711
|
- |
|
-
|
-
|
A CWE-306 "Missing Authentication for Critical Function" in maxprofile/setup/routes.lua in Q-Free MaxTime less than or equal to version 2.11.0 allows an unauthenticated remote attacker to enable fron…
|
CWE-306
Missing Authentication for Critical Function
|
CVE-2025-26365
|
2025-02-12 23:15 |
2025-02-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
712
|
- |
|
-
|
-
|
A CWE-306 "Missing Authentication for Critical Function" in maxprofile/setup/routes.lua in Q-Free MaxTime less than or equal to version 2.11.0 allows an unauthenticated remote attacker to disable an …
|
CWE-306
Missing Authentication for Critical Function
|
CVE-2025-26364
|
2025-02-12 23:15 |
2025-02-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
713
|
- |
|
-
|
-
|
A CWE-306 "Missing Authentication for Critical Function" in maxprofile/setup/routes.lua in Q-Free MaxTime less than or equal to version 2.11.0 allows an unauthenticated remote attacker to enable an a…
|
CWE-306
Missing Authentication for Critical Function
|
CVE-2025-26363
|
2025-02-12 23:15 |
2025-02-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
714
|
- |
|
-
|
-
|
A CWE-306 "Missing Authentication for Critical Function" in maxprofile/setup/routes.lua in Q-Free MaxTime less than or equal to version 2.11.0 allows an unauthenticated remote attacker to set an arbi…
|
CWE-306
Missing Authentication for Critical Function
|
CVE-2025-26362
|
2025-02-12 23:15 |
2025-02-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
715
|
- |
|
-
|
-
|
A CWE-306 "Missing Authentication for Critical Function" in maxprofile/setup/routes.lua in Q-Free MaxTime less than or equal to version 2.11.0 allows an unauthenticated remote attacker to factory res…
|
CWE-306
Missing Authentication for Critical Function
|
CVE-2025-26361
|
2025-02-12 23:15 |
2025-02-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
716
|
- |
|
-
|
-
|
A CWE-306 "Missing Authentication for Critical Function" in maxprofile/persistance/routes.lua in Q-Free MaxTime less than or equal to version 2.11.0 allows an unauthenticated remote attacker to delet…
|
CWE-306
Missing Authentication for Critical Function
|
CVE-2025-26360
|
2025-02-12 23:15 |
2025-02-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
717
|
- |
|
-
|
-
|
A CWE-306 "Missing Authentication for Critical Function" in maxprofile/accounts/routes.lua in Q-Free MaxTime less than or equal to version 2.11.0 allows an unauthenticated remote attacker to reset us…
|
CWE-306
Missing Authentication for Critical Function
|
CVE-2025-26359
|
2025-02-12 23:15 |
2025-02-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
718
|
- |
|
-
|
-
|
A CWE-20 "Improper Input Validation" in ldbMT.so in Q-Free MaxTime less than or equal to version 2.11.0 allows an authenticated remote attacker to modify system configuration via crafted HTTP request…
|
CWE-20
Improper Input Validation
|
CVE-2025-26358
|
2025-02-12 23:15 |
2025-02-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
719
|
- |
|
-
|
-
|
A CWE-35 "Path Traversal" in maxtime/api/database/database.lua in Q-Free MaxTime less than or equal to version 2.11.0 allows an authenticated remote attacker to read sensitive files via crafted HTTP …
|
CWE-35
Path Traversal: '.../...//'
|
CVE-2025-26357
|
2025-02-12 23:15 |
2025-02-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
720
|
- |
|
-
|
-
|
A CWE-35 "Path Traversal" in maxtime/api/database/database.lua (setActive endpoint) in Q-Free MaxTime less than or equal to version 2.11.0 allows an authenticated remote attacker to overwrite sensiti…
|
CWE-35
Path Traversal: '.../...//'
|
CVE-2025-26356
|
2025-02-12 23:15 |
2025-02-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|