361,800
Total CVEs
26,223
Critical
85,816
High
1,626
CISA KEV
88
This Week
195 results · Page 4/8
In MISP 2.4.167, app/webroot/js/action_table.js allows XSS via a network history name.
misp
In MISP 2.4.167, app/webroot/js/event-graph.js has an XSS vulnerability via an event-graph preview payload.
misp-project
In MISP before 2.4.167, there is XSS in the template file uploads in app/View/Templates/upload_file.ctp.
misp-project
Due to lack of proper memory management, when a victim opens a manipulated Right Hemisphere Binary (.rh, rh.x3d) file received from untrusted sources in SAP 3D Visual Enterprise Viewer - version 9, it is possible that a Remote Code Execution can be triggered when payload forces a stack-based overflow or a re-use of dangling pointer which refers to overwritten space in memory.
sap