Vulnerabilidades em pdovhomilja
4 resultadosCVE-2026-47129HIGHNextCRM has Broken Access Control in Server Actions that allows any authenticated user to deactivate/activate arbitrary accountsEPSS 0.2%CVE-2026-55550HIGHNextCRM has RBAC Bypass in MCP Product Tools that Allows Low-Privileged Users to Modify the CRM Product CatalogEPSS 0.2%CVE-2026-55544HIGHNextCRM has BOLA/IDOR in MCP Campaign Tools that Allows Cross-User Campaign Disclosure and TamperingEPSS 0.2%CVE-2026-47130HIGHNextCRM has a BOLA/IDOR in PATCH /api/crm/contacts/[id] that allows Cross-Tenant CRM Data TamperingEPSS 0.2%