Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2726▼ 82 respecto a la semana anterior
Críticas / altas1416▲ 189 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)100▼ 400 respecto a la semana anterior
75 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (7.5) | 0.42% | — | DirectusAIPostgresqlAIPostgisAI | 5/8/2026 | 28/8/2026 | Directus contains an authenticated SQL injection vulnerability in the collection creation flow when the instance uses PostgreSQL with PostGIS enabled. An administrator can create a collection with a geometry field whose fields[].type value starts with geometry but contains attacker-controlled SQL syntax after the… | |
| Analizada | Alta (8.6) | 0.47% | — | Monospace Directus | 15/7/2026 | 28/7/2026 | Directus is a real-time API and App dashboard for managing SQL database content. Prior to 12.0.0, when response caching is enabled, the cache-key derivation in api/src/utils/get-cache-key.ts includes version, path, query, and accountability.user but omits authorization context such as share, role, roles, admin, app,… | |
| Analizada | Alta (7.7) | 0.41% | — | Monospace Directus | 15/7/2026 | 28/7/2026 | Directus is a real-time API and App dashboard for managing SQL database content. Prior to 12.0.0, the SSRF protection on Directus's file-import-from-URL feature can be bypassed using the address 0.0.0.0 because api/src/request/is-denied-ip.ts treats 0.0.0.0 as a keyword for local interfaces but never blocks the… | |
| Aplazada | Baja (2.1) | 0.37% | — | Pixelsock Directus-mcpAI | 4/5/2026 | 17/6/2026 | A security flaw has been discovered in pixelsock directus-mcp 1.0.0. This issue affects the function validateUrl of the file index.ts of the component MCP Interface. Performing a manipulation of the argument fileUrl results in server-side request forgery. The attack may be initiated remotely. The exploit has been… | |
| Analizada | Media (6.5) | 0.27% | — | Monospace Directus | 9/4/2026 | 17/6/2026 | Directus is a real-time API and App dashboard for managing SQL database content. Prior to 11.17.0, Directus stores revision records (in directus_revisions) whenever items are created or updated. Due to the revision snapshot code not consistently calling the prepareDelta sanitization pipeline, sensitive fields… | |
| Analizada | Alta (8.8) | 0.36% | — | Monospace Directus | 9/4/2026 | 17/6/2026 | Directus is a real-time API and App dashboard for managing SQL database content. Prior to 11.17.0, the PATCH /files/{id} endpoint accepts a user-controlled filename_disk parameter. By setting this value to match the storage path of another user's file, an attacker can overwrite that file's content while manipulating… | |
| Analizada | Alta (8.1) | 0.43% | — | Monospace Directus | 6/4/2026 | 24/7/2026 | Directus is a real-time API and App dashboard for managing SQL database content. Prior to 11.17.0, aggregate functions (min, max) applied to fields with the conceal special type incorrectly return raw database values instead of the masked placeholder. When combined with groupBy, any authenticated user with read access… | |
| Analizada | Media (6.5) | 0.42% | — | Monospace Directus | 6/4/2026 | 24/7/2026 | Directus is a real-time API and App dashboard for managing SQL database content. Prior to 11.17.0, Directus' GraphQL endpoints (/graphql and /graphql/system) did not deduplicate resolver invocations within a single request. An authenticated user could exploit GraphQL aliasing to repeat an expensive relational query… | |
| Analizada | Media (5.3) | 0.36% | — | Monospace Directus | 6/4/2026 | 24/7/2026 | Directus is a real-time API and App dashboard for managing SQL database content. Prior to 11.16.1, when GRAPHQL_INTROSPECTION=false is configured, Directus correctly blocks standard GraphQL introspection queries (__schema, __type). However, the server_specs_graphql resolver on the /graphql/system endpoint returns an… | |
| Analizada | Alta (8.1) | 0.39% | — | Monospace Directus | 6/4/2026 | 24/7/2026 | Directus is a real-time API and App dashboard for managing SQL database content. Prior to 11.16.1, Directus' TUS resumable upload endpoint (/files/tus) allows any authenticated user with basic file upload permissions to overwrite arbitrary existing files by UUID. The TUS controller performs only collection-level… | |
| Analizada | Media (4.3) | 0.33% | — | Monospace Directus | 6/4/2026 | 24/7/2026 | Directus is a real-time API and App dashboard for managing SQL database content. Prior to 11.16.1, Directus is vulnerable to an open redirect via the redirect query parameter on the /admin/tfa-setup page. When an administrator who has not yet configured Two-Factor Authentication (2FA) visits a crafted URL, they are… | |
| Analizada | Media (6.1) | 0.32% | — | Monospace Directus | 6/4/2026 | 24/7/2026 | Directus is a real-time API and App dashboard for managing SQL database content. Prior to 11.16.1, an open redirect vulnerability exists in the login redirection logic. The isLoginRedirectAllowed function fails to correctly identify certain malformed URLs as external, allowing attackers to bypass redirect allow-list… | |
