Vulnerabilities in Grokability
82 resultsVexday analysis
Grokability apresenta footprint reduzido com apenas 1 vulnerabilidade registrada, ainda sem constatação de exploração ativa. A fraqueza identificada (CWE-639, relacionada a autorização/controle de acesso) foi recentemente publicada, demandando validação de sua relevância operacional e eventual remediação.
CVE-2026-55469MEDIUMSnipe-IT: Path traversal vulnerability via CSV import `image` fieldEPSS 0.6%CVE-2026-55843HIGHSnipe-IT: Improper Privilege ManagementEPSS 0.5%CVE-2026-86745MEDIUMSnipe-IT before 8.7.0 CSV Formula Injection via Location-Scoping ExportEPSS 0.4%CVE-2026-55466MEDIUMSnipe-IT: Stored XSS via inline-served attachmentEPSS 0.4%CVE-2026-55460HIGHSnipe-IT: Authorization bypass on bulk editing usersEPSS 0.4%CVE-2026-54329HIGHSnipe-IT: Cross-Tenant Accessory Injection in Snipe-IT APIEPSS 0.4%CVE-2026-48492MEDIUMSnipe-IT's selectlist visibility is too permissiveEPSS 0.4%CVE-2026-55516HIGHSnipe-IT: Cross-company asset maintenance re-parenting via API updateEPSS 0.4%CVE-2026-55475MEDIUMSnipe-IT: Import created_by can be overwrittenEPSS 0.3%CVE-2026-55462MEDIUMSnipe-IT: Authorization bypass on print inventory pageEPSS 0.3%CVE-2026-49976MEDIUMSnipe-IT: User Account Escalation via CSV ImportEPSS 0.3%CVE-2026-55515MEDIUMSnipe-IT: Cross-company deletion of pending checkout acceptances via unscoped report endpointEPSS 0.3%CVE-2026-55472MEDIUMSnipe-IT: API Location Creation Bypasses FMCS Parent-Child Company Boundary ValidationEPSS 0.3%CVE-2026-55474HIGHSnipe-IT: Directory traversal in displaySigEPSS 0.3%CVE-2026-86733HIGHSnipe-IT before 8.7.0 Remote Code Execution via Backup RestoreEPSS 0.3%CVE-2026-86762HIGHSnipe-IT before 8.7.0 Authentication Bypass via API MiddlewareEPSS 0.3%CVE-2026-86770HIGHSnipe-IT before 8.7.0 Authentication Bypass via SAML Username CollationEPSS 0.3%CVE-2026-44832HIGHSnipe-IT: Privilege Escalation via API Permissions AssignmentEPSS 0.3%CVE-2026-49870MEDIUMSnipe-IT: TOTP Brute-Forceable Due to Missing Rate Limiting on `POST /two-factor`EPSS 0.3%CVE-2026-55461MEDIUMSnipe-IT: Open Redirect After User EditEPSS 0.3%