CVE Feed

    Dashboard / CVE

    8.8
    High

    CVE-2025-26375

    Last Modified: 10 Apr 2025

    A CWE-862 "Missing Authorization" in maxprofile/users/routes.lua in Q-Free MaxTime less than or equal to version 2.11.0 allows an authenticated (low-privileged) attacker to create users with arbitrary privileges via crafted HTTP requests.

    Published: 12 Feb 2025
    6.5
    Medium

    CVE-2025-26374

    Last Modified: 12 Jul 2025

    A CWE-862 "Missing Authorization" in maxprofile/users/routes.lua (users endpoint) in Q-Free MaxTime less than or equal to version 2.11.0 allows an authenticated (low-privileged) attacker to enumerate users via crafted HTTP requests.

    Published: 12 Feb 2025
    6.5
    Medium

    CVE-2025-26373

    Last Modified: 28 Oct 2025

    A CWE-862 "Missing Authorization" in maxprofile/users/routes.lua (user endpoint) in Q-Free MaxTime less than or equal to version 2.11.0 allows an authenticated (low-privileged) attacker to enumerate users via crafted HTTP requests.

    Published: 12 Feb 2025
    7.1
    High

    CVE-2025-26372

    Last Modified: 13 Jul 2025

    A CWE-862 "Missing Authorization" in maxprofile/user-groups/routes.lua in Q-Free MaxTime less than or equal to version 2.11.0 allows an authenticated (low-privileged) attacker to remove users from groups via crafted HTTP requests.

    Published: 12 Feb 2025
    8.8
    High

    CVE-2025-26371

    Last Modified: 10 Apr 2025

    A CWE-862 "Missing Authorization" in maxprofile/user-groups/routes.lua in Q-Free MaxTime less than or equal to version 2.11.0 allows an authenticated (low-privileged) attacker to add users to groups via crafted HTTP requests.

    Published: 12 Feb 2025
    7.1
    High

    CVE-2025-26370

    Last Modified: 28 Oct 2025

    A CWE-862 "Missing Authorization" in maxprofile/user-groups/routes.lua in Q-Free MaxTime less than or equal to version 2.11.0 allows an authenticated (low-privileged) attacker to remove privileges from user groups via crafted HTTP requests.

    Published: 12 Feb 2025
    8.8
    High

    CVE-2025-26369

    Last Modified: 27 May 2025

    A CWE-862 "Missing Authorization" in maxprofile/user-groups/routes.lua in Q-Free MaxTime less than or equal to version 2.11.0 allows an authenticated (low-privileged) attacker to add privileges to user groups via crafted HTTP requests.

    Published: 12 Feb 2025
    8.1
    High

    CVE-2025-26368

    Last Modified: 10 Apr 2025

    A CWE-862 "Missing Authorization" in maxprofile/user-groups/routes.lua in Q-Free MaxTime less than or equal to version 2.11.0 allows an authenticated (low-privileged) attacker to remove user groups via crafted HTTP requests.

    Published: 12 Feb 2025
    4.3
    Medium

    CVE-2025-26367

    Last Modified: 10 Apr 2025

    A CWE-862 "Missing Authorization" in maxprofile/user-groups/routes.lua in Q-Free MaxTime less than or equal to version 2.11.0 allows an authenticated (low-privileged) attacker to create arbitrary user groups via crafted HTTP requests.

    Published: 12 Feb 2025
    7.5
    High

    CVE-2025-26366

    Last Modified: 28 Oct 2025

    A CWE-306 "Missing Authentication for Critical Function" in maxprofile/setup/routes.lua in Q-Free MaxTime less than or equal to version 2.11.0 allows an unauthenticated remote attacker to disable front panel authentication via crafted HTTP requests.

    Published: 12 Feb 2025
    7.5
    High

    CVE-2025-26365

    Last Modified: 28 Oct 2025

    A CWE-306 "Missing Authentication for Critical Function" in maxprofile/setup/routes.lua in Q-Free MaxTime less than or equal to version 2.11.0 allows an unauthenticated remote attacker to enable front panel authentication via crafted HTTP requests.

