Monospace
19 CVEs tracked since 2024. Since Jul 2024, none of them reached CISA KEV.
Monospace CVEs per month
| Month | CVEs | In CISA KEV |
|---|---|---|
| 2024-07 | 4 | 0 |
| 2024-08 | null or fewer | |
| 2024-09 | null or fewer | |
| 2024-10 | null or fewer | |
| 2024-11 | null or fewer | |
| 2024-12 | null or fewer | |
| 2025-01 | null or fewer | |
| 2025-02 | null or fewer | |
| 2025-03 | 5 | 0 |
| 2025-04 | null or fewer | |
| 2025-05 | null or fewer | |
| 2025-06 | null or fewer | |
| 2025-07 | null or fewer | |
| 2025-08 | null or fewer | |
| 2025-09 | null or fewer | |
| 2025-10 | null or fewer | |
| 2025-11 | null or fewer | |
| 2025-12 | null or fewer | |
| 2026-01 | null or fewer | |
| 2026-02 | null or fewer | |
| 2026-03 | null or fewer | |
| 2026-04 | 10 | 0 |
Products
The products that kept showing up in Monospace's monthly top three, with their CVEs summed over those months.
Latest CVEs
The 15 most recently published vulnerabilities affecting Monospace.
- CVE-2026-61836Directus: Authorization-dependent response served from unsegmented cache key8.6
- CVE-2026-61835Directus: SSRF Protection Bypass via 0.0.0.0 in File Import7.7
- CVE-2026-39943Directus exposes sensitive fields in revision history6.5
- CVE-2026-39942Directus has a Path Traversal and Broken Access Control in File Management API8.5
- CVE-2026-35442Directus: Authenticated Users Can Extract Concealed Fields via Aggregate Queries8.1
- CVE-2026-35441Directus Affected by GraphQL Alias Amplification Denial-of-Service Due to Missing Query Cost/Complexity Limits6.5
- CVE-2026-35413Directus GraphQL Schema SDL Disclosure Setting5.3
- CVE-2026-35412Directus has a TUS Upload Authorization Bypass Allows Arbitrary File Overwrite7.1
- CVE-2026-35411Directus is an Open Redirect in Admin 2FA Setup Page4.3
- CVE-2026-35410Directus has an Open Redirect via Parser Bypass in OAuth2/SAML Authentication Flow6.1
- CVE-2026-35409Directus has a SSRF Protection Bypass via IPv4-Mapped IPv6 Addresses in File Import7.7
- CVE-2026-35408Directus is Missing Cross-Origin Opener Policy8.7
- CVE-2026-26185Directus Affected by User Enumeration via Password Reset Timing Attack5.3
- CVE-2026-22032Directus has open redirect in SAML4.3
- CVE-2025-64749Directus Vulnerable to Information Leakage in Existing Collections4.3
The record
- Peak rank
- #107 in Apr 2026
- Busiest month shown
- Apr 2026, 10 CVEs
- Months with a KEV entry
- 0 since Jul 2024
- Monthly snapshots
- 3 since 2024