CVE Tools

Misp

215 CVEs tracked. None of them is in CISA KEV.

This hub aggregates every CVE we track for Misp, a product in the security products space. Use it to gauge the current risk picture and drill into individual advisories.

Misp CVEs per month

Oct 2024 to Sep 2026. Point at a month, or focus the strip and use the arrow keys.
Misp CVEs per month
MonthCVEs
2024-100
2024-110
2024-120
2025-010
2025-021
2025-033
2025-040
2025-050
2025-060
2025-070
2025-080
2025-090
2025-100
2025-112
2025-121
2026-010
2026-020
2026-030
2026-041
2026-057
2026-0627
2026-074
2026-080
2026-0972

Severity

How the 215 CVEs score on CVSS. Severity is not exploitation: KEV is counted above.

  • Critical2819%
  • High2819%
  • Medium8861%

Latest CVEs

The 15 most recently published vulnerabilities affecting Misp.

  1. CVE-2026-95806MISP: PHP phar stream wrapper enables deserialization and code execution via caller-influenced filesystem paths—
  2. CVE-2026-95805MISP ACLComponent: Typo in previewEventAttributes ACL key bypasses intended access restriction—
  3. CVE-2026-95754MISP: Disabled-user check ineffective in pre-authentication TOTP login branch—
  4. CVE-2026-95703MISP OrganisationsController File Existence and Image-Type Oracle via Forged Upload tmp_name—
  5. CVE-2026-95701MISP Path Traversal via Organization Name in Org-Statistics Logo Check—
  6. CVE-2026-95698MISP Path Traversal in OrgImgHelper findOrgImage via Crafted Organization Name—
  7. CVE-2026-95697MISP: Insufficient Authorization Allows Sharing Group Editors to Overwrite Organization Metadata—
  8. CVE-2026-95693MISP Information Disclosure via Forged Upload Path—
  9. CVE-2026-95685MISP Missing Authorization on replaceSuggestionInReport Event Report Action—
  10. CVE-2026-95683MISP Overmind Event View Discloses Report Content Bypassing Report-Level ACL—
  11. CVE-2026-95682MISP Stored Cross-Site Scripting via Unescaped Organization Name in Admin Email View—
  12. CVE-2026-95679MISP Unauthenticated Blind SSRF via XML Body Processing—
  13. CVE-2026-95674MISP EventsController queryEnrichment allows querying unavailable or legacy modules without validation—
  14. CVE-2026-95671MISP Collections: Missing Authorization Check for Sharing Group on PUT Request in collections/add—
  15. CVE-2026-95667MISP Installer Log and FIFO Created World-Readable, Exposing Sensitive Credentials—

Product grouping is registry-driven, with AI assist and human review. How it works

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store