Misp
This hub aggregates every CVE we track for Misp, a product in the security products space. Use it to gauge the current risk picture and drill into individual advisories.
215
CVEs tracked
28
Critical
28
High
0
In CISA KEV
Severity distribution
MEDIUM88HIGH28CRITICAL28
Monthly trend
0
0
0
0
1
3
0
0
0
0
0
0
0
2
1
0
0
0
1
7
27
4
0
72
2024-102026-09
Latest CVEs
The 15 most recently published vulnerabilities affecting Misp.
- CVE-2026-95806MISP: PHP phar stream wrapper enables deserialization and code execution via caller-influenced filesystem paths
- CVE-2026-95805MISP ACLComponent: Typo in previewEventAttributes ACL key bypasses intended access restriction
- CVE-2026-95754MISP: Disabled-user check ineffective in pre-authentication TOTP login branch
- CVE-2026-95703MISP OrganisationsController File Existence and Image-Type Oracle via Forged Upload tmp_name
- CVE-2026-95701MISP Path Traversal via Organization Name in Org-Statistics Logo Check
- CVE-2026-95698MISP Path Traversal in OrgImgHelper findOrgImage via Crafted Organization Name
- CVE-2026-95697MISP: Insufficient Authorization Allows Sharing Group Editors to Overwrite Organization Metadata
- CVE-2026-95693MISP Information Disclosure via Forged Upload Path
- CVE-2026-95685MISP Missing Authorization on replaceSuggestionInReport Event Report Action
- CVE-2026-95683MISP Overmind Event View Discloses Report Content Bypassing Report-Level ACL
- CVE-2026-95682MISP Stored Cross-Site Scripting via Unescaped Organization Name in Admin Email View
- CVE-2026-95679MISP Unauthenticated Blind SSRF via XML Body Processing
- CVE-2026-95674MISP EventsController queryEnrichment allows querying unavailable or legacy modules without validation
- CVE-2026-95671MISP Collections: Missing Authorization Check for Sharing Group on PUT Request in collections/add
- CVE-2026-95667MISP Installer Log and FIFO Created World-Readable, Exposing Sensitive Credentials
Product normalization is registry-driven with AI assist and human review. How it works