Vulnerabilidades en Roskus

19 resultados
Análisis Vexday

Roskus apresenta 7 vulnerabilidades catalogadas, todas publicadas nos últimos 90 dias, indicando descobertas recentes de segurança. Nenhuma está sob exploração ativa em campo (KEV) e não há críticas de severidade máxima, reduzindo o risco imediato. A fraqueza dominante é CWE-639 (autorização inadequada), sugerindo problemas de controle de acesso que requerem revisão nas políticas de permissão do fornecedor.

CVE-2026-59235HIGHMissing authorization in Prospero Flow CRM allows low-privileged users to read all bank accountsEPSS 0.7%CVE-2026-59237MEDIUMIDOR in Prospero Flow CRM Order API allows cross-tenant read and modification of ordersEPSS 0.6%CVE-2026-59234MEDIUMAuthorization Bypass Through User-Controlled Key in Prospero Flow CRM calendar event deletionEPSS 0.6%CVE-2026-59236MEDIUMAuthorization bypass in Prospero Flow CRM Excel import allows cross-tenant record injectionEPSS 0.6%CVE-2026-19871CRITICALUse of hard-coded credentials in Prospero Flow CRM employee onboardingEPSS 0.4%CVE-2026-59239HIGHStored XSS in Prospero Flow CRM email body allows administrator account takeoverEPSS 0.4%CVE-2026-78365CRITICALIDOR and missing authorization in Prospero Flow CRM supplier API allows cross-tenant read and modificationEPSS 0.4%CVE-2026-19734HIGHIDOR in Prospero Flow CRM allows cross-tenant product disclosure and hijackingEPSS 0.3%CVE-2026-19539HIGHIDOR in Prospero Flow CRM allows cross-tenant ticket read, hijacking, and deletionEPSS 0.3%CVE-2026-77759HIGHIDOR and missing authorization in the Prospero Flow CRM transaction API allow cross-tenant reading of financial recordsEPSS 0.3%CVE-2026-59232MEDIUMStored Cross-site Scripting in Prospero Flow CRM lead name fieldEPSS 0.3%CVE-2026-78337MEDIUMUnrestricted upload of file with dangerous type in Prospero Flow CRM allows stored cross-site scripting via SVGEPSS 0.3%CVE-2026-59240MEDIUMIDOR in Prospero Flow CRM allows deletion of other users' notificationsEPSS 0.3%CVE-2026-81931MEDIUMUnrestricted upload of file with dangerous type in Prospero Flow CRM product photo allows stored cross-site scriptingEPSS 0.3%CVE-2026-19870HIGHIDOR in Prospero Flow CRM allows cross-tenant payroll disclosure and creationEPSS 0.3%CVE-2026-77780MEDIUMUnvalidated bank account and card foreign keys in the Prospero Flow CRM transaction save endpoint allow cross-tenant disclosure of banking identifiersEPSS 0.3%CVE-2026-19433HIGHAuthorization Bypass Through User-Controlled Key in Prospero Flow CRM contact save and vCard exportEPSS 0.3%CVE-2026-59233HIGHMissing Authorization in Prospero Flow CRM permission save endpoint allows privilege escalationEPSS 0.2%CVE-2026-82911MEDIUMCSRF in Prospero Flow CRM order confirmation allows unauthorized order state changesEPSS 0.2%