Grokability
77 CVEs tracked since 2026. Since Jul 2026, none of them reached CISA KEV.
Grokability CVEs per month
| Month | CVEs | In CISA KEV |
|---|---|---|
| 2026-07 | 20 | 0 |
| 2026-08 | 11 | 0 |
| 2026-09 | 46 | 0 |
Products
The products that kept showing up in Grokability's monthly top three, with their CVEs summed over those months.
Latest CVEs
The 15 most recently published vulnerabilities affecting Grokability.
- CVE-2026-62368Snipe-IT: Stored XSS via Custom Field name in asset-list column headers8.1
- CVE-2026-63493Snipe-IT: 2FA bypass via the API token flow—
- CVE-2026-63498Snipe-IT: Stored XSS via Inline XML Rendering in the Uploaded Files API8.7
- CVE-2026-88894Snipe-IT before 8.7.2 Authorization Bypass via Predefined Kit Checkout5.4
- CVE-2026-86774Snipe-IT before 8.7.0 Broken Access Control via AssetModelPolicy6.3
- CVE-2026-86773Snipe-IT 8.6.3 Broken Access Control via Kit Update Endpoints5.4
- CVE-2026-86772Snipe-IT 8.6.3 Stored XSS via Department Names5.4
- CVE-2026-86771Snipe-IT before 8.7.0 Server-Side Request Forgery via employee_num7.6
- CVE-2026-86770Snipe-IT before 8.7.0 Authentication Bypass via SAML Username Collation8.1
- CVE-2026-86769Snipe-IT before 8.7.0 Audit Log Misattribution via Consumables Checkout4.3
- CVE-2026-86768Snipe-IT before 8.7.0 Improper Input Validation via API Checkout5.4
- CVE-2026-86767Snipe-IT before 8.7.0 Cross-Company Read via requested-assets5.0
- CVE-2026-86766Snipe-IT 8.6.3 Race Condition via Consumable Checkout6.5
- CVE-2026-86764Snipe-IT 8.6.4 before 8.7.0 Permission Bypass via assigned components6.5
- CVE-2026-86765Snipe-IT 8.6.3 Authorization Bypass via Asset Update Endpoint6.5
The record
- Peak rank
- #20 in Sep 2026
- Busiest month shown
- Sep 2026, 46 CVEs
- Months with a KEV entry
- 0 since Jul 2026
- Monthly snapshots
- 3 since 2026