Tildeslash maintains a narrowly scoped product portfolio centered on Monit and M/Monit, system monitoring and management tools widely deployed in infrastructure and cloud environments. Vulnerabilities affecting the vendor recur through access-control and credential-management weakness classes, including incorrect authorization, insufficiently protected credentials, and weak password recovery mechanisms, reflecting the authentication and privilege demands of privileged monitoring agents. The vulnerabilities frequently acquire public exploit code, making timely patching a priority for exposed instances; live severity and exploitation counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Tildeslash over time
Signals from CVEs in this vendor scope (10 CVEs).
10 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2003-1083HIGH Stack-based buffer overflow in Monit 1.4 to 4.1 allows remote attackers to execute arbitrary code via a long HTTP request. | Dec 31, 2003 | 10.0 | 53 | NO | YES |
CVE-2004-1898HIGH Stack-based buffer overflow in the administration interface in Monit 1.4 through 4.2 allows remote attackers to execute arbitrary code via a long username. | Dec 31, 2004 | 10.0 | 43 | NO | YES |
CVE-2020-36969HIGH M/Monit 3.7.4 contains a privilege escalation vulnerability that allows authenticated users to modify user permissions by manipulating the admin parameter. Attackers can send a POS | Jan 28, 2026 | 8.8 | 29 | NO | NO |
CVE-2019-11393CRITICAL An issue was discovered in /admin/users/update in M/Monit before 3.7.3. It allows unprivileged users to escalate their privileges to an administrator by requesting a password chang | Apr 22, 2019 | 9.8 | 29 | NO | NO |
CVE-2019-11455HIGH A buffer over-read in Util_urlDecode in util.c in Tildeslash Monit before 5.25.3 allows a remote authenticated attacker to retrieve the contents of adjacent memory via manipulation | Apr 22, 2019 | 8.1 | 28 | NO | NO |
CVE-2004-1897MEDIUM Administration interface in Monit 1.4 through 4.2 allows remote attackers to cause a denial of service (segmentation fault) by sending a Basic Authentication request without a pass | Dec 31, 2004 | 5.0 | 26 | NO | YES |
CVE-2022-26563HIGH An issue was discovered in Tildeslash Monit before 5.31.0, allows remote attackers to gain escilated privlidges due to improper PAM-authorization. | Jul 18, 2023 | 8.8 | 24 | NO | NO |
CVE-2020-36968MEDIUM M/Monit 3.7.4 contains an authentication vulnerability that allows authenticated attackers to retrieve user password hashes through an administrative API endpoint. Attackers can se | Jan 28, 2026 | 6.5 | 22 | NO | NO |
CVE-2003-1084MEDIUM Monit 1.4 to 4.1 allows remote attackers to cause a denial of service (daemon crash) via an HTTP POST request with a negative Content-Length field. | Nov 24, 2003 | 5.0 | 20 | NO | NO |
CVE-2004-1899MEDIUM The administration interface in Monit 1.4 through 4.2 allows remote attackers to cause an off-by-one overflow via a POST that contains 1024 bytes. | Dec 31, 2004 | 5.0 | 15 | NO | NO |
Signals from CVEs in this vendor scope (10 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Tildeslash.
Media articles that mention a CVE ID that affects a product developed by Tildeslash — matched by CVE ID, not by vendor name.