Latest CVE Feed
-
7.5
HIGHCVE-2025-26364
A CWE-306 "Missing Authentication for Critical Function" in maxprofile/setup/routes.lua in Q-Free MaxTime less than or equal to version 2.11.0 allows an unauthenticated remote attacker to disable an authentication profile server via crafted HTTP requests.... Read more
Affected Products : maxtime- Published: Feb. 12, 2025
- Modified: Feb. 12, 2025
- Vuln Type: Authentication
-
7.5
HIGHCVE-2025-26363
A CWE-306 "Missing Authentication for Critical Function" in maxprofile/setup/routes.lua in Q-Free MaxTime less than or equal to version 2.11.0 allows an unauthenticated remote attacker to enable an authentication profile server via crafted HTTP requests.... Read more
Affected Products : maxtime- Published: Feb. 12, 2025
- Modified: Feb. 12, 2025
- Vuln Type: Authentication
-
7.5
HIGHCVE-2025-26362
A CWE-306 "Missing Authentication for Critical Function" in maxprofile/setup/routes.lua in Q-Free MaxTime less than or equal to version 2.11.0 allows an unauthenticated remote attacker to set an arbitrary authentication profile server via crafted HTTP req... Read more
Affected Products : maxtime- Published: Feb. 12, 2025
- Modified: Feb. 12, 2025
- Vuln Type: Authentication
-
9.1
CRITICALCVE-2025-26361
A CWE-306 "Missing Authentication for Critical Function" in maxprofile/setup/routes.lua in Q-Free MaxTime less than or equal to version 2.11.0 allows an unauthenticated remote attacker to factory reset the device via crafted HTTP requests.... Read more
Affected Products : maxtime- Published: Feb. 12, 2025
- Modified: Feb. 12, 2025
- Vuln Type: Authentication
-
5.3
MEDIUMCVE-2025-26360
A CWE-306 "Missing Authentication for Critical Function" in maxprofile/persistance/routes.lua in Q-Free MaxTime less than or equal to version 2.11.0 allows an unauthenticated remote attacker to delete dashboards via crafted HTTP requests.... Read more
Affected Products : maxtime- Published: Feb. 12, 2025
- Modified: Feb. 12, 2025
- Vuln Type: Authentication
-
9.8
CRITICALCVE-2025-26359
A CWE-306 "Missing Authentication for Critical Function" in maxprofile/accounts/routes.lua in Q-Free MaxTime less than or equal to version 2.11.0 allows an unauthenticated remote attacker to reset user PINs via crafted HTTP requests.... Read more
Affected Products : maxtime- Published: Feb. 12, 2025
- Modified: Feb. 12, 2025
- Vuln Type: Authentication
-
5.5
MEDIUMCVE-2025-26358
A CWE-20 "Improper Input Validation" in ldbMT.so in Q-Free MaxTime less than or equal to version 2.11.0 allows an authenticated remote attacker to modify system configuration via crafted HTTP requests.... Read more
Affected Products : maxtime- Published: Feb. 12, 2025
- Modified: Feb. 12, 2025
- Vuln Type: Misconfiguration
-
4.9
MEDIUMCVE-2025-26357
A CWE-35 "Path Traversal" in maxtime/api/database/database.lua in Q-Free MaxTime less than or equal to version 2.11.0 allows an authenticated remote attacker to read sensitive files via crafted HTTP requests.... Read more
Affected Products : maxtime- Published: Feb. 12, 2025
- Modified: Feb. 12, 2025
- Vuln Type: Path Traversal
-
7.2
HIGHCVE-2025-26356
A CWE-35 "Path Traversal" in maxtime/api/database/database.lua (setActive endpoint) in Q-Free MaxTime less than or equal to version 2.11.0 allows an authenticated remote attacker to overwrite sensitive files via crafted HTTP requests.... Read more
Affected Products : maxtime- Published: Feb. 12, 2025
- Modified: Feb. 12, 2025
- Vuln Type: Path Traversal
-
6.5
MEDIUMCVE-2025-26355
A CWE-35 "Path Traversal" in maxtime/api/database/database.lua in Q-Free MaxTime less than or equal to version 2.11.0 allows an authenticated remote attacker to delete sensitive files via crafted HTTP requests.... Read more
Affected Products : maxtime- Published: Feb. 12, 2025
