Vulnerabilities in Grokability
82 resultsVexday analysis
Grokability apresenta footprint reduzido com apenas 1 vulnerabilidade registrada, ainda sem constatação de exploração ativa. A fraqueza identificada (CWE-639, relacionada a autorização/controle de acesso) foi recentemente publicada, demandando validação de sua relevância operacional e eventual remediação.
CVE-2026-86761MEDIUMsnipe-it 8.6.3 before 8.7.0 Authorization Bypass via print endpointsEPSS 0.2%CVE-2026-86735MEDIUMsnipe-it before 8.7.0 SSRF via IPv6 transition address bypassEPSS 0.2%CVE-2026-86758HIGHSnipe-IT before 8.7.0 License Key Exposure via CSV ExportEPSS 0.2%CVE-2026-55481MEDIUMSnipe-IT: CSS Injection via `header_color` SettingEPSS 0.2%CVE-2026-48507HIGHSnipe-IT: Bulk editing users allowed `ldap_import` and `activated_in` bulk editing usersEPSS 0.2%CVE-2026-86768MEDIUMSnipe-IT before 8.7.0 Improper Input Validation via API CheckoutEPSS 0.2%CVE-2026-86749HIGHsnipe-it before 8.7.0 Data Loss via Failed Image WriteEPSS 0.2%CVE-2026-55452MEDIUMSnipe-IT: CSV formula injection in Activity Report exportEPSS 0.2%CVE-2026-88894MEDIUMSnipe-IT before 8.7.2 Authorization Bypass via Predefined Kit CheckoutEPSS 0.2%CVE-2026-86766HIGHSnipe-IT 8.6.3 Race Condition via Consumable CheckoutEPSS 0.2%CVE-2026-86765HIGHSnipe-IT 8.6.3 Authorization Bypass via Asset Update EndpointEPSS 0.2%CVE-2026-84206MEDIUMSnipe-IT before 8.7.0 Authorization Bypass via Bulk RestoreEPSS 0.2%CVE-2026-44831MEDIUMSnipe-IT: XSS vulnerability in component notesEPSS 0.2%CVE-2026-86760MEDIUMsnipe-it 8.2.0 before 8.7.0 Authentication Bypass via activated flagEPSS 0.2%CVE-2026-86757HIGHSnipe-IT before 8.7.0 Information Disclosure via Custom FieldsEPSS 0.2%CVE-2026-86764HIGHSnipe-IT 8.6.4 before 8.7.0 Permission Bypass via assigned componentsEPSS 0.2%CVE-2026-86744LOWsnipe-it before 8.7.0 Race Condition in Asset CheckoutEPSS 0.2%CVE-2026-55519MEDIUMSnipe-IT: Improper Authorization in File Deletion (IDOR)EPSS 0.2%CVE-2026-86740MEDIUMSnipe-IT before 8.7.0 Attachment Deletion Reports Success While File RemainsEPSS 0.2%CVE-2026-86759HIGHSnipe-IT before 8.7.0 Missing Authorization via asset-history CSV importerEPSS 0.2%