Записи monospace
56 опубликованных записей вендора monospace.
Профиль для исследователя
- Попали в KEV
- 0 · 0 %
- С эксплойтом
- 0 · 0 %
- Pre-auth RCE
- 0
- С записью об исправлении
- 100 %
- Медиана: публикация → KEV
- Ни одна запись не попала в KEV
Повторяющиеся классы
- CWE-200 Exposure of Sensitive Information to an Unauthorized Actor14
- CWE-284 Improper Access Control5
- CWE-918 Server-Side Request Forgery (SSRF)4
- CWE-601 URL Redirection to Untrusted Site ('Open Redirect')3
- CWE-400 Uncontrolled Resource Consumption3
- CWE-203 Observable Discrepancy2
Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.
CWEВсе записи
56 записей| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
39Наблюдать | CVE-2022-26969Эксплойта нет | In Directus before 9.7.0, the default settings of CORS_ORIGIN and CORS_ENABLED are true.monospace · directus · CWE-942 | Критическая9,8 | — | 0,9 % | 26 дек. 2022 г. |
37Наблюдать | CVE-2026-35408Эксплойта нет | Directus is Missing Cross-Origin Opener Policymonospace · directus · CWE-346 | Критическая9,3 | — | 0,2 % | 6 апр. 2026 г. |
35Наблюдать | CVE-2026-39942Эксплойта нет | Directus has a Path Traversal and Broken Access Control in File Management APImonospace · directus · CWE-284 | Высокая8,8 | — | 0,4 % | 9 апр. 2026 г. |
34Наблюдать | CVE-2026-61836Эксплойта нет | Directus: Authorization-dependent response served from unsegmented cache keymonospace · directus · CWE-524 | Высокая8,6 | — | 0,5 % | 15 июл. 2026 г. |
32Наблюдать | CVE-2024-27295Эксплойта нет | Directus MySQL accent insensitive email matchingmonospace · directus · CWE-706 | Высокая8,2 | — | 0,7 % | 1 мар. 2024 г. |
32Наблюдать | CVE-2026-35442Эксплойта нет | Directus: Authenticated Users Can Extract Concealed Fields via Aggregate Queriesmonospace · directus · CWE-200 | Высокая8,1 | — | 0,4 % | 6 апр. 2026 г. |
32Наблюдать | CVE-2026-35412Эксплойта нет | Directus has a TUS Upload Authorization Bypass Allows Arbitrary File Overwritemonospace · directus · CWE-863 | Высокая8,1 | — | 0,4 % | 6 апр. 2026 г. |
30Наблюдать | CVE-2025-55746Proof of concept | Directus allows unauthenticated file upload and file modification due to lacking input sanitizationmonospace · directus · CWE-73 | Высокая7,5 | — | 1,3 % | 20 авг. 2025 г. |
30Наблюдать | CVE-2023-26492Эксплойта нет | Directus vulnerable to Server-Side Request Forgery On File Importmonospace · directus · CWE-918 | Высокая7,5 | — | 1,0 % | 3 мар. 2023 г. |
30Наблюдать | CVE-2024-36128Эксплойта нет | Directus is soft-locked by providing a string value to random string utilmonospace · directus · CWE-754 | Высокая7,5 | — | 0,6 % | 3 июн. 2024 г. |
30Наблюдать | CVE-2024-54151Эксплойта нет | Directus allows unauthenticated access to WebSocket events and operationsmonospace · directus · CWE-200 | Высокая7,5 | — | 0,6 % | 9 дек. 2024 г. |
30Наблюдать | CVE-2025-30353Эксплойта нет | Directus's webhook trigger flows can leak sensitive datamonospace · directus · CWE-200 | Высокая7,5 | — | 0,5 % | 26 мар. 2025 г. |
30Наблюдать | CVE-2024-39701Эксплойта нет | Directus Incorrectly handles _in` filtermonospace · directus · CWE-284 | Высокая7,7 | — | 0,4 % | 8 июл. 2024 г. |