    Published: 12 Feb 2025
    7.5
    High

    CVE-2025-26364

    Last Modified: 28 Oct 2025

    A CWE-306 "Missing Authentication for Critical Function" in maxprofile/setup/routes.lua in Q-Free MaxTime less than or equal to version 2.11.0 allows an unauthenticated remote attacker to disable an authentication profile server via crafted HTTP requests.

    Published: 12 Feb 2025
    7.5
    High

    CVE-2025-26363

    Last Modified: 28 Oct 2025

    A CWE-306 "Missing Authentication for Critical Function" in maxprofile/setup/routes.lua in Q-Free MaxTime less than or equal to version 2.11.0 allows an unauthenticated remote attacker to enable an authentication profile server via crafted HTTP requests.

    Published: 12 Feb 2025
    7.5
    High

    CVE-2025-26362

    Last Modified: 28 Oct 2025

    A CWE-306 "Missing Authentication for Critical Function" in maxprofile/setup/routes.lua in Q-Free MaxTime less than or equal to version 2.11.0 allows an unauthenticated remote attacker to set an arbitrary authentication profile server via crafted HTTP requests.

    Published: 12 Feb 2025
    9.1
    Critical

    CVE-2025-26361

    Last Modified: 28 Oct 2025

    A CWE-306 "Missing Authentication for Critical Function" in maxprofile/setup/routes.lua in Q-Free MaxTime less than or equal to version 2.11.0 allows an unauthenticated remote attacker to factory reset the device via crafted HTTP requests.

    Published: 12 Feb 2025
    5.3
    Medium

    CVE-2025-26360

    Last Modified: 28 Oct 2025

    A CWE-306 "Missing Authentication for Critical Function" in maxprofile/persistance/routes.lua in Q-Free MaxTime less than or equal to version 2.11.0 allows an unauthenticated remote attacker to delete dashboards via crafted HTTP requests.

    Published: 12 Feb 2025
    9.8
    Critical

    CVE-2025-26359

    Last Modified: 28 Oct 2025

    A CWE-306 "Missing Authentication for Critical Function" in maxprofile/accounts/routes.lua in Q-Free MaxTime less than or equal to version 2.11.0 allows an unauthenticated remote attacker to reset user PINs via crafted HTTP requests.

    Published: 12 Feb 2025
    5.5
    Medium

    CVE-2025-26358

    Last Modified: 28 Oct 2025

    A CWE-15 "External Control of System or Configuration Setting" in ldbMT.so in Q-Free MaxTime less than or equal to version 2.11.0 allows an authenticated remote attacker to modify system configuration via crafted HTTP requests.

    Published: 12 Feb 2025
    4.9
    Medium

    CVE-2025-26357

    Last Modified: 28 Oct 2025

    A CWE-35 "Path Traversal" in maxtime/api/database/database.lua in Q-Free MaxTime less than or equal to version 2.11.0 allows an authenticated remote attacker to read sensitive files via crafted HTTP requests.

    Published: 12 Feb 2025
    7.2
    High

    CVE-2025-26356

    Last Modified: 28 Oct 2025

    A CWE-35 "Path Traversal" in maxtime/api/database/database.lua (setActive endpoint) in Q-Free MaxTime less than or equal to version 2.11.0 allows an authenticated remote attacker to overwrite sensitive files via crafted HTTP requests.

    Published: 12 Feb 2025
    6.5
    Medium

    CVE-2025-26355

    Last Modified: 28 Oct 2025

    A CWE-35 "Path Traversal" in maxtime/api/database/database.lua in Q-Free MaxTime less than or equal to version 2.11.0 allows an authenticated remote attacker to delete sensitive files via crafted HTTP requests.

    Published: 12 Feb 2025
    7.2
    High

    CVE-2025-26354

    Last Modified: 28 Oct 2025

    A CWE-35 "Path Traversal" in maxtime/api/database/database.lua (copy endpoint) in Q-Free MaxTime less than or equal to version 2.11.0 allows an authenticated remote attacker to overwrite sensitive files via crafted HTTP requests.

    Published: 12 Feb 2025
    4.9
    Medium

    CVE-2025-26353

    Last Modified: 28 Oct 2025

    A CWE-35 "Path Traversal" in maxtime/api/sql/sql.lua in Q-Free MaxTime less than or equal to version 2.11.0 allows an authenticated remote attacker to read sensitive files via crafted HTTP requests.

