Brainslug
23 exploits
Active since Mar 2023
Directus 10.8.0-11.9.2 - Unauthenticated Arbitrary File Upload via File Update Mechanism
CVSS 9.3
Directus < 9.23.3 - Unauthenticated Token Exposure via Log Output
CVSS 4.2
Directus 10.4.0-10.6.1 - Denial of Service via Invalid WebSocket Frame
CVSS 5.9
Directus < 10.8.3 - Unauthenticated Sensitive Information Exposure via Compiled JS Bundles
CVSS 5.3
Directus < 10.10.0 - Open Redirect via Auth API Redirect Parameter
CVSS 5.4
Directus < 10.11.0 - Exposure of Sensitive Information via Alias Parameter
CVSS 4.9
Directus < 10.11.0 - Insufficient Session Expiration via JWT Token
CVSS 5.4
Directus < 10.12.0 - Denial of Service via GraphQL Field Duplication
CVSS 6.5
Directus < 10.13.0 - User Enumeration via SSO Error Messages
CVSS 7.5
Directus < 10.13.3 - Improper Access Control via Loopback Device Bypass
CVSS 5.0
Directus <11.3.0 - Privilege Escalation
CVSS 7.5
Directus <11.5.0 - Privilege Escalation
CVSS 3.5
Directus 9.0.0-alpha.4-11.4.9 - Unauthorized Sensitive Information Exposure via Search Query Parameter
CVSS 5.3
Directus 9.0.0-11.8.0 - Sensitive Information Exposure via Log to Console Operation
CVSS 4.2
Directus 9.0.0-11.8.0 - Sensitive Information Exposure in WebHook Flow Logs
CVSS 4.5
Directus 9.0.0-11.8.0 - Unauthenticated Exposure of Sensitive Version Information via OpenAPI Spec Endpoint
CVSS 5.3
Directus <11.9.0 - Privilege Escalation
CVSS 6.5
Directus < 11.13.0 - Improper Access Control via Stale Field Permission References
CVSS 4.6
Directus < 11.13.0 - Stored Cross-Site Scripting via Block Editor Interface
CVSS 5.5
Directus <11.13.0 - Info Disclosure
CVSS 6.5
Directus < 11.13.0 - Information Disclosure via Collection Existence Error Messages
CVSS 4.3
Directus < 11.14.0 - Unauthenticated Open Redirect via SAML RelayState Parameter
CVSS 4.3
Directus < 11.14.1 - Timing-Based User Enumeration via Password Reset
CVSS 5.3