Vulnerabilities
CVE-2026-28685 - Kimai: API invoice endpoint missing customer-level access control (IDOR)
2026-03-06
0 views
admin
CVE ID : CVE-2026-28685 Published : March 6, 2026, 5:16 a.m. | 35 minutes ago Description : Kimai is a web-based multi-user time-tracking application. Prior to version 2.51.0,
CVE Details
CVE ID
Published
March 6, 2026
🏷️ Tags
28685kimaiinvoiceendpointmissingcustomerlevelaccesscontrolcve
More from Vulnerabilities
Report: Essential Guide: CVE-2026-6951 - SimpleGit Remote Code Execution (RCE)
2026-04-25
0
Report: - Deskflow: Local privilege escalation via unauthenticated IPC CVE-2026-41477
2026-04-25
0
Report: CVE-2026-41475 - BACnet Stack: Out-of-Bounds Read in WritePropertyMultiple Decoder via Deprecated...
2026-04-25
0
Report: CVE-2026-6966 - Signature Threshold Bypass in awslabs/tough Delegated Roles - Full Analysis
2026-04-25
0
Trending
1
CVE-2025-61481: Critical Remote Code Execution Vulnerability in MikroTik RouterOS & SwitchOS
2025-10-27 • 189 views
2
CVE-2025-43939: Dell Unity OS Command Injection (High)
2025-10-30 • 148 views
3
Google disputes false claims of massive Gmail data breach
2025-10-30 • 130 views
4
Microsoft: DNS outage impacts Azure and Microsoft 365 services
2025-10-30 • 88 views
5
3.5B Accounts, 1 Critical Flaw: Meta Closes WhatsApp Data-Harvesting
2025-11-25 • 81 views