    Published: 12 Feb 2025
    6.5
    Medium

    CVE-2025-26352

    Last Modified: 28 Oct 2025

    A CWE-35 "Path Traversal" in the template deletion mechanism in Q-Free MaxTime less than or equal to version 2.11.0 allows an authenticated remote attacker to delete sensitive files via crafted HTTP requests.

    Published: 12 Feb 2025
    4.9
    Medium

    CVE-2025-26351

    Last Modified: 24 Oct 2025

    A CWE-35 "Path Traversal" in the template download mechanism in Q-Free MaxTime less than or equal to version 2.11.0 allows an authenticated remote attacker to read sensitive files via crafted HTTP requests.

    Published: 12 Feb 2025
    4.9
    Medium

    CVE-2025-26350

    Last Modified: 24 Oct 2025

    A CWE-434 "Unrestricted Upload of File with Dangerous Type" in the template file uploads in Q-Free MaxTime less than or equal to version 2.11.0 allows an authenticated remote attacker to upload malicious files via crafted HTTP requests.

    Published: 12 Feb 2025
    7.2
    High

    CVE-2025-26349

    Last Modified: 24 Oct 2025

    A CWE-23 "Relative Path Traversal" in the file upload mechanism in Q-Free MaxTime less than or equal to version 2.11.0 allows an authenticated remote attacker to overwrite arbitrary files via crafted HTTP requests.

    Published: 12 Feb 2025
    5.5
    Medium

    CVE-2025-26348

    Last Modified: 24 Oct 2025

    A CWE-89 "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')" in maxprofile/menu/model.lua (editUserMenu endpoint) in Q-Free MaxTime less than or equal to version 2.11.0 allows an authenticated remote attacker to execute arbitrary SQL commands via crafted HTTP requests.

    Published: 12 Feb 2025
    9.8
    Critical

    CVE-2025-26347

    Last Modified: 24 Oct 2025

    A CWE-306 "Missing Authentication for Critical Function" in maxprofile/menu/routes.lua in Q-Free MaxTime less than or equal to version 2.11.0 allows an unauthenticated remote attacker to edit user permissions via crafted HTTP requests.

    Published: 12 Feb 2025
    5.5
    Medium

    CVE-2025-26346

    Last Modified: 24 Oct 2025

    A CWE-89 "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')" in maxprofile/menu/model.lua (editUserGroupMenu endpoint) in Q-Free MaxTime less than or equal to version 2.11.0 allows an authenticated remote attacker to execute arbitrary SQL commands via crafted HTTP requests.

    Published: 12 Feb 2025
    9.8
    Critical

    CVE-2025-26345

    Last Modified: 24 Oct 2025

    A CWE-306 "Missing Authentication for Critical Function" in maxprofile/menu/routes.lua in Q-Free MaxTime less than or equal to version 2.11.0 allows an unauthenticated remote attacker to edit user group permissions via crafted HTTP requests.

    Published: 12 Feb 2025
    9.8
    Critical

    CVE-2025-26344

    Last Modified: 24 Oct 2025

    A CWE-306 "Missing Authentication for Critical Function" in maxprofile/guest-mode/routes.lua in Q-Free MaxTime less than or equal to version 2.11.0 allows an unauthenticated remote attacker to enable passwordless guest mode via crafted HTTP requests.

    Published: 12 Feb 2025
    8.1
    High

    CVE-2025-26343

    Last Modified: 24 Oct 2025

    A CWE-1390 "Weak Authentication" in the PIN authentication mechanism in Q-Free MaxTime less than or equal to version 2.11.0 allows an unauthenticated remote attacker to brute-force user PINs via multiple crafted HTTP requests.

    Published: 12 Feb 2025
    9.8
    Critical

    CVE-2025-26342

    Last Modified: 24 Oct 2025

    A CWE-306 "Missing Authentication for Critical Function" in maxprofile/accounts/routes.lua in Q-Free MaxTime less than or equal to version 2.11.0 allows an unauthenticated remote attacker to create arbitrary users, including administrators, via crafted HTTP requests.

