE-2021-35502İstismar yok | app/View/Elements/genericElements/IndexTable/Fields/generic_field.ctp in MISP 2.4.144 does not sanitize certain data related to generic-tempmisp-project · misp | Kritik9,8 | — | %1,1 | 25 Haz 2021 |
39İzleyin | CVE-2021-39302İstismar yok | MISP 2.4.148, in certain configurations, allows SQL injection via the app/Model/Log.php $conditions['org'] value.misp-project · misp · CWE-89 | Kritik9,8 | — | %0,9 | 19 Ağu 2021 |
39İzleyin | CVE-2022-48329İstismar yok | MISP before 2.4.166 unsafely allows users to use the order parameter, related to app/Model/Attribute.php, app/Model/GalaxyCluster.php, app/Mmisp-project · misp · CWE-755 | Kritik9,8 | — | %0,9 | 20 Şub 2023 |
39İzleyin | CVE-2023-48655İstismar yok | An issue was discovered in MISP before 2.4.176.misp-project · misp · CWE-116 | Kritik9,8 | — | %0,9 | 17 Kas 2023 |
39İzleyin | CVE-2023-48657İstismar yok | An issue was discovered in MISP before 2.4.176.misp-project · misp | Kritik9,8 | — | %0,9 | 17 Kas 2023 |
39İzleyin | CVE-2023-48656İstismar yok | An issue was discovered in MISP before 2.4.176.misp-project · misp | Kritik9,8 | — | %0,9 | 17 Kas 2023 |
39İzleyin | CVE-2023-48658İstismar yok | An issue was discovered in MISP before 2.4.176.misp-project · misp | Kritik9,8 | — | %0,9 | 17 Kas 2023 |
39İzleyin | CVE-2023-48659İstismar yok | An issue was discovered in MISP before 2.4.176.misp-project · misp | Kritik9,8 | — | %0,9 | 17 Kas 2023 |
39İzleyin | CVE-2024-25675İstismar yok | An issue was discovered in MISP before 2.4.184.misp-project · misp · CWE-749 | Kritik9,8 | — | %0,8 | 9 Şub 2024 |
39İzleyin | CVE-2024-29859İstismar yok | In MISP before 2.4.187, add_misp_export in app/Controller/EventsController.php does not properly check for a valid file upload.misp-project · misp · CWE-434 | Kritik9,8 | — | %0,8 | 21 Mar 2024 |
39İzleyin | CVE-2023-50918İstismar yok | app/Controller/AuditLogsController.php in MISP before 2.4.182 mishandles ACLs for audit logs.misp-project · misp | Kritik9,8 | — | %0,8 | 15 Ara 2023 |
39İzleyin | CVE-2024-25674İstismar yok | An issue was discovered in MISP before 2.4.184.misp-project · misp · CWE-434 | Kritik9,8 | — | %0,8 | 9 Şub 2024 |
39İzleyin | CVE-2023-24028İstismar yok | In MISP 2.4.167, app/Controller/Component/ACLComponent.php has incorrect access control for the decaying import function.misp-project · misp · CWE-284 | Kritik9,8 | — | %0,7 | 20 Oca 2023 |
39İzleyin | CVE-2024-29858İstismar yok | In MISP before 2.4.187, __uploadLogo in app/Controller/OrganisationsController.php does not properly check for a valid logo upload.misp-project · misp · CWE-616 | Kritik9,8 | — | %0,4 | 21 Mar 2024 |
38İzleyin | CVE-2026-85216İstismar yok | MISP LDAP and LinOTP Authentication Bypass via Empty or Invalid Credentialsmisp-project · misp · CWE-521 | Kritik9,5 | — | %0,9 | 3 Eyl 2026 |
37İzleyin | CVE-2026-44381Kavram kanıtı | MISP: SQL injection via unvalidated ordering parameters in event and shadow attribute listingsmisp-project · misp · CWE-89 | Kritik9,3 | — | %0,8 | 13 May 2026 |
- CVE-2018-1990840Planlayın
An issue was discovered in MISP 2.4.9x before 2.4.99.
YüksekCVSS 8,8Kavram kanıtıEPSS %17misp-project · misp6 Ara 2018
- CVE-2015-572140Planlayın
Malware Information Sharing Platform (MISP) before 2.3.90 allows remote attackers to conduct PHP object injection attacks via crafted serial
KritikCVSS 9,8İstismar yokEPSS %3misp-project · misp3 Eyl 2016
- CVE-2015-571940Planlayın
app/Controller/TemplatesController.php in Malware Information Sharing Platform (MISP) before 2.3.92 does not properly restrict filenames und
KritikCVSS 9,8İstismar yokEPSS %2misp-project · misp3 Eyl 2016
- CVE-2022-2952840Planlayın
An issue was discovered in MISP before 2.4.158.
