Products: 2
    Vulnerabilities: 4
    Known Exploited: 0
    0
    Critical Level Threats
    1
    High Level Threats
    3
    Medium Level Threats
    0
    Low Level Threats

    Vulnerabilities

    100806040200
    JanFebMarAprMayJunJulAugSepOctNovDec
    Critical Level Threats
    High Level Threats
    Medium Level Threats
    Low Level Threats

    Products Security index

    Actions
    Items Per Page

    Vulnerabilities

    CVE-2019-11454

    Persistent cross-site scripting (XSS) in http/cervlet.c in Tildeslash Monit before 5.25.3 allows a remote unauthenticated attacker to introduce arbitrary JavaScript via manipulation of an unsanitized user field of the Authorization header for HTTP Basic Authentication, which is mishandled during an _viewlog operation.

    Last Modified: Nov 21, 2024
    Published: Apr 22, 2019

    CVE-2016-7067

    Monit before version 5.20.0 is vulnerable to a cross site request forgery attack. Successful exploitation will enable an attacker to disable/enable all monitoring for a particular host or disable/enable monitoring for a specific service.

    Last Modified: Nov 21, 2024
    Published: Sep 10, 2018

    CVE-2014-6607

    M/Monit 3.3.2 and earlier does not verify the original password before changing passwords, which allows remote attackers to change the password of other users and gain privileges via the fullname and password parameters, a different vulnerability than CVE-2014-6409.

    Last Modified: Apr 12, 2025
    Published: Oct 06, 2014

    CVE-2014-6409

    Cross-site request forgery (CSRF) vulnerability in M/Monit 3.3.2 and earlier allows remote attackers to hijack the authentication of administrators for requests that change user passwords via the fullname and password parameters to /admin/users/update.

    Last Modified: Apr 12, 2025
    Published: Oct 06, 2014
    Items Per Page
    Mmonit Vulnerabilities & Security CVEs | CVE-DB