İçeriğe atla
Noroxi

misp-project kayıtları

misp-project üreticisine ait 141 yayımlanmış kayıt.

Araştırmacı profili

KEV’e giren
0 · %0
Silahlaştırılmış
0 · %0
Pre-auth RCE
1
Düzeltme kaydı olan
%7,1
Yayından KEV’e ortanca
KEV’e giren kayıt yok

Tüm kayıtlar

141 kayıt
  • CVE-2018-19908
    40Planlayın

    An issue was discovered in MISP 2.4.9x before 2.4.99.

    YüksekCVSS 8,8Kavram kanıtıEPSS %17

    misp-project · misp6 Ara 2018

  • CVE-2015-5721
    40Planlayın

    Malware Information Sharing Platform (MISP) before 2.3.90 allows remote attackers to conduct PHP object injection attacks via crafted serial

    KritikCVSS 9,8İstismar yokEPSS %3

    misp-project · misp3 Eyl 2016

  • CVE-2015-5719
    40Planlayın

    app/Controller/TemplatesController.php in Malware Information Sharing Platform (MISP) before 2.3.92 does not properly restrict filenames und

    KritikCVSS 9,8İstismar yokEPSS %2

    misp-project · misp3 Eyl 2016

  • CVE-2022-29528
    40Planlayın

    An issue was discovered in MISP before 2.4.158.

    KritikCVSS 9,8İstismar yokEPSS %2

    misp-project · misp20 Nis 2022

  • CVE-2021-41326
    40Planlayın

    In MISP before 2.4.148, app/Lib/Export/OpendataExport.php mishandles parameter data that is used in a shell_exec call.

    KritikCVSS 9,8İstismar yokEPSS %2

    misp-project · misp17 Eyl 2021

  • CVE-2018-12649
    39İzleyin

    An issue was discovered in app/Controller/UsersController.php in MISP 2.4.92.

    KritikCVSS 9,8İstismar yokEPSS %1

    misp-project · misp22 Haz 2018

  • CVE-2020-15411
    39İzleyin

    An issue was discovered in MISP 2.4.128.

    KritikCVSS 9,8İstismar yokEPSS %1

    misp-project · misp30 Haz 2020

  • CVE-2022-48328
    39İzleyin

    app/Controller/Component/IndexFilterComponent.php in MISP before 2.4.167 mishandles ordered_url_params and additional_delimiters.

    KritikCVSS 9,8İstismar yokEPSS %1

    misp-project · misp20 Şub 2023

  • CVE-2020-29006
    39İzleyin

    MISP before 2.4.135 lacks an ACL check, related to app/Controller/GalaxyElementsController.php and app/Model/GalaxyElement.php.

    KritikCVSS 9,8İstismar yokEPSS %1

    misp-project · misp24 Kas 2020

  • CVE-2021-35502
    39İzleyin

    app/View/Elements/genericElements/IndexTable/Fields/generic_field.ctp in MISP 2.4.144 does not sanitize certain data related to generic-temp

    KritikCVSS 9,8İstismar yokEPSS %1

    misp-project · misp25 Haz 2021

  • CVE-2021-39302
    39İzleyin

    MISP 2.4.148, in certain configurations, allows SQL injection via the app/Model/Log.php $conditions['org'] value.

    KritikCVSS 9,8İstismar yokEPSS %1

    misp-project · misp19 Ağu 2021

  • CVE-2022-48329
    39İzleyin

    MISP before 2.4.166 unsafely allows users to use the order parameter, related to app/Model/Attribute.php, app/Model/GalaxyCluster.php, app/M

    KritikCVSS 9,8İstismar yokEPSS %1

    misp-project · misp20 Şub 2023

  • CVE-2023-48655
    39İzleyin

    An issue was discovered in MISP before 2.4.176.

    KritikCVSS 9,8İstismar yokEPSS %1

    misp-project · misp17 Kas 2023

  • CVE-2023-48657
    39İzleyin

    An issue was discovered in MISP before 2.4.176.

    KritikCVSS 9,8İstismar yokEPSS %1

    misp-project · misp17 Kas 2023

  • CVE-2023-48656
    39İzleyin

    An issue was discovered in MISP before 2.4.176.

    KritikCVSS 9,8İstismar yokEPSS %1

    misp-project · misp17 Kas 2023

  • CVE-2023-48658
    39İzleyin

    An issue was discovered in MISP before 2.4.176.

    KritikCVSS 9,8İstismar yokEPSS %1

    misp-project · misp17 Kas 2023

  • CVE-2023-48659
    39İzleyin

    An issue was discovered in MISP before 2.4.176.

    KritikCVSS 9,8İstismar yokEPSS %1

    misp-project · misp17 Kas 2023

  • CVE-2024-25675
    39İzleyin

    An issue was discovered in MISP before 2.4.184.

    KritikCVSS 9,8İstismar yokEPSS %1

    misp-project · misp9 Şub 2024

  • CVE-2024-29859
    39İzleyin

    In MISP before 2.4.187, add_misp_export in app/Controller/EventsController.php does not properly check for a valid file upload.

    KritikCVSS 9,8İstismar yokEPSS %1

    misp-project · misp21 Mar 2024

  • CVE-2023-50918
    39İzleyin

    app/Controller/AuditLogsController.php in MISP before 2.4.182 mishandles ACLs for audit logs.

    KritikCVSS 9,8İstismar yokEPSS %1

    misp-project · misp15 Ara 2023

  • CVE-2024-25674
    39İzleyin

    An issue was discovered in MISP before 2.4.184.

    KritikCVSS 9,8İstismar yokEPSS %1

    misp-project · misp9 Şub 2024

  • CVE-2023-24028
    39İzleyin

    In MISP 2.4.167, app/Controller/Component/ACLComponent.php has incorrect access control for the decaying import function.

    KritikCVSS 9,8İstismar yokEPSS %1

    misp-project · misp20 Oca 2023

  • CVE-2024-29858
    39İzleyin

    In MISP before 2.4.187, __uploadLogo in app/Controller/OrganisationsController.php does not properly check for a valid logo upload.

    KritikCVSS 9,8İstismar yokEPSS %0

    misp-project · misp21 Mar 2024

  • CVE-2026-85216
    38İzleyin

    MISP LDAP and LinOTP Authentication Bypass via Empty or Invalid Credentials

    KritikCVSS 9,5İstismar yokEPSS %1

    misp-project · misp3 Eyl 2026

  • CVE-2026-44381
    37İzleyin

    MISP: SQL injection via unvalidated ordering parameters in event and shadow attribute listings

    KritikCVSS 9,3Kavram kanıtıEPSS %1

    misp-project · misp13 May 2026