Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3081▲ 625 respecto a la semana anterior
Críticas / altas1483▲ 317 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)393▲ 186 respecto a la semana anterior
143 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (5.1) | 0.18% | — | PymonocypherAI | 3/9/2026 | 9/9/2026 | pymonocypher uses cython to wrap the Monocypher C library. Prior to version 4.0.2.8, the argon2i_32 implementation does not check the nb_blocks size. If the caller does not provide a sufficiently large buffer based on the API contract, then argon2i_32 will write past the end of the buffer and possibly corrupt the… | |
| Aplazada | Baja (2.1) | 0.50% | — | Monomythdevelopment La-forge-mcpAI | 6/8/2026 | 12/8/2026 | A security vulnerability has been detected in MonomythDevelopment la-forge-mcp 1.0.0. This issue affects the function screenshotElement of the file src/index.ts of the component screenshot_element Tool. Such manipulation of the argument output_name leads to path traversal. The attack can be executed remotely.… | |
| Analizada | Alta (8.6) | 0.47% | — | Monospace Directus | 15/7/2026 | 28/7/2026 | Directus is a real-time API and App dashboard for managing SQL database content. Prior to 12.0.0, when response caching is enabled, the cache-key derivation in api/src/utils/get-cache-key.ts includes version, path, query, and accountability.user but omits authorization context such as share, role, roles, admin, app,… | |
| Analizada | Alta (7.7) | 0.41% | — | Monospace Directus | 15/7/2026 | 28/7/2026 | Directus is a real-time API and App dashboard for managing SQL database content. Prior to 12.0.0, the SSRF protection on Directus's file-import-from-URL feature can be bypassed using the address 0.0.0.0 because api/src/request/is-denied-ip.ts treats 0.0.0.0 as a keyword for local interfaces but never blocks the… | |
| Aplazada | Alta (8.7) | 0.28% | — | Memono NotepadAI | 10/5/2026 | 25/7/2026 | memono Notepad 4.2 contains a denial of service vulnerability that allows attackers to crash the application by pasting excessively long character buffers into note fields. Attackers can generate a payload containing 350000 repeated characters and paste it twice into a new note to trigger an application crash on iOS… | |
| Analizada | Media (6.5) | 0.27% | — | Monospace Directus | 9/4/2026 | 17/6/2026 | Directus is a real-time API and App dashboard for managing SQL database content. Prior to 11.17.0, Directus stores revision records (in directus_revisions) whenever items are created or updated. Due to the revision snapshot code not consistently calling the prepareDelta sanitization pipeline, sensitive fields… | |
| Analizada | Alta (8.8) | 0.36% | — | Monospace Directus | 9/4/2026 | 17/6/2026 | Directus is a real-time API and App dashboard for managing SQL database content. Prior to 11.17.0, the PATCH /files/{id} endpoint accepts a user-controlled filename_disk parameter. By setting this value to match the storage path of another user's file, an attacker can overwrite that file's content while manipulating… | |
| Analizada | Alta (8.1) | 0.43% | — | Monospace Directus | 6/4/2026 | 24/7/2026 | Directus is a real-time API and App dashboard for managing SQL database content. Prior to 11.17.0, aggregate functions (min, max) applied to fields with the conceal special type incorrectly return raw database values instead of the masked placeholder. When combined with groupBy, any authenticated user with read access… | |
| Analizada | Media (6.5) | 0.42% | — | Monospace Directus | 6/4/2026 | 24/7/2026 | Directus is a real-time API and App dashboard for managing SQL database content. Prior to 11.17.0, Directus' GraphQL endpoints (/graphql and /graphql/system) did not deduplicate resolver invocations within a single request. An authenticated user could exploit GraphQL aliasing to repeat an expensive relational query… | |
| Analizada | Media (5.3) | 0.36% | — | Monospace Directus | 6/4/2026 | 24/7/2026 | Directus is a real-time API and App dashboard for managing SQL database content. Prior to 11.16.1, when GRAPHQL_INTROSPECTION=false is configured, Directus correctly blocks standard GraphQL introspection queries (__schema, __type). However, the server_specs_graphql resolver on the /graphql/system endpoint returns an… | |
| Analizada | Alta (8.1) | 0.39% | — | Monospace Directus | 6/4/2026 | 24/7/2026 | Directus is a real-time API and App dashboard for managing SQL database content. Prior to 11.16.1, Directus' TUS resumable upload endpoint (/files/tus) allows any authenticated user with basic file upload permissions to overwrite arbitrary existing files by UUID. The TUS controller performs only collection-level… | |
| Analizada | Media (4.3) | 0.33% | — | Monospace Directus | 6/4/2026 | 24/7/2026 | Directus is a real-time API and App dashboard for managing SQL database content. Prior to 11.16.1, Directus is vulnerable to an open redirect via the redirect query parameter on the /admin/tfa-setup page. When an administrator who has not yet configured Two-Factor Authentication (2FA) visits a crafted URL, they are… | |
