Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2987▼ 96 respecto a la semana anterior
Críticas / altas1458▲ 101 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
143 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Alta (7.5) | 1.4% | 💥 Exploit | Monospace Directus | 20/8/2025 | 17/6/2026 | Directus is a real-time API and App dashboard for managing SQL database content. From 10.8.0 to before 11.9.3, a vulnerability exists in the file update mechanism which allows an unauthenticated actor to modify existing files with arbitrary contents (without changes being applied to the files' database-resident… | |
| Analizada | Media (5.5) | 0.97% | — | Lemonos | 15/8/2025 | 17/6/2026 | A vulnerability was determined in LemonOS up to nightly-2024-07-12 on LemonOS. Affected by this issue is the function HTTPGet of the file /Applications/Steal/main.cpp of the component HTTP Client. The manipulation of the argument chunkSize leads to stack-based buffer overflow. The attack may be launched remotely. The… | |
| Analizada | Media (6.5) | 0.44% | — | Monospace Directus | 15/7/2025 | 17/6/2026 | Directus is a real-time API and App dashboard for managing SQL database content. Starting in version 9.12.0 and prior to version 11.9.0, Directus Flows with a manual trigger are not validating whether the user triggering the Flow has permissions to the items provided as payload to the Flow. Depending on what the Flow… | |
| Analizada | Media (5.3) | 0.98% | 💥 Exploit | Monospace Directus | 15/7/2025 | 17/6/2026 | Directus is a real-time API and App dashboard for managing SQL database content. Starting in version 9.0.0 and prior to version 11.9.0, the exact Directus version number is incorrectly being used as OpenAPI Spec version this means that it is being exposed by the `/server/specs/oas` endpoint without authentication.… | |
| Analizada | Media (4.5) | 0.43% | — | Monospace Directus | 15/7/2025 | 17/6/2026 | Directus is a real-time API and App dashboard for managing SQL database content. Starting in version 9.0.0 and prior to version 11.9.0, when using Directus Flows with the WebHook trigger all incoming request details are logged including security sensitive data like access and refresh tokens in cookies. Malicious… | |
| Analizada | Media (4.2) | 0.19% | — | Monospace Directus | 15/7/2025 | 17/6/2026 | Directus is a real-time API and App dashboard for managing SQL database content. Starting in version 9.0.0 and prior to version 11.9.0, when using Directus Flows to handle CRUD events for users it is possible to log the incoming data to console using the "Log to Console" operation and a template string. Malicious… | |
| Analizada | Alta (7.5) | 0.52% | — | Monospace Directus | 26/3/2025 | 17/6/2026 | Directus is a real-time API and App dashboard for managing SQL database content. Starting in version 9.12.0 and prior to version 11.5.0, when a Flow with the "Webhook" trigger and the "Data of Last Operation" response body encounters a ValidationError thrown by a failed condition operation, the API response includes… | |
| Analizada | Media (5.3) | 0.37% | — | Monospace Directus | 26/3/2025 | 17/6/2026 | Directus is a real-time API and App dashboard for managing SQL database content. Starting in version 9.0.0-alpha.4 and prior to version 11.5.0, the `search` query parameter allows users with access to a collection to filter items based on fields they do not have permission to view. This allows the enumeration of… | |
| Analizada | Media (4.3) | 0.37% | — | Monospace Directus | 26/3/2025 | 17/6/2026 | Directus is a real-time API and App dashboard for managing SQL database content. Starting in version 10.10.0 and prior to version 11.5.0, a suspended user can use the token generated in session auth mode to access the API despite their status. This happens because there is a check missing in `verifySessionJWT` to… | |
| Analizada | Media (5.3) | 0.43% | — | Monospace Directus | 26/3/2025 | 17/6/2026 | Directus is a real-time API and App dashboard for managing SQL database content. The `@directus/storage-driver-s3` package starting in version 9.22.0 and prior to version 12.0.1, corresponding to Directus starting in version 9.22.0 and prior to 11.5.0, is vulnerable to asset unavailability after a burst of HEAD… | |
| Analizada | Media (5.3) | 0.43% | — | Monospace Directus | 26/3/2025 | 17/6/2026 | Directus is a real-time API and App dashboard for managing SQL database content. The `@directus/storage-driver-s3` package starting in version 9.22.0 and prior to version 12.0.1, corresponding to Directus starting in version 9.22.0 and prior to 11.5.0, is vulnerable to asset unavailability after a burst of malformed… | |
| Analizada | Media (4.3) | 0.24% | — | Monospace Directus | 19/2/2025 | 17/6/2026 | Directus is a real-time API and App dashboard for managing SQL database content. In affected versions if there are two overlapping policies for the `update` action that allow access to different fields, instead of correctly checking access permissions against the item they apply for the user is allowed to update the… | |
