Vulnerabilities in grokability
85 resultsVexday analysis
A Grokability apresenta 25 vulnerabilidades registradas, todas publicadas nos últimos 90 dias, indicando exposição recente e concentrada. Nenhuma vulnerabilidade está sob ataque ativo (KEV) e nenhuma é classificada como crítica, reduzindo a urgência imediata. A fraqueza dominante é CWE-863 (falha de autorização), sugerindo problemas estruturais no controle de acesso que requerem revisão arquitetural.
CVE-2026-86742MEDIUMSnipe-IT before 8.7.0 CSV Formula Injection via Asset Acceptance ReportEPSS 0.4%CVE-2026-86765HIGHSnipe-IT 8.6.3 Authorization Bypass via Asset Update EndpointEPSS 0.4%CVE-2026-86748MEDIUMSnipe-IT before 8.7.0 Database Wipe via Invalid Backup ArchiveEPSS 0.4%CVE-2026-49870MEDIUMSnipe-IT: TOTP Brute-Forceable Due to Missing Rate Limiting on `POST /two-factor`EPSS 0.4%CVE-2026-54329HIGHSnipe-IT: Cross-Tenant Accessory Injection in Snipe-IT APIEPSS 0.4%CVE-2026-48492MEDIUMSnipe-IT's selectlist visibility is too permissiveEPSS 0.4%CVE-2026-84206MEDIUMSnipe-IT before 8.7.0 Authorization Bypass via Bulk RestoreEPSS 0.4%CVE-2026-86760MEDIUMsnipe-it 8.2.0 before 8.7.0 Authentication Bypass via activated flagEPSS 0.4%CVE-2026-85616HIGHSnipe-IT before 8.6.2 Authorization Bypass via Checkout-AcceptanceEPSS 0.4%CVE-2026-55516HIGHSnipe-IT: Cross-company asset maintenance re-parenting via API updateEPSS 0.4%CVE-2026-86757HIGHSnipe-IT before 8.7.0 Information Disclosure via Custom FieldsEPSS 0.4%CVE-2026-86764HIGHSnipe-IT 8.6.4 before 8.7.0 Permission Bypass via assigned componentsEPSS 0.4%CVE-2026-86751HIGHSnipe-IT before 8.7.0 Arbitrary File Read and SSRF via MarkdownEPSS 0.4%CVE-2026-55519MEDIUMSnipe-IT: Improper Authorization in File Deletion (IDOR)EPSS 0.4%CVE-2026-86759HIGHSnipe-IT before 8.7.0 Missing Authorization via asset-history CSV importerEPSS 0.4%CVE-2026-86745MEDIUMSnipe-IT before 8.7.0 CSV Formula Injection via Location-Scoping ExportEPSS 0.4%CVE-2026-86739LOWSnipe-IT before 8.7.0 Acceptance Finalization Without Stored EvidenceEPSS 0.4%CVE-2026-86761MEDIUMsnipe-it 8.6.3 before 8.7.0 Authorization Bypass via print endpointsEPSS 0.4%CVE-2026-86741HIGHSnipe-IT before 8.7.0 Arbitrary File Read and SSRF via Category EULAEPSS 0.4%CVE-2026-86768MEDIUMSnipe-IT before 8.7.0 Improper Input Validation via API CheckoutEPSS 0.3%