Skip to content
Noroxi

misp-project records

141 published records for vendor misp-project.

Researcher profile

Entered KEV
0 · 0%
Weaponized
0 · 0%
Pre-auth RCE
1
With a fix record
7.1%
Median publish → KEV
No record has entered KEV

All records

141 records
  • An issue was discovered in MISP 2.4.9x before 2.4.99.

    HighCVSS 8.8Proof of conceptEPSS 17%

    misp-project · mispDec 6, 2018

  • Malware Information Sharing Platform (MISP) before 2.3.90 allows remote attackers to conduct PHP object injection attacks via crafted serial

    CriticalCVSS 9.8No exploitEPSS 3%

    misp-project · mispSep 3, 2016

  • app/Controller/TemplatesController.php in Malware Information Sharing Platform (MISP) before 2.3.92 does not properly restrict filenames und

    CriticalCVSS 9.8No exploitEPSS 2%

    misp-project · mispSep 3, 2016

  • An issue was discovered in MISP before 2.4.158.

    CriticalCVSS 9.8No exploitEPSS 2%

    misp-project · mispApr 20, 2022

  • In MISP before 2.4.148, app/Lib/Export/OpendataExport.php mishandles parameter data that is used in a shell_exec call.

    CriticalCVSS 9.8No exploitEPSS 2%

    misp-project · mispSep 17, 2021

  • An issue was discovered in app/Controller/UsersController.php in MISP 2.4.92.

    CriticalCVSS 9.8No exploitEPSS 1%

    misp-project · mispJun 22, 2018

  • An issue was discovered in MISP 2.4.128.

    CriticalCVSS 9.8No exploitEPSS 1%

    misp-project · mispJun 30, 2020

  • app/Controller/Component/IndexFilterComponent.php in MISP before 2.4.167 mishandles ordered_url_params and additional_delimiters.

    CriticalCVSS 9.8No exploitEPSS 1%

    misp-project · mispFeb 20, 2023

  • MISP before 2.4.135 lacks an ACL check, related to app/Controller/GalaxyElementsController.php and app/Model/GalaxyElement.php.

    CriticalCVSS 9.8No exploitEPSS 1%

    misp-project · mispNov 24, 2020

  • app/View/Elements/genericElements/IndexTable/Fields/generic_field.ctp in MISP 2.4.144 does not sanitize certain data related to generic-temp

    CriticalCVSS 9.8No exploitEPSS 1%

    misp-project · mispJun 25, 2021

  • MISP 2.4.148, in certain configurations, allows SQL injection via the app/Model/Log.php $conditions['org'] value.

    CriticalCVSS 9.8No exploitEPSS 1%

    misp-project · mispAug 19, 2021

  • MISP before 2.4.166 unsafely allows users to use the order parameter, related to app/Model/Attribute.php, app/Model/GalaxyCluster.php, app/M

    CriticalCVSS 9.8No exploitEPSS 1%

    misp-project · mispFeb 20, 2023

  • An issue was discovered in MISP before 2.4.176.

    CriticalCVSS 9.8No exploitEPSS 1%

    misp-project · mispNov 17, 2023

  • An issue was discovered in MISP before 2.4.176.

    CriticalCVSS 9.8No exploitEPSS 1%

    misp-project · mispNov 17, 2023

  • An issue was discovered in MISP before 2.4.176.

    CriticalCVSS 9.8No exploitEPSS 1%

    misp-project · mispNov 17, 2023

  • An issue was discovered in MISP before 2.4.176.

    CriticalCVSS 9.8No exploitEPSS 1%

    misp-project · mispNov 17, 2023

  • An issue was discovered in MISP before 2.4.176.

    CriticalCVSS 9.8No exploitEPSS 1%

    misp-project · mispNov 17, 2023

  • An issue was discovered in MISP before 2.4.184.

    CriticalCVSS 9.8No exploitEPSS 1%

    misp-project · mispFeb 9, 2024

  • In MISP before 2.4.187, add_misp_export in app/Controller/EventsController.php does not properly check for a valid file upload.

    CriticalCVSS 9.8No exploitEPSS 1%

    misp-project · mispMar 21, 2024

  • app/Controller/AuditLogsController.php in MISP before 2.4.182 mishandles ACLs for audit logs.

    CriticalCVSS 9.8No exploitEPSS 1%

    misp-project · mispDec 15, 2023

  • An issue was discovered in MISP before 2.4.184.

    CriticalCVSS 9.8No exploitEPSS 1%

    misp-project · mispFeb 9, 2024

  • In MISP 2.4.167, app/Controller/Component/ACLComponent.php has incorrect access control for the decaying import function.

    CriticalCVSS 9.8No exploitEPSS 1%

    misp-project · mispJan 20, 2023

  • In MISP before 2.4.187, __uploadLogo in app/Controller/OrganisationsController.php does not properly check for a valid logo upload.

    CriticalCVSS 9.8No exploitEPSS 0%

    misp-project · mispMar 21, 2024

  • MISP LDAP and LinOTP Authentication Bypass via Empty or Invalid Credentials

    CriticalCVSS 9.5No exploitEPSS 1%

    misp-project · mispSep 3, 2026

  • MISP: SQL injection via unvalidated ordering parameters in event and shadow attribute listings

    CriticalCVSS 9.3Proof of conceptEPSS 1%

    misp-project · mispMay 13, 2026