Vulnerabilidades em flowintel
13 resultadosAnálise Vexday
A Flowintel apresenta presença mínima na base de vulnerabilidades com apenas 1 CVE registrado, publicado recentemente (últimos 90 dias), relacionado a Server-Side Request Forgery (CWE-918). Sem registros de exploração ativa ou severidade crítica, o risco atual é baixo, mas recomenda-se monitorar a evolução deste fornecedor de menor expressão no mercado.
CVE-2026-81753MEDIUMFlowintel Stored XSS in Case Notes via Malicious Mermaid Diagram ContentEPSS 0.4%CVE-2026-81826CRITICALFlowintel Fails to Invalidate Active Sessions After Password ChangeEPSS 0.3%CVE-2026-81743HIGHFlowintel Arbitrary Log File Path Allows Remote Code Execution via Template InjectionEPSS 0.3%CVE-2026-81662HIGHFlowintel Alert Settings Configuration Allows Remote Code Execution via Arbitrary Configuration KeysEPSS 0.3%CVE-2026-81818HIGHFlowintel Organization Administrator Can Reset Full Administrator Password and Escalate PrivilegesEPSS 0.3%CVE-2026-81659HIGHFlowintel Note PDF Export Allows Arbitrary Local File Read via Pandoc/XeLaTeX ProcessingEPSS 0.3%CVE-2026-81827MEDIUMFlowintel Login Email Validation Bypass Allows Log Injection via Crafted Email InputEPSS 0.3%CVE-2026-81819MEDIUMFlowintel Missing Authorization Allows Regular API Users to View Other Users’ Task AssignmentsEPSS 0.3%CVE-2026-69075MEDIUMStored Cross-Site Scripting via Vue Template Injection in FlowIntelEPSS 0.3%CVE-2026-81814MEDIUMFlowintel Stored XSS in Calendar via Malicious Case TitleEPSS 0.3%CVE-2026-81820MEDIUMFlowintel HTML Injection in MISP Case History Timeline via Crafted Object AttributesEPSS 0.3%CVE-2026-9813MEDIUMFlowIntel external reference URL probe allows server-side request forgeryEPSS 0.2%CVE-2026-81817HIGHFlowintel Missing Task-to-Case Authorization Allows Cross-Case Task ModificationEPSS 0.2%