30Наблюдать | CVE-2026-61835Эксплойта нет | Directus: SSRF Protection Bypass via 0.0.0.0 in File Importmonospace · directus · CWE-918 | Высокая7,7 | — | 0,4 % | 15 июл. 2026 г. |
30Наблюдать | CVE-2026-35409Эксплойта нет | Directus has a SSRF Protection Bypass via IPv4-Mapped IPv6 Addresses in File Importmonospace · directus · CWE-918 | Высокая7,7 | — | 0,4 % | 6 апр. 2026 г. |
26Наблюдать | CVE-2020-19850Эксплойта нет | An issue found in Directus API v.2.2.0 allows a remote attacker to cause a denial of service via a great amount of HTTP requests.monospace · directus · CWE-400 | Средняя6,5 | — | 1,1 % | 4 апр. 2023 г. |
26Наблюдать | CVE-2022-36031Эксплойта нет | Unhandled exception on illegal filename_disk valuemonospace · directus · CWE-755 | Средняя6,5 | — | 1,0 % | 19 авг. 2022 г. |
26Наблюдать | CVE-2024-39895Эксплойта нет | Directus GraphQL Field Duplication Denial of Service (DoS)monospace · directus · CWE-400 | Средняя6,5 | — | 0,8 % | 8 июл. 2024 г. |
26Наблюдать | CVE-2023-45820Эксплойта нет | Directus crashes on invalid WebSocket messagemonospace · directus · CWE-755 | Средняя6,5 | — | 0,7 % | 19 окт. 2023 г. |
26Наблюдать | CVE-2024-45596Эксплойта нет | Directus's session is cached for OpenID and OAuth2 if `redirect` is not usedmonospace · directus · CWE-524 | Средняя6,5 | — | 0,7 % | 10 сент. 2024 г. |
26Наблюдать | CVE-2023-38503Эксплойта нет | Directus has Incorrect Permission Checking for GraphQL Subscriptionsmonospace · directus · CWE-200 | Средняя6,5 | — | 0,5 % | 25 июл. 2023 г. |
26Наблюдать | CVE-2026-35441Эксплойта нет | Directus Affected by GraphQL Alias Amplification Denial-of-Service Due to Missing Query Cost/Complexity Limitsmonospace · directus · CWE-400 | Средняя6,5 | — | 0,4 % | 6 апр. 2026 г. |
26Наблюдать | CVE-2025-53889Эксплойта нет | Directus missing permission checks for manual trigger Flowsmonospace · directus · CWE-287 | Средняя6,5 | — | 0,4 % | 14 июл. 2025 г. |
26Наблюдать | CVE-2025-64748Эксплойта нет | Directus's conceal fields are searchable if read permissions enabledmonospace · directus · CWE-201 | Средняя6,5 | — | 0,3 % | 13 нояб. 2025 г. |
26Наблюдать | CVE-2026-39943Эксплойта нет | Directus exposes sensitive fields in revision historymonospace · directus · CWE-200 | Средняя6,5 | — | 0,3 % | 9 апр. 2026 г. |
- CVE-2022-2696939Наблюдать
In Directus before 9.7.0, the default settings of CORS_ORIGIN and CORS_ENABLED are true.
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %monospace · directus26 дек. 2022 г.
- CVE-2026-3540837Наблюдать
Directus is Missing Cross-Origin Opener Policy
КритическаяCVSS 9,3Эксплойта нетEPSS 0 %monospace · directus6 апр. 2026 г.
- CVE-2026-3994235Наблюдать
Directus has a Path Traversal and Broken Access Control in File Management API
ВысокаяCVSS 8,8Эксплойта нетEPSS 0 %monospace · directus9 апр. 2026 г.
- CVE-2026-6183634Наблюдать
Directus: Authorization-dependent response served from unsegmented cache key
ВысокаяCVSS 8,6Эксплойта нетEPSS 0 %monospace · directus15 июл. 2026 г.
- CVE-2024-2729532Наблюдать
Directus MySQL accent insensitive email matching
ВысокаяCVSS 8,2Эксплойта нетEPSS 1 %monospace · directus1 мар. 2024 г.
- CVE-2026-3544232Наблюдать
Directus: Authenticated Users Can Extract Concealed Fields via Aggregate Queries
ВысокаяCVSS 8,1Эксплойта нетEPSS 0 %monospace · directus6 апр. 2026 г.
