All
Operating Systems
Servers
Hypervisors
Hosting Panels
Billing
CMS
Plugins
CRM
ERP
Databases
Network / Firewall
Mail Servers
Web & Hosting Related
Filtered by category:
CRM
Clear category filter
Total Tracked
1
Indexed CVEs
Critical
0
CVSS 9.0 - 10.0
High
0
CVSS 7.0 - 8.9
Medium
0
CVSS 4.0 - 6.9
Low
0
CVSS 0.1 - 3.9
Unscored
1
Pending Score
High-Impact Zero-Day Spotlight
UNKNOWN
2 months ago
CVE-2026-59237: by Roskus Prospero Flow CRM
Authorization Bypass Through User-Controlled Key (CWE-639) in the Order and OrderItem REST API controllers in Roskus Prospero Flow CRM before 5.5.3 allows a remote, authenticated user to read, modify, and delete orders and order items belonging to any other company (tenant) via a sequential numeric {id} supplied to GET /api/order/{id}, PUT /api/order/{id}, GET /api/order-item/{id}, PUT /api/order-item/{id}, or DELETE /api/order-item/{id}, because the controllers resolve records with Order::find($id) / Item::find($id) without scoping by the authenticated user's company.
Vendor: Roskus Prospero Flow CRM
Top Targeted Vendors & Stacks
RankedLatest Security Vulnerabilities
Explore FeedThreat News & Incidents
All Reports
HackerNews
1 month ago
Wallabag Full Disclosure CVSS8.5 Stored XSS+SSRF after no patched no cve
SecurityWeek
1 month ago
In Other News: Rapid7 Layoffs, Hacking a Boeing 737, Refrigeration System Vulnerabilities
SecurityWeek
1 month ago
Trivy, Not LiteLLM Behind the 2,500 Org Compromise
SecurityWeek
1 month ago
Google Cloud Sets Out Post-Quantum Roadmap With 2029 Readiness Goal
SecurityWeek
1 month ago
1.6 Million Likely Impacted by RingCentral Data Breach
SecurityWeek
1 month ago
Over 1,000 Charities Hit by Beacon CRM Data Breach
SecurityWeek
1 month ago
14,000 Trezor Customers Impacted by Data Breach at ShipMonk
HackerNews
1 month ago