Vulnerabilities
Aggregated CVE / GHSA / KEV / OSV — filter by tag and category.
| ID | Title | |
|---|---|---|
| CVE-2022-42724 |
|
Information Disclosure in misp-project (CVE-2022-42724)
vulnerability in misp-project (CVE-2022-42724). Risk of unauthorized operations or information disclosure.
|
| CVE-2019-12868 |
|
Unsafe Deserialization in deserialization (CVE-2019-12868)
vulnerability in deserialization (CVE-2019-12868). Successful exploitation can lead to full system takeover.
|
| CVE-2021-41326 |
|
Vulnerability in misp-project (CVE-2021-41326)
vulnerability in misp-project (CVE-2021-41326). Successful exploitation can lead to full system takeover.
|
| CVE-2021-39302 |
|
SQL Injection in sqli (CVE-2021-39302)
SQL injection in sqli (CVE-2021-39302). Successful exploitation can lead to full system takeover.
|
| CVE-2021-37743 |
|
Cross-Site Scripting (XSS) in misp-project (CVE-2021-37743)
cross-site scripting in misp-project (CVE-2021-37743). Risk of unauthorized operations or information disclosure.
|
| CVE-2021-37742 |
|
Cross-Site Scripting (XSS) in misp-project (CVE-2021-37742)
cross-site scripting in misp-project (CVE-2021-37742). Risk of unauthorized operations or information disclosure.
|
| CVE-2021-37534 |
|
app/View/GalaxyClusters/add.ctp in MISP 2.4.146 allows Stored XSS when forking a galaxy cluster.
app/View/GalaxyClusters/add.ctp in MISP 2.4.146 allows Stored XSS when forking a galaxy cluster.
|
| CVE-2021-36212 |
|
Cross-Site Scripting (XSS) in misp-project (CVE-2021-36212)
cross-site scripting in misp-project (CVE-2021-36212). Risk of unauthorized operations or information disclosure.
|
| CVE-2021-35502 |
|
Vulnerability in misp-project (CVE-2021-35502)
vulnerability in misp-project (CVE-2021-35502). Successful exploitation can lead to full system takeover.
|
| CVE-2021-31780 |
|
Vulnerability in misp-project (CVE-2021-31780)
vulnerability in misp-project (CVE-2021-31780). Confidential information can be exposed externally.
|
| CVE-2021-27904 |
|
Vulnerability in misp-project (CVE-2021-27904)
vulnerability in misp-project (CVE-2021-27904). Confidential information can be exposed externally.
|
| CVE-2020-24085 |
|
Cross-Site Scripting (XSS) in misp-project (CVE-2020-24085)
cross-site scripting in misp-project (CVE-2020-24085). Risk of unauthorized operations or information disclosure.
|
| CVE-2021-3184 |
|
Cross-Site Scripting (XSS) in misp-project (CVE-2021-3184)
cross-site scripting in misp-project (CVE-2021-3184). Risk of unauthorized operations or information disclosure.
|
| CVE-2021-25325 |
|
Cross-Site Scripting (XSS) in misp-project (CVE-2021-25325)
cross-site scripting in misp-project (CVE-2021-25325). Risk of unauthorized operations or information disclosure.
|
| CVE-2021-25324 |
|
Cross-Site Scripting (XSS) in misp-project (CVE-2021-25324)
cross-site scripting in misp-project (CVE-2021-25324). Risk of unauthorized operations or information disclosure.
|
| CVE-2020-29572 |
|
Cross-Site Scripting (XSS) in misp-project (CVE-2020-29572)
cross-site scripting in misp-project (CVE-2020-29572). Risk of unauthorized operations or information disclosure.
|
| CVE-2020-29006 |
|
Vulnerability in misp-project (CVE-2020-29006)
vulnerability in misp-project (CVE-2020-29006). Successful exploitation can lead to full system takeover.
|
| CVE-2020-28947 |
|
Cross-Site Scripting (XSS) in misp-project (CVE-2020-28947)
cross-site scripting in misp-project (CVE-2020-28947). Risk of unauthorized operations or information disclosure.
|
| CVE-2020-28043 |
|
SSRF (Server-Side Request Forgery) in ssrf (CVE-2020-28043)
SSRF in ssrf (CVE-2020-28043). Confidential information can be exposed externally.
|
| CVE-2020-25766 |
|
Vulnerability in misp-project (CVE-2020-25766)
vulnerability in misp-project (CVE-2020-25766). Data can be tampered with by attackers.
|
| CVE-2020-15711 |
|
In MISP before 2.4.129, setting a favourite homepage was not CSRF protected.
