Vulnerabilidades em grokability
85 resultadosAnálise Vexday
A Grokability apresenta 25 vulnerabilidades registradas, todas publicadas nos últimos 90 dias, indicando exposição recente e concentrada. Nenhuma vulnerabilidade está sob ataque ativo (KEV) e nenhuma é classificada como crítica, reduzindo a urgência imediata. A fraqueza dominante é CWE-863 (falha de autorização), sugerindo problemas estruturais no controle de acesso que requerem revisão arquitetural.
CVE-2026-55469MEDIUMSnipe-IT: Path traversal vulnerability via CSV import `image` fieldEPSS 0.6%CVE-2026-86733HIGHSnipe-IT before 8.7.0 Remote Code Execution via Backup RestoreEPSS 0.6%CVE-2026-86770HIGHSnipe-IT before 8.7.0 Authentication Bypass via SAML Username CollationEPSS 0.6%CVE-2026-86734HIGHSnipe-IT before 8.7.1 Denial of Service via Unbounded Note FieldEPSS 0.5%CVE-2026-55843HIGHSnipe-IT: Improper Privilege ManagementEPSS 0.5%CVE-2026-86738CRITICALSnipe-IT before 8.7.0 CSS Injection via Custom CSSEPSS 0.5%CVE-2026-55474HIGHSnipe-IT: Directory traversal in displaySigEPSS 0.5%CVE-2026-85617HIGHsnipe-it before 8.6.3 Authorization Bypass via Bulk DeleteEPSS 0.5%CVE-2026-49976MEDIUMSnipe-IT: User Account Escalation via CSV ImportEPSS 0.5%CVE-2026-86762HIGHSnipe-IT before 8.7.0 Authentication Bypass via API MiddlewareEPSS 0.5%CVE-2026-61807MEDIUMSnipe-IT: Stored DOM XSS via table selected-count IDsEPSS 0.5%CVE-2026-55643HIGHSnipe-IT: Tenant Isolation Bypass in FMCS Floater ModeEPSS 0.4%CVE-2026-44832HIGHSnipe-IT: Privilege Escalation via API Permissions AssignmentEPSS 0.4%CVE-2026-55460HIGHSnipe-IT: Authorization bypass on bulk editing usersEPSS 0.4%CVE-2026-55466MEDIUMSnipe-IT: Stored XSS via inline-served attachmentEPSS 0.4%CVE-2026-55452MEDIUMSnipe-IT: CSV formula injection in Activity Report exportEPSS 0.4%CVE-2026-48507HIGHSnipe-IT: Bulk editing users allowed `ldap_import` and `activated_in` bulk editing usersEPSS 0.4%CVE-2026-55694HIGHSnipe-IT: Chained Information Disclosure and IDOR Leads to Full EULA File TakeoverEPSS 0.4%CVE-2026-55483MEDIUMSnipe-IT: Privilege Escalation via Missing admin Permission Check in User CreationEPSS 0.4%CVE-2026-86758HIGHSnipe-IT before 8.7.0 License Key Exposure via CSV ExportEPSS 0.4%