- CVE-2026-3541232Наблюдать
Directus has a TUS Upload Authorization Bypass Allows Arbitrary File Overwrite
ВысокаяCVSS 8,1Эксплойта нетEPSS 0 %monospace · directus6 апр. 2026 г.
- CVE-2025-5574630Наблюдать
Directus allows unauthenticated file upload and file modification due to lacking input sanitization
ВысокаяCVSS 7,5Proof of conceptEPSS 1 %monospace · directus20 авг. 2025 г.
- CVE-2023-2649230Наблюдать
Directus vulnerable to Server-Side Request Forgery On File Import
ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %monospace · directus3 мар. 2023 г.
- CVE-2024-3612830Наблюдать
Directus is soft-locked by providing a string value to random string util
ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %monospace · directus3 июн. 2024 г.
- CVE-2024-5415130Наблюдать
Directus allows unauthenticated access to WebSocket events and operations
ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %monospace · directus9 дек. 2024 г.
- CVE-2025-3035330Наблюдать
Directus's webhook trigger flows can leak sensitive data
ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %monospace · directus26 мар. 2025 г.
- CVE-2024-3970130Наблюдать
Directus Incorrectly handles _in` filter
ВысокаяCVSS 7,7Эксплойта нетEPSS 0 %monospace · directus8 июл. 2024 г.
- CVE-2026-6183530Наблюдать
Directus: SSRF Protection Bypass via 0.0.0.0 in File Import
ВысокаяCVSS 7,7Эксплойта нетEPSS 0 %monospace · directus15 июл. 2026 г.
- CVE-2026-3540930Наблюдать
Directus has a SSRF Protection Bypass via IPv4-Mapped IPv6 Addresses in File Import
ВысокаяCVSS 7,7Эксплойта нетEPSS 0 %monospace · directus6 апр. 2026 г.
- CVE-2020-1985026Наблюдать
An issue found in Directus API v.2.2.0 allows a remote attacker to cause a denial of service via a great amount of HTTP requests.
СредняяCVSS 6,5Эксплойта нетEPSS 1 %monospace · directus4 апр. 2023 г.
- CVE-2022-3603126Наблюдать
Unhandled exception on illegal filename_disk value
СредняяCVSS 6,5Эксплойта нетEPSS 1 %monospace · directus19 авг. 2022 г.
- CVE-2024-3989526Наблюдать
Directus GraphQL Field Duplication Denial of Service (DoS)
СредняяCVSS 6,5Эксплойта нетEPSS 1 %monospace · directus8 июл. 2024 г.
- CVE-2023-4582026Наблюдать
Directus crashes on invalid WebSocket message
СредняяCVSS 6,5Эксплойта нетEPSS 1 %monospace · directus19 окт. 2023 г.
- CVE-2024-4559626Наблюдать
Directus's session is cached for OpenID and OAuth2 if `redirect` is not used
СредняяCVSS 6,5Эксплойта нетEPSS 1 %monospace · directus10 сент. 2024 г.
- CVE-2023-3850326Наблюдать
Directus has Incorrect Permission Checking for GraphQL Subscriptions
СредняяCVSS 6,5Эксплойта нетEPSS 0 %monospace · directus25 июл. 2023 г.
- CVE-2026-3544126Наблюдать
Directus Affected by GraphQL Alias Amplification Denial-of-Service Due to Missing Query Cost/Complexity Limits
СредняяCVSS 6,5Эксплойта нетEPSS 0 %monospace · directus6 апр. 2026 г.
- CVE-2025-5388926Наблюдать
Directus missing permission checks for manual trigger Flows
СредняяCVSS 6,5Эксплойта нетEPSS 0 %monospace · directus14 июл. 2025 г.
- CVE-2025-6474826Наблюдать
Directus's conceal fields are searchable if read permissions enabled
СредняяCVSS 6,5Эксплойта нетEPSS 0 %monospace · directus13 нояб. 2025 г.
- CVE-2026-3994326Наблюдать
Directus exposes sensitive fields in revision history
СредняяCVSS 6,5Эксплойта нетEPSS 0 %monospace · directus9 апр. 2026 г.