| Analizada | Media (4.3) | 0.39% | — | Monospace Directus | 23/1/2025 | 17/6/2026 | Directus is a real-time API and App dashboard for managing SQL database content. Prior to version 11.2.0, when sharing an item, a typical user can specify an arbitrary role. It allows the user to use a higher-privileged role to see fields that otherwise the user should not be able to see. Instances that are impacted… | |
| Analizada | Alta (7.5) | 0.60% | — | Monospace Directus | 9/12/2024 | 17/6/2026 | Directus is a real-time API and App dashboard for managing SQL database content. Starting in version 11.0.0 and prior to version 11.3.0, when setting `WEBSOCKETS_GRAPHQL_AUTH` or `WEBSOCKETS_REST_AUTH` to "public", an unauthenticated user is able to do any of the supported operations (CRUD, subscriptions) with full… | |
| Analizada | Media (4.6) | 0.34% | — | Monospace Directus | 5/12/2024 | 17/6/2026 | Directus is a real-time API and App dashboard for managing SQL database content. The Comment feature has implemented a filter to prevent users from adding restricted characters, such as HTML tags. However, this filter operates on the client-side, which can be bypassed, making the application vulnerable to HTML… | |
| Analizada | Media (5.3) | 0.39% | — | Monocms | 6/11/2024 | 17/6/2026 | A vulnerability was found in MonoCMS up to 20240528. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the file /monofiles/opensaved.php of the component Posts Page. The manipulation of the argument filtcategory/filtstatus leads to cross site scripting. The attack can… | |
| Analizada | Media (5.3) | 0.42% | — | Monocms | 6/11/2024 | 17/6/2026 | A vulnerability was found in MonoCMS up to 20240528. It has been classified as problematic. Affected is an unknown function of the file /monofiles/account.php of the component Account Information Page. The manipulation of the argument userid leads to cross site scripting. It is possible to launch the attack remotely.… | |
| Modificada | Media (4.2) | 0.31% | — | Monospace Directus | 8/10/2024 | 17/6/2026 | Directus is a real-time API and App dashboard for managing SQL database content. Access tokens from query strings are not redacted and are potentially exposed in system logs which may be persisted. The access token in `req.query` is not redacted when the `LOG_STYLE` is set to `raw`. If these logs are not properly… | |
| Analizada | Media (5) | 0.47% | — | Monospace Directus | 18/9/2024 | 17/6/2026 | Directus is a real-time API and App dashboard for managing SQL database content. When relying on blocking access to localhost using the default `0.0.0.0` filter a user may bypass this block by using other registered loopback devices (like `127.0.0.2` - `127.127.127.127`). This issue has been addressed in release… | |
| Analizada | Media (6.5) | 0.66% | — | Monospace Directus | 10/9/2024 | 17/6/2026 | Directus is a real-time API and App dashboard for managing SQL database content. An unauthenticated user can access credentials of last authenticated user via OpenID or OAuth2 where the authentication URL did not include redirect query string. This happens because on that endpoint for both OpenId and Oauth2 Directus… | |
| Modificada | Media (4.3) | 0.33% | — | Monospace Directus | 15/8/2024 | 17/6/2026 | Directus v10.13.0 allows an authenticated external attacker to modify presets created by the same user to assign them to another user. This is possible because the application only validates the user parameter in the 'POST /presets' request but not in the PATCH request. When chained with CVE-2024-6533, it could result… | |
| Modificada | Media (5.4) | 0.38% | — | Monospace Directus | 15/8/2024 | 17/6/2026 | Directus v10.13.0 allows an authenticated external attacker to execute arbitrary JavaScript on the client. This is possible because the application injects an attacker-controlled parameter that will be stored in the server and used by the client into an unsanitized DOM element. When chained with CVE-2024-6534, it… | |
| Analizada | Media (5.3) | 0.51% | — | Monospace Directus | 8/7/2024 | 17/6/2026 | Directus is a real-time API and App dashboard for managing SQL database content. When relying on SSO providers in combination with local authentication it can be possible to enumerate existing SSO users in the instance. This is possible because if an email address exists in Directus and belongs to a known SSO provider… | |
| Analizada | Media (6.5) | 0.80% | — | Monospace Directus | 8/7/2024 | 17/6/2026 | Directus is a real-time API and App dashboard for managing SQL database content. A denial of service (DoS) attack by field duplication in GraphQL is a type of attack where an attacker exploits the flexibility of GraphQL to overwhelm a server by requesting the same field multiple times in a single query. This can cause… | |
| Analizada | Alta (7.7) | 0.42% | — | Monospace Directus | 8/7/2024 | 17/6/2026 | Directus is a real-time API and App dashboard for managing SQL database content. Directus >=9.23.0, <=v10.5.3 improperly handles _in, _nin operators. It evaluates empty arrays as valid so expressions like {"role": {"_in": $CURRENT_USER.some_field}} would evaluate to true allowing the request to pass. This results in… |