16 Total CVEs
16 AI Analyzed
0 CISA KEV
5 Critical

Profile

0% ended up actively exploited 0 of 16 added to CISA KEV
31% rated critical (CVSS 9.0+) 5 critical, 11 high
0 with a public exploit on record positive-only index; absence is not proof

Last 12 months

16 CVEs in the last 12 months

Products

  • MISP8
  • cti-transmute4
  • misp-stix2
  • misp-modules1
  • AAD Authentication Plugin1

5 products in total

Every figure counts the high and critical CVEs CVE Brief has published for this vendor, not every CVE the vendor has ever received. Exploitation means listing in the CISA Known Exploited Vulnerabilities catalog. No patch-availability figure is shown because CVE Brief does not measure it.

All Vendors
Showing 1-16 of 16 CVEs
CVE-2026-85546
Analyzed
8.6
MISP MISP

MISP contains a cross-site request forgery (CSRF) vulnerability in the sharing group quick-edit functionality. The addOrg, removeOrg, addServer, and r...

2026-09-05
CVE-2026-85538
Analyzed
8.3
MISP MISP

An incorrect authorization vulnerability in MISP allowed authenticated users to delete attributes from events despite lacking the required perm_modify...

2026-09-05
CVE-2026-85237
Analyzed
8.6
MISP MISP

A vulnerability in MISP's email-based one-time password (OTP) authentication flow allowed an attacker to perform an unrestricted number of OTP verific...

2026-09-04
CVE-2026-85236
Analyzed
8.8
MISP MISP

A cross-site request forgery (CSRF) vulnerability existed in the cullEmptyEvents action of MISP. The endpoint performed a state-changing and irreversi...

2026-09-04
CVE-2026-85216
Analyzed
9.5
MISP MISP

MISP contains an authentication bypass vulnerability in its LDAP and LinOTP components, allowing remote unauthenticated attackers to impersonate users...

2026-09-04
CVE-2026-77755
Analyzed
8.7
MISP misp-stix

A denial-of-service vulnerability was identified in misp-stix when processing attacker-controlled STIX 1 or STIX 2 documents

2026-08-22
CVE-2026-77751
Analyzed
8.8
MISP misp-stix

A path traversal vulnerability existed in the handling of MISP object template names during STIX 2 import and MISP-to-STIX 2 export

2026-08-22
CVE-2026-73160
Analyzed
8.7
MISP cti-transmute

Affected versions of cti-transmute contain an SSRF vulnerability in the /fetch_misp_event and /misp_search_events endpoints

2026-08-12
CVE-2026-69082
Analyzed
8.8
MISP cti-transmute

CTI-Transmute contained a cross-site request forgery vulnerability in the administrative user deletion functionality

2026-08-04
CVE-2026-69079
Analyzed
8.7
MISP cti-transmute

CTI-Transmute contains an uncontrolled resource-consumption vulnerability in the unauthenticated /activity_timeline endpoint

2026-08-04
CVE-2026-69078
Analyzed
8.8
MISP cti-transmute

CTI-Transmute is affected by a server-side request forgery vulnerability in the evaluation report PDF-generation functionality

2026-08-04
CVE-2026-62143
Analyzed
8.3
MISP misp-modules

A Server-Side Request Forgery (SSRF) protection bypass existed in the html_to_markdown expansion module of misp-modules

2026-07-13
CVE-2026-56447
Analyzed
9.3
MISP MISP

An authenticated MISP administrator can trigger arbitrary code execution by providing a malicious configuration file path for the Kafka_rdkafka_config...

2026-06-23
CVE-2026-56425
Analyzed
9.3
MISP AAD Authentication Plugin

The Azure Active Directory (AAD) authentication plugin for MISP contains multiple OAuth 2.0 implementation flaws, including session token leakage and...

2026-06-23
CVE-2026-56423
Analyzed
9.4
MISP MISP

MISP Core contains broken access-control checks in bulk deletion flows for Event Reports and Sharing Groups, allowing unauthorized deletion of data ac...

2026-06-23
CVE-2026-56422
Analyzed
9.4
MISP MISP

MISP core controllers fail to properly validate ownership and primary keys, allowing authenticated users to perform unauthorized data modifications on...

2026-06-23