| Analizada | Alta (7.7) | 0.38% | — | Monospace Directus | 6/4/2026 | 24/7/2026 | Directus is a real-time API and App dashboard for managing SQL database content. Prior to 11.16.0, a Server-Side Request Forgery (SSRF) protection bypass has been identified and fixed in Directus. The IP address validation mechanism used to block requests to local and private networks could be circumvented using… | |
| Analizada | Crítica (9.3) | 0.19% | — | Monospace Directus | 6/4/2026 | 24/7/2026 | Directus is a real-time API and App dashboard for managing SQL database content. Prior to 11.17.0, Directus's Single Sign-On (SSO) login pages lacked a Cross-Origin-Opener-Policy (COOP) HTTP response header. Without this header, a malicious cross-origin window that opens the Directus login page retains the ability to… | |
| Analizada | Media (5.3) | 0.43% | — | Monospace Directus | 12/2/2026 | 17/6/2026 | Directus is a real-time API and App dashboard for managing SQL database content. Before 11.14.1, a timing-based user enumeration vulnerability exists in the password reset functionality. When an invalid reset_url parameter is provided, the response time differs by approximately 500ms between existing and non-existing… | |
| Analizada | Media (6.1) | 0.23% | — | Monospace Directus | 8/1/2026 | 17/6/2026 | Directus is a real-time API and App dashboard for managing SQL database content. Prior to version 11.14.0, an open redirect vulnerability exists in the Directus SAML authentication callback endpoint. During SAML authentication, the `RelayState` parameter is intended to preserve the user's original destination.… | |
| Analizada | Media (4.3) | 0.33% | — | Monospace Directus | 13/11/2025 | 17/6/2026 | Directus is a real-time API and App dashboard for managing SQL database content. An observable difference in error messaging was found in the Directus REST API in versions of Directus prior to version 11.13.0. The `/items/{collection}` API returns different error messages for two cases: when a user tries to access an… | |
| Analizada | Media (6.5) | 0.28% | — | Monospace Directus | 13/11/2025 | 17/6/2026 | Directus is a real-time API and App dashboard for managing SQL database content. A vulnerability in versions prior to 11.13.0 allows authenticated users to search concealed/sensitive fields when they have read permissions. While actual values remain masked (`****`), successful matches can be detected through returned… | |
| Analizada | Media (5.5) | 0.25% | — | Monospace Directus | 13/11/2025 | 17/6/2026 | Directus is a real-time API and App dashboard for managing SQL database content. A stored cross-site scripting (XSS) vulnerability exists in versions prior to 11.13.0 that allows users with `upload files` and `edit item` permissions to inject malicious JavaScript through the Block Editor interface. Attackers can… | |
| Analizada | Media (5.4) | 0.19% | — | Monospace Directus | 13/11/2025 | 17/6/2026 | Directus is a real-time API and App dashboard for managing SQL database content. Prior to version 11.13.0, Directus does not properly clean up field-level permissions when a field is deleted. When a field is removed from a collection, its reference in the permissions table remains intact. This stale reference creates… | |
| Analizada | Alta (7.5) | 1.3% | — | Monospace Directus | 20/8/2025 | 17/6/2026 | Directus is a real-time API and App dashboard for managing SQL database content. From 10.8.0 to before 11.9.3, a vulnerability exists in the file update mechanism which allows an unauthenticated actor to modify existing files with arbitrary contents (without changes being applied to the files' database-resident… | |
| Analizada | Media (6.5) | 0.41% | — | Monospace Directus | 15/7/2025 | 17/6/2026 | Directus is a real-time API and App dashboard for managing SQL database content. Starting in version 9.12.0 and prior to version 11.9.0, Directus Flows with a manual trigger are not validating whether the user triggering the Flow has permissions to the items provided as payload to the Flow. Depending on what the Flow… | |
| Analizada | Media (5.3) | 0.92% | — | Monospace Directus | 15/7/2025 | 17/6/2026 | Directus is a real-time API and App dashboard for managing SQL database content. Starting in version 9.0.0 and prior to version 11.9.0, the exact Directus version number is incorrectly being used as OpenAPI Spec version this means that it is being exposed by the `/server/specs/oas` endpoint without authentication.… | |
| Analizada | Media (4.5) | 0.40% | — | Monospace Directus | 15/7/2025 | 17/6/2026 | Directus is a real-time API and App dashboard for managing SQL database content. Starting in version 9.0.0 and prior to version 11.9.0, when using Directus Flows with the WebHook trigger all incoming request details are logged including security sensitive data like access and refresh tokens in cookies. Malicious… | |
| Analizada | Media (4.2) | 0.18% | — | Monospace Directus | 15/7/2025 | 17/6/2026 | Directus is a real-time API and App dashboard for managing SQL database content. Starting in version 9.0.0 and prior to version 11.9.0, when using Directus Flows to handle CRUD events for users it is possible to log the incoming data to console using the "Log to Console" operation and a template string. Malicious… |