701
|
- |
|
-
|
-
|
A CWE-862 "Missing Authorization" in maxprofile/users/routes.lua in Q-Free MaxTime less than or equal to version 2.11.0 allows an authenticated (low-privileged) attacker to create users with arbitrar…
|
CWE-862
Missing Authorization
|
CVE-2025-26375
|
2025-02-12 23:15 |
2025-02-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
702
|
- |
|
-
|
-
|
A CWE-862 "Missing Authorization" in maxprofile/users/routes.lua (users endpoint) in Q-Free MaxTime less than or equal to version 2.11.0 allows an authenticated (low-privileged) attacker to enumerate…
|
CWE-862
Missing Authorization
|
CVE-2025-26374
|
2025-02-12 23:15 |
2025-02-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
703
|
- |
|
-
|
-
|
A CWE-862 "Missing Authorization" in maxprofile/users/routes.lua (user endpoint) in Q-Free MaxTime less than or equal to version 2.11.0 allows an authenticated (low-privileged) attacker to enumerate …
|
CWE-862
Missing Authorization
|
CVE-2025-26373
|
2025-02-12 23:15 |
2025-02-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
704
|
- |
|
-
|
-
|
A CWE-862 "Missing Authorization" in maxprofile/user-groups/routes.lua in Q-Free MaxTime less than or equal to version 2.11.0 allows an authenticated (low-privileged) attacker to remove users from gr…
|
CWE-862
Missing Authorization
|
CVE-2025-26372
|
2025-02-12 23:15 |
2025-02-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
705
|
- |
|
-
|
-
|
A CWE-862 "Missing Authorization" in maxprofile/user-groups/routes.lua in Q-Free MaxTime less than or equal to version 2.11.0 allows an authenticated (low-privileged) attacker to add users to groups …
|
CWE-862
Missing Authorization
|
CVE-2025-26371
|
2025-02-12 23:15 |
2025-02-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
706
|
- |
|
-
|
-
|
A CWE-862 "Missing Authorization" in maxprofile/user-groups/routes.lua in Q-Free MaxTime less than or equal to version 2.11.0 allows an authenticated (low-privileged) attacker to remove privileges fr…
|
CWE-862
Missing Authorization
|
CVE-2025-26370
|
2025-02-12 23:15 |
2025-02-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
707
|
- |
|
-
|
-
|
A CWE-862 "Missing Authorization" in maxprofile/user-groups/routes.lua in Q-Free MaxTime less than or equal to version 2.11.0 allows an authenticated (low-privileged) attacker to add privileges to us…
|
CWE-862
Missing Authorization
|
CVE-2025-26369
|
2025-02-12 23:15 |
2025-02-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
708
|
- |
|
-
|
-
|
A CWE-862 "Missing Authorization" in maxprofile/user-groups/routes.lua in Q-Free MaxTime less than or equal to version 2.11.0 allows an authenticated (low-privileged) attacker to remove user groups v…
|
CWE-862
Missing Authorization
|
CVE-2025-26368
|
2025-02-12 23:15 |
2025-02-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
709
|
- |
|
-
|
-
|
A CWE-862 "Missing Authorization" in maxprofile/user-groups/routes.lua in Q-Free MaxTime less than or equal to version 2.11.0 allows an authenticated (low-privileged) attacker to create arbitrary use…
|
CWE-862
Missing Authorization
|
CVE-2025-26367
|
2025-02-12 23:15 |
2025-02-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
710
|
- |
|
-
|
-
|
A CWE-306 "Missing Authentication for Critical Function" in maxprofile/setup/routes.lua in Q-Free MaxTime less than or equal to version 2.11.0 allows an unauthenticated remote attacker to disable fro…
|
CWE-306
Missing Authentication for Critical Function
|
CVE-2025-26366
|
2025-02-12 23:15 |
2025-02-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|