- Modified: Feb. 12, 2025
- Vuln Type: Path Traversal
-
7.2
HIGHCVE-2025-26354
A CWE-35 "Path Traversal" in maxtime/api/database/database.lua (copy endpoint) in Q-Free MaxTime less than or equal to version 2.11.0 allows an authenticated remote attacker to overwrite sensitive files via crafted HTTP requests.... Read more
Affected Products : maxtime- Published: Feb. 12, 2025
- Modified: Feb. 12, 2025
- Vuln Type: Path Traversal
-
4.9
MEDIUMCVE-2025-26353
A CWE-35 "Path Traversal" in maxtime/api/sql/sql.lua in Q-Free MaxTime less than or equal to version 2.11.0 allows an authenticated remote attacker to read sensitive files via crafted HTTP requests.... Read more
Affected Products : maxtime- Published: Feb. 12, 2025
- Modified: Feb. 12, 2025
- Vuln Type: Path Traversal
-
6.5
MEDIUMCVE-2025-26352
A CWE-35 "Path Traversal" in the template deletion mechanism in Q-Free MaxTime less than or equal to version 2.11.0 allows an authenticated remote attacker to delete sensitive files via crafted HTTP requests.... Read more
Affected Products : maxtime- Published: Feb. 12, 2025
- Modified: Feb. 12, 2025
- Vuln Type: Path Traversal
-
4.9
MEDIUMCVE-2025-26351
A CWE-35 "Path Traversal" in the template download mechanism in Q-Free MaxTime less than or equal to version 2.11.0 allows an authenticated remote attacker to read sensitive files via crafted HTTP requests.... Read more
Affected Products : maxtime- Published: Feb. 12, 2025
- Modified: Feb. 12, 2025
- Vuln Type: Path Traversal
-
4.9
MEDIUMCVE-2025-26350
A CWE-434 "Unrestricted Upload of File with Dangerous Type" in the template file uploads in Q-Free MaxTime less than or equal to version 2.11.0 allows an authenticated remote attacker to upload malicious files via crafted HTTP requests.... Read more
Affected Products : maxtime- Published: Feb. 12, 2025
- Modified: Feb. 12, 2025
- Vuln Type: Misconfiguration
-
7.2
HIGHCVE-2025-26349
A CWE-23 "Relative Path Traversal" in the file upload mechanism in Q-Free MaxTime less than or equal to version 2.11.0 allows an authenticated remote attacker to overwrite arbitrary files via crafted HTTP requests.... Read more
Affected Products : maxtime- Published: Feb. 12, 2025
- Modified: Feb. 12, 2025
- Vuln Type: Path Traversal
-
5.5
MEDIUMCVE-2025-26348
A CWE-89 "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')" in maxprofile/menu/model.lua (editUserMenu endpoint) in Q-Free MaxTime less than or equal to version 2.11.0 allows an authenticated remote attacker to execute ... Read more
Affected Products : maxtime- Published: Feb. 12, 2025
- Modified: Feb. 12, 2025
- Vuln Type: Injection
-
9.8
CRITICALCVE-2025-26347
A CWE-306 "Missing Authentication for Critical Function" in maxprofile/menu/routes.lua in Q-Free MaxTime less than or equal to version 2.11.0 allows an unauthenticated remote attacker to edit user permissions via crafted HTTP requests.... Read more
Affected Products : maxtime- Published: Feb. 12, 2025
- Modified: Feb. 12, 2025
- Vuln Type: Authentication
-
5.5
MEDIUMCVE-2025-26346
A CWE-89 "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')" in maxprofile/menu/model.lua (editUserGroupMenu endpoint) in Q-Free MaxTime less than or equal to version 2.11.0 allows an authenticated remote attacker to exe... Read more
Affected Products : maxtime- Published: Feb. 12, 2025
- Modified: Feb. 12, 2025
- Vuln Type: Injection
-
9.8
CRITICALCVE-2025-26345
A CWE-306 "Missing Authentication for Critical Function" in maxprofile/menu/routes.lua in Q-Free MaxTime less than or equal to version 2.11.0 allows an unauthenticated remote attacker to edit user group permissions via crafted HTTP requests.... Read more
Affected Products : maxtime- Published: Feb. 12, 2025
- Modified: Feb. 18, 2025
- Vuln Type: Authentication