KritikCVSS 9,8İstismar yokEPSS %2misp-project · misp20 Nis 2022
- CVE-2021-4132640Planlayın
In MISP before 2.4.148, app/Lib/Export/OpendataExport.php mishandles parameter data that is used in a shell_exec call.
KritikCVSS 9,8İstismar yokEPSS %2misp-project · misp17 Eyl 2021
- CVE-2018-1264939İzleyin
An issue was discovered in app/Controller/UsersController.php in MISP 2.4.92.
KritikCVSS 9,8İstismar yokEPSS %1misp-project · misp22 Haz 2018
- CVE-2020-1541139İzleyin
An issue was discovered in MISP 2.4.128.
KritikCVSS 9,8İstismar yokEPSS %1misp-project · misp30 Haz 2020
- CVE-2022-4832839İzleyin
app/Controller/Component/IndexFilterComponent.php in MISP before 2.4.167 mishandles ordered_url_params and additional_delimiters.
KritikCVSS 9,8İstismar yokEPSS %1misp-project · misp20 Şub 2023
- CVE-2020-2900639İzleyin
MISP before 2.4.135 lacks an ACL check, related to app/Controller/GalaxyElementsController.php and app/Model/GalaxyElement.php.
KritikCVSS 9,8İstismar yokEPSS %1misp-project · misp24 Kas 2020
- CVE-2021-3550239İzleyin
app/View/Elements/genericElements/IndexTable/Fields/generic_field.ctp in MISP 2.4.144 does not sanitize certain data related to generic-temp
KritikCVSS 9,8İstismar yokEPSS %1misp-project · misp25 Haz 2021
- CVE-2021-3930239İzleyin
MISP 2.4.148, in certain configurations, allows SQL injection via the app/Model/Log.php $conditions['org'] value.
KritikCVSS 9,8İstismar yokEPSS %1misp-project · misp19 Ağu 2021
- CVE-2022-4832939İzleyin
MISP before 2.4.166 unsafely allows users to use the order parameter, related to app/Model/Attribute.php, app/Model/GalaxyCluster.php, app/M
KritikCVSS 9,8İstismar yokEPSS %1misp-project · misp20 Şub 2023
- CVE-2023-4865539İzleyin
An issue was discovered in MISP before 2.4.176.
KritikCVSS 9,8İstismar yokEPSS %1misp-project · misp17 Kas 2023
- CVE-2023-4865739İzleyin
An issue was discovered in MISP before 2.4.176.
KritikCVSS 9,8İstismar yokEPSS %1misp-project · misp17 Kas 2023
- CVE-2023-4865639İzleyin
An issue was discovered in MISP before 2.4.176.
KritikCVSS 9,8İstismar yokEPSS %1misp-project · misp17 Kas 2023
- CVE-2023-4865839İzleyin
An issue was discovered in MISP before 2.4.176.
KritikCVSS 9,8İstismar yokEPSS %1misp-project · misp17 Kas 2023
- CVE-2023-4865939İzleyin
An issue was discovered in MISP before 2.4.176.
KritikCVSS 9,8İstismar yokEPSS %1misp-project · misp17 Kas 2023
- CVE-2024-2567539İzleyin
An issue was discovered in MISP before 2.4.184.
KritikCVSS 9,8İstismar yokEPSS %1misp-project · misp9 Şub 2024
- CVE-2024-2985939İzleyin
In MISP before 2.4.187, add_misp_export in app/Controller/EventsController.php does not properly check for a valid file upload.
KritikCVSS 9,8İstismar yokEPSS %1misp-project · misp21 Mar 2024
- CVE-2023-5091839İzleyin
app/Controller/AuditLogsController.php in MISP before 2.4.182 mishandles ACLs for audit logs.
KritikCVSS 9,8İstismar yokEPSS %1misp-project · misp15 Ara 2023
- CVE-2024-2567439İzleyin
An issue was discovered in MISP before 2.4.184.
KritikCVSS 9,8İstismar yokEPSS %1misp-project · misp9 Şub 2024
- CVE-2023-2402839İzleyin
In MISP 2.4.167, app/Controller/Component/ACLComponent.php has incorrect access control for the decaying import function.
KritikCVSS 9,8İstismar yokEPSS %1misp-project · misp20 Oca 2023
- CVE-2024-2985839İzleyin
In MISP before 2.4.187, __uploadLogo in app/Controller/OrganisationsController.php does not properly check for a valid logo upload.
KritikCVSS 9,8İstismar yokEPSS %0misp-project · misp21 Mar 2024
- CVE-2026-8521638İzleyin
MISP LDAP and LinOTP Authentication Bypass via Empty or Invalid Credentials
KritikCVSS 9,5İstismar yokEPSS %1misp-project · misp3 Eyl 2026
- CVE-2026-4438137İzleyin
MISP: SQL injection via unvalidated ordering parameters in event and shadow attribute listings
KritikCVSS 9,3Kavram kanıtıEPSS %1misp-project · misp13 May 2026