Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

grokability — Vulnerabilities & Security Advisories 85

Browse all 85 CVE security advisories affecting grokability. AI-powered Chinese analysis, POCs, and references for each vulnerability.

This aggregation page catalogs security vulnerabilities associated with the vendor grokability. The collection compiles records of defects across the vendor’s software and hardware products, covering advisories issued within a defined historical time range. Readers can use this index to track the vendor’s disclosed security notices, analyze the distribution of specific weakness classes, and review the complete vulnerability history for individual product lines. The data is organized to support risk assessment, patch planning, and the study of recurring defect patterns within the grokability ecosystem.

Top products by grokability: snipe-it
CVE ID Title CVSS Severity Published
CVE-2026-62368 Snipe-IT: Stored XSS via Custom Field name in asset-list column headers — snipe-it CWE-79 8.1 High 2026-09-24
CVE-2026-63493 Snipe-IT: 2FA bypass via the API token flow — snipe-it CWE-288 8.6 High 2026-09-24
CVE-2026-63498 Snipe-IT: Stored XSS via Inline XML Rendering in the Uploaded Files API — snipe-it CWE-79 8.7 High 2026-09-24
CVE-2026-88894 Snipe-IT before 8.7.2 Authorization Bypass via Predefined Kit Checkout — snipe-it CWE-863 5.4 Medium 2026-09-10
CVE-2026-86774 Snipe-IT before 8.7.0 Broken Access Control via AssetModelPolicy — snipe-it CWE-284 6.3 Medium 2026-09-09
CVE-2026-86773 Snipe-IT 8.6.3 Broken Access Control via Kit Update Endpoints — snipe-it CWE-863 5.4 Medium 2026-09-09
CVE-2026-86772 Snipe-IT 8.6.3 Stored XSS via Department Names — snipe-it CWE-79 5.4 Medium 2026-09-09
CVE-2026-86771 Snipe-IT before 8.7.0 Server-Side Request Forgery via employee_num — snipe-it CWE-918 7.6 High 2026-09-09
CVE-2026-86769 Snipe-IT before 8.7.0 Audit Log Misattribution via Consumables Checkout — snipe-it CWE-282 4.3 Medium 2026-09-09
CVE-2026-86770 Snipe-IT before 8.7.0 Authentication Bypass via SAML Username Collation — snipe-it CWE-178 8.1 High 2026-09-09
CVE-2026-86768 Snipe-IT before 8.7.0 Improper Input Validation via API Checkout — snipe-it CWE-20 5.4 Medium 2026-09-09
CVE-2026-86767 Snipe-IT before 8.7.0 Cross-Company Read via requested-assets — snipe-it CWE-200 5.0 Medium 2026-09-09
CVE-2026-86766 Snipe-IT 8.6.3 Race Condition via Consumable Checkout — snipe-it CWE-362 6.5 Medium 2026-09-09
CVE-2026-86765 Snipe-IT 8.6.3 Authorization Bypass via Asset Update Endpoint — snipe-it CWE-862 6.5 Medium 2026-09-09
CVE-2026-86764 Snipe-IT 8.6.4 before 8.7.0 Permission Bypass via assigned components — snipe-it CWE-862 6.5 Medium 2026-09-09
CVE-2026-86763 snipe-it 7.0.12 through 8.6.3 Authorization Bypass via Importer — snipe-it CWE-639 3.5 Low 2026-09-09
CVE-2026-86762 Snipe-IT before 8.7.0 Authentication Bypass via API Middleware — snipe-it CWE-862 8.1 High 2026-09-09
CVE-2026-86761 snipe-it 8.6.3 before 8.7.0 Authorization Bypass via print endpoints — snipe-it CWE-639 4.3 Medium 2026-09-09
CVE-2026-86760 snipe-it 8.2.0 before 8.7.0 Authentication Bypass via activated flag — snipe-it CWE-863 5.4 Medium 2026-09-09
CVE-2026-86759 Snipe-IT before 8.7.0 Missing Authorization via asset-history CSV importer — snipe-it CWE-862 7.1 High 2026-09-09
CVE-2026-86758 Snipe-IT before 8.7.0 License Key Exposure via CSV Export — snipe-it CWE-204 6.5 Medium 2026-09-09
CVE-2026-86756 Snipe-IT 8.5.0 through 8.6.3 Open Redirect via SAML RelayState — snipe-it CWE-601 6.1 Medium 2026-09-09
CVE-2026-86757 Snipe-IT before 8.7.0 Information Disclosure via Custom Fields — snipe-it CWE-862 6.5 Medium 2026-09-09
CVE-2026-86755 Snipe-IT 4.2.0 through 8.6.3 Permission Bypass via OAuth — snipe-it CWE-863 5.4 Medium 2026-09-09
CVE-2026-86754 Snipe-IT before 8.7.0 Authorization Bypass via OAuth Clients — snipe-it CWE-863 7.3 High 2026-09-09
CVE-2026-86753 snipe-it before 8.7.0 Business Logic Bypass via asset_model endpoint — snipe-it CWE-863 4.3 Medium 2026-09-09
CVE-2026-86752 snipe-it before 8.7.0 Authorization Bypass via Asset Audit Endpoints — snipe-it CWE-863 5.4 Medium 2026-09-09
CVE-2026-86751 Snipe-IT before 8.7.0 Arbitrary File Read and SSRF via Markdown — snipe-it CWE-73 8.5 High 2026-09-09
CVE-2026-86749 snipe-it before 8.7.0 Data Loss via Failed Image Write — snipe-it CWE-252 6.3 Medium 2026-09-09
CVE-2026-86750 snipe-it before 8.7.0 Authorization Bypass via API User Create/Update — snipe-it CWE-863 7.7 High 2026-09-09

This page lists every published CVE security advisory associated with grokability. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.