| Analizada | Media (6.1) | 0.32% | — | Monospace Directus | 6/4/2026 | 24/7/2026 | Directus is a real-time API and App dashboard for managing SQL database content. Prior to 11.16.1, an open redirect vulnerability exists in the login redirection logic. The isLoginRedirectAllowed function fails to correctly identify certain malformed URLs as external, allowing attackers to bypass redirect allow-list… | |
| Analizada | Alta (7.7) | 0.38% | — | Monospace Directus | 6/4/2026 | 24/7/2026 | Directus is a real-time API and App dashboard for managing SQL database content. Prior to 11.16.0, a Server-Side Request Forgery (SSRF) protection bypass has been identified and fixed in Directus. The IP address validation mechanism used to block requests to local and private networks could be circumvented using… | |
| Analizada | Crítica (9.3) | 0.19% | — | Monospace Directus | 6/4/2026 | 24/7/2026 | Directus is a real-time API and App dashboard for managing SQL database content. Prior to 11.17.0, Directus's Single Sign-On (SSO) login pages lacked a Cross-Origin-Opener-Policy (COOP) HTTP response header. Without this header, a malicious cross-origin window that opens the Directus login page retains the ability to… | |
| Aplazada | Baja (2.1) | 0.51% | — | Badlogic Pi-monoAI | 5/4/2026 | 24/7/2026 | A vulnerability was detected in badlogic pi-mono up to 0.58.4. This issue affects some unknown processing of the file packages/mom/src/slack.ts of the component pi-mom Slack Bot. The manipulation results in authentication bypass using alternate channel. The attack can be executed remotely. The exploit is now public… | |
| Aplazada | Baja (2.1) | 0.39% | — | Badlogic Pi-monoAI | 5/4/2026 | 24/7/2026 | A security vulnerability has been detected in badlogic pi-mono up to 0.58.4. This vulnerability affects the function discoverAndLoadExtensions of the file packages/coding-agent/src/core/extensions/loader.ts. The manipulation leads to code injection. Remote exploitation of the attack is possible. The exploit has been… | |
| Aplazada | Baja (2.1) | 0.45% | — | Badlogic Pi-monoAI | 5/4/2026 | 24/7/2026 | A vulnerability was determined in badlogic pi-mono 0.58.4. The impacted element is an unknown function of the file packages/web-ui/src/tools/artifacts/SvgArtifact.ts of the component SVG Artifact Handler. This manipulation causes cross site scripting. Remote exploitation of the attack is possible. The exploit has been… | |
| Analizada | Media (5.3) | 0.43% | — | Monospace Directus | 12/2/2026 | 17/6/2026 | Directus is a real-time API and App dashboard for managing SQL database content. Before 11.14.1, a timing-based user enumeration vulnerability exists in the password reset functionality. When an invalid reset_url parameter is provided, the response time differs by approximately 500ms between existing and non-existing… | |
| Analizada | Crítica (9.1) | 0.29% | — | Themrdemonized Xray-monolith | 27/1/2026 | 31/8/2026 | Access of Resource Using Incompatible Type ('Type Confusion') vulnerability in themrdemonized xray-monolith.This issue affects xray-monolith: before 2025.12.30. | |
| Analizada | Media (6.1) | 0.23% | — | Monospace Directus | 8/1/2026 | 17/6/2026 | Directus is a real-time API and App dashboard for managing SQL database content. Prior to version 11.14.0, an open redirect vulnerability exists in the Directus SAML authentication callback endpoint. During SAML authentication, the `RelayState` parameter is intended to preserve the user's original destination.… | |
| Analizada | Media (4.3) | 0.33% | — | Monospace Directus | 13/11/2025 | 17/6/2026 | Directus is a real-time API and App dashboard for managing SQL database content. An observable difference in error messaging was found in the Directus REST API in versions of Directus prior to version 11.13.0. The `/items/{collection}` API returns different error messages for two cases: when a user tries to access an… | |
| Analizada | Media (6.5) | 0.28% | — | Monospace Directus | 13/11/2025 | 17/6/2026 | Directus is a real-time API and App dashboard for managing SQL database content. A vulnerability in versions prior to 11.13.0 allows authenticated users to search concealed/sensitive fields when they have read permissions. While actual values remain masked (`****`), successful matches can be detected through returned… | |
| Analizada | Media (5.5) | 0.25% | — | Monospace Directus | 13/11/2025 | 17/6/2026 | Directus is a real-time API and App dashboard for managing SQL database content. A stored cross-site scripting (XSS) vulnerability exists in versions prior to 11.13.0 that allows users with `upload files` and `edit item` permissions to inject malicious JavaScript through the Block Editor interface. Attackers can… | |
| Analizada | Media (5.4) | 0.19% | — | Monospace Directus | 13/11/2025 | 17/6/2026 | Directus is a real-time API and App dashboard for managing SQL database content. Prior to version 11.13.0, Directus does not properly clean up field-level permissions when a field is deleted. When a field is removed from a collection, its reference in the permissions table remains intact. This stale reference creates… |