VYPR
Vendor

Monit

Products
1
CVEs
4
Across products
4
Status
Private

Products

1

Recent CVEs

4
  • CVE-2019-11393CriApr 22, 2019
    risk 0.64cvss 9.8epss 0.02

    An issue was discovered in /admin/users/update in M/Monit before 3.7.3. It allows unprivileged users to escalate their privileges to an administrator by requesting a password change and specifying the admin parameter.

  • CVE-2020-36969HigJan 28, 2026
    risk 0.57cvss 8.8epss 0.00

    M/Monit 3.7.4 contains a privilege escalation vulnerability that allows authenticated users to modify user permissions by manipulating the admin parameter. Attackers can send a POST request to the /api/1/admin/users/update endpoint with a crafted payload to grant administrative…

  • CVE-2020-36968MedJan 28, 2026
    risk 0.42cvss 6.5epss 0.00

    M/Monit 3.7.4 contains an authentication vulnerability that allows authenticated attackers to retrieve user password hashes through an administrative API endpoint. Attackers can send requests to the /api/1/admin/users/list and /api/1/admin/users/get endpoints to extract MD5…

  • CVE-2016-7067MedSep 10, 2018
    risk 0.35cvss 6.5epss 0.01

    Monit before version 5.20.0 is vulnerable to a cross site request forgery attack. Successful exploitation will enable an attacker to disable/enable all monitoring for a particular host or disable/enable monitoring for a specific service.