1121
|
- |
|
-
|
-
|
A CWE-306 "Missing Authentication for Critical Function" in maxprofile/setup/routes.lua in Q-Free MaxTime less than or equal to version 2.11.0 allows an unauthenticated remote attacker to disable fro…
|
CWE-306
Missing Authentication for Critical Function
|
CVE-2025-26366
|
2025-02-12 23:15 |
2025-02-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
1122
|
- |
|
-
|
-
|
A CWE-306 "Missing Authentication for Critical Function" in maxprofile/setup/routes.lua in Q-Free MaxTime less than or equal to version 2.11.0 allows an unauthenticated remote attacker to enable fron…
|
CWE-306
Missing Authentication for Critical Function
|
CVE-2025-26365
|
2025-02-12 23:15 |
2025-02-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
1123
|
- |
|
-
|
-
|
A CWE-306 "Missing Authentication for Critical Function" in maxprofile/setup/routes.lua in Q-Free MaxTime less than or equal to version 2.11.0 allows an unauthenticated remote attacker to disable an …
|
CWE-306
Missing Authentication for Critical Function
|
CVE-2025-26364
|
2025-02-12 23:15 |
2025-02-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
1124
|
- |
|
-
|
-
|
A CWE-306 "Missing Authentication for Critical Function" in maxprofile/setup/routes.lua in Q-Free MaxTime less than or equal to version 2.11.0 allows an unauthenticated remote attacker to enable an a…
|
CWE-306
Missing Authentication for Critical Function
|
CVE-2025-26363
|
2025-02-12 23:15 |
2025-02-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
1125
|
- |
|
-
|
-
|
A CWE-306 "Missing Authentication for Critical Function" in maxprofile/setup/routes.lua in Q-Free MaxTime less than or equal to version 2.11.0 allows an unauthenticated remote attacker to set an arbi…
|
CWE-306
Missing Authentication for Critical Function
|
CVE-2025-26362
|
2025-02-12 23:15 |
2025-02-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
1126
|
- |
|
-
|
-
|
A CWE-306 "Missing Authentication for Critical Function" in maxprofile/setup/routes.lua in Q-Free MaxTime less than or equal to version 2.11.0 allows an unauthenticated remote attacker to factory res…
|
CWE-306
Missing Authentication for Critical Function
|
CVE-2025-26361
|
2025-02-12 23:15 |
2025-02-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
1127
|
- |
|
-
|
-
|
A CWE-306 "Missing Authentication for Critical Function" in maxprofile/persistance/routes.lua in Q-Free MaxTime less than or equal to version 2.11.0 allows an unauthenticated remote attacker to delet…
|
CWE-306
Missing Authentication for Critical Function
|
CVE-2025-26360
|
2025-02-12 23:15 |
2025-02-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
1128
|
- |
|
-
|
-
|
A CWE-306 "Missing Authentication for Critical Function" in maxprofile/accounts/routes.lua in Q-Free MaxTime less than or equal to version 2.11.0 allows an unauthenticated remote attacker to reset us…
|
CWE-306
Missing Authentication for Critical Function
|
CVE-2025-26359
|
2025-02-12 23:15 |
2025-02-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
1129
|
- |
|
-
|
-
|
A CWE-20 "Improper Input Validation" in ldbMT.so in Q-Free MaxTime less than or equal to version 2.11.0 allows an authenticated remote attacker to modify system configuration via crafted HTTP request…
|
CWE-20
Improper Input Validation
|
CVE-2025-26358
|
2025-02-12 23:15 |
2025-02-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
1130
|
- |
|
-
|
-
|
A CWE-35 "Path Traversal" in maxtime/api/database/database.lua in Q-Free MaxTime less than or equal to version 2.11.0 allows an authenticated remote attacker to read sensitive files via crafted HTTP …
|
CWE-35
Path Traversal: '.../...//'
|
CVE-2025-26357
|
2025-02-12 23:15 |
2025-02-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|