In MISP before 2.4.129, setting a favourite homepage was not CSRF protected.
|
| CVE-2020-15412 |
|
Vulnerability in misp-project (CVE-2020-15412)
vulnerability in misp-project (CVE-2020-15412). Risk of unauthorized operations or information disclosure.
|
| CVE-2020-15411 |
|
Privilege Escalation in misp-project (CVE-2020-15411)
vulnerability in misp-project (CVE-2020-15411). Successful exploitation can lead to full system takeover.
|
| CVE-2020-14969 |
|
Vulnerability in misp-project (CVE-2020-14969)
vulnerability in misp-project (CVE-2020-14969). Confidential information can be exposed externally.
|
| CVE-2020-13153 |
|
Cross-Site Scripting (XSS) in misp-project (CVE-2020-13153)
cross-site scripting in misp-project (CVE-2020-13153). Risk of unauthorized operations or information disclosure.
|
| CVE-2020-11458 |
|
Information Disclosure in misp-project (CVE-2020-11458)
vulnerability in misp-project (CVE-2020-11458). Confidential information can be exposed externally.
|
| CVE-2020-8893 |
|
Vulnerability in misp-project (CVE-2020-8893)
vulnerability in misp-project (CVE-2020-8893). Data can be tampered with by attackers.
|
| CVE-2020-8894 |
|
Vulnerability in misp-project (CVE-2020-8894)
vulnerability in misp-project (CVE-2020-8894). Risk of unauthorized operations or information disclosure.
|
| CVE-2020-8891 |
|
Vulnerability in misp-project (CVE-2020-8891)
vulnerability in misp-project (CVE-2020-8891). Data can be tampered with by attackers.
|
| CVE-2020-8890 |
|
Vulnerability in misp-project (CVE-2020-8890)
vulnerability in misp-project (CVE-2020-8890). Data can be tampered with by attackers.
|
| CVE-2020-8892 |
|
Vulnerability in misp-project (CVE-2020-8892)
vulnerability in misp-project (CVE-2020-8892). Successful exploitation can lead to full system takeover.
|
| CVE-2019-19379 |
|
Vulnerability in misp-project (CVE-2019-19379)
vulnerability in misp-project (CVE-2019-19379). Risk of unauthorized operations or information disclosure.
|
| CVE-2019-12794 |
|
Privilege Escalation in misp-project (CVE-2019-12794)
vulnerability in misp-project (CVE-2019-12794). Successful exploitation can lead to full system takeover.
|
| CVE-2019-11814 |
|
Cross-Site Scripting (XSS) in misp-project (CVE-2019-11814)
cross-site scripting in misp-project (CVE-2019-11814). Risk of unauthorized operations or information disclosure.
|
| CVE-2019-11813 |
|
Cross-Site Scripting (XSS) in misp-project (CVE-2019-11813)
cross-site scripting in misp-project (CVE-2019-11813). Risk of unauthorized operations or information disclosure.
|
| CVE-2019-11812 |
|
Cross-Site Scripting (XSS) in misp-project (CVE-2019-11812)
cross-site scripting in misp-project (CVE-2019-11812). Risk of unauthorized operations or information disclosure.
|
| CVE-2018-19908 |
|
OS Command Injection in misp-project (CVE-2018-19908)
OS command injection in misp-project (CVE-2018-19908). Successful exploitation can lead to full system takeover.
|
| CVE-2022-29529 |
|
An issue was discovered in MISP before 2.4.158. There is stored XSS via the LinOTP login field.
An issue was discovered in MISP before 2.4.158. There is stored XSS via the LinOTP login field.
|
| CVE-2022-29530 |
|
An issue was discovered in MISP before 2.4.158. There is stored XSS in the galaxy clusters.
An issue was discovered in MISP before 2.4.158. There is stored XSS in the galaxy clusters.
|
| CVE-2022-29533 |
|
Cross-Site Scripting (XSS) in misp-project (CVE-2022-29533)
cross-site scripting in misp-project (CVE-2022-29533). Risk of unauthorized operations or information disclosure.
|
| CVE-2022-29528 |
|
An issue was discovered in MISP before 2.4.158. PHAR deserialization can occur.
An issue was discovered in MISP before 2.4.158. PHAR deserialization can occur.
|
| CVE-2022-29532 |
|
Cross-Site Scripting (XSS) in misp-project (CVE-2022-29532)
cross-site scripting in misp-project (CVE-2022-29532). Risk of unauthorized operations or information disclosure.
|
| CVE-2022-29531 |
|
Cross-Site Scripting (XSS) in misp-project (CVE-2022-29531)
cross-site scripting in misp-project (CVE-2022-29531). Risk of unauthorized operations or information disclosure.
|
| CVE-2022-29534 |
|
Authentication Bypass in misp-project (CVE-2022-29534)
authentication bypass in misp-project (CVE-2022-29534). Data can be tampered with by attackers.
|
| CVE-2022-27243 |
|
Vulnerability in misp-project (CVE-2022-27243)
vulnerability in misp-project (CVE-2022-27243). Successful exploitation can lead to full system takeover.
|
| CVE-2022-27244 |
|
Cross-Site Scripting (XSS) in misp-project (CVE-2022-27244)
cross-site scripting in misp-project (CVE-2022-27244). Risk of unauthorized operations or information disclosure.
|
| CVE-2022-27245 |
|
SSRF (Server-Side Request Forgery) in ssrf (CVE-2022-27245)
SSRF in ssrf (CVE-2022-27245). Successful exploitation can lead to full system takeover.
|
| CVE-2022-27246 |
|
Cross-Site Scripting (XSS) in misp-project (CVE-2022-27246)
cross-site scripting in misp-project (CVE-2022-27246). Risk of unauthorized operations or information disclosure.
|
| CVE-2021-25323 |
|
Vulnerability in misp-project (CVE-2021-25323)
vulnerability in misp-project (CVE-2021-25323). Confidential information can be exposed externally.
|
| CVE-2020-10246 |
|
Cross-Site Scripting (XSS) in misp-project (CVE-2020-10246)
cross-site scripting in misp-project (CVE-2020-10246). Risk of unauthorized operations or information disclosure.
|