    Published: 12 Feb 2025
    9.8
    Critical

    CVE-2025-26341

    Last Modified: 24 Oct 2025

    A CWE-306 "Missing Authentication for Critical Function" in maxprofile/accounts/routes.lua in Q-Free MaxTime less than or equal to version 2.11.0 allows an unauthenticated remote attacker to reset arbitrary user passwords via crafted HTTP requests.

    Published: 12 Feb 2025
    8.8
    High

    CVE-2025-26340

    Last Modified: 24 Oct 2025

    A CWE-321 "Use of Hard-coded Cryptographic Key" in the JWT signing in Q-Free MaxTime less than or equal to version 2.11.0 allows an unauthenticated remote attacker to bypass the authentication via crafted HTTP requests.

    Published: 12 Feb 2025
    9.8
    Critical

    CVE-2025-26339

    Last Modified: 24 Oct 2025

    A CWE-306 "Missing Authentication for Critical Function" in maxtime/handleRoute.lua in Q-Free MaxTime less than or equal to version 2.11.0 allows an unauthenticated remote attacker to affect the device confidentiality, integrity, or availability in multiple unspecified ways via crafted HTTP requests.

    Published: 12 Feb 2025
    5.5
    Medium

    CVE-2025-1102

    Last Modified: 24 Oct 2025

    A CWE-346 "Origin Validation Error" in the CORS configuration in Q-Free MaxTime less than or equal to version 2.11.0 allows an unauthenticated remote attacker to affect the device confidentiality, integrity, or availability via crafted URLs or HTTP requests.

    Published: 12 Feb 2025
    5.3
    Medium

    CVE-2025-1101

    Last Modified: 24 Oct 2025

    A CWE-204 "Observable Response Discrepancy" in the login page in Q-Free MaxTime less than or equal to version 2.11.0 allows an unauthenticated remote attacker to enumerate valid usernames via crafted HTTP requests.

    Published: 12 Feb 2025
    9.8
    Critical

    CVE-2025-1100

    Last Modified: 24 Oct 2025

    A CWE-259 "Use of Hard-coded Password" for the root account in Q-Free MaxTime less than or equal to version 2.11.0 allows an unauthenticated remote attacker to execute arbitrary code with root privileges via SSH.

    Published: 12 Feb 2025
    5.3
    Medium

    CVE-2025-1199

    Last Modified: 18 Feb 2025

    A vulnerability was found in SourceCodester Best Church Management Software 1.1. It has been classified as critical. This affects an unknown part of the file /admin/app/role_crud.php. The manipulation of the argument id leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.

    Published: 12 Feb 2025
    5.3
    Medium

    CVE-2025-1197

    Last Modified: 23 Oct 2025

    A vulnerability has been found in code-projects Real Estate Property Management System 1.0 and classified as critical. Affected by this vulnerability is an unknown functionality of the file /_parse/load_user-profile.php. The manipulation of the argument userhash leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.

    Published: 12 Feb 2025
    6.4
    Medium

    CVE-2024-10322

    Last Modified: 8 Apr 2026

    The Brizy – Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via REST API SVG File uploads in all versions up to, and including, 2.6.8 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Author-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses the SVG file.

    Published: 12 Feb 2025
    7.1
    High

    CVE-2024-11629

    Last Modified: 19 Feb 2025

    In Progress® Telerik® Document Processing Libraries, versions prior to 2025 Q1 (2025.1.205), using .NET Standard 2.0, the contents of a file at an arbitrary path can be exported to RTF.

    Published: 12 Feb 2025
    4.1
    Medium

    CVE-2024-11628

    Last Modified: 27 Jun 2025

    In Progress® Telerik® Kendo UI for Vue versions v2.4.0 through v6.0.1, an attacker can introduce or modify properties within the global prototype chain which can result in denial of service or command injection.

    Published: 12 Feb 2025
    5.1
    Medium

    CVE-2025-1196

    Last Modified: 20 Feb 2025

    A vulnerability, which was classified as problematic, was found in code-projects Real Estate Property Management System 1.0. Affected is an unknown function of the file /search.php. The manipulation of the argument PropertyName leads to cross site scripting. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. Other parameters might be affected as well.

    Published: 12 Feb 2025
    8.3
    High

    CVE-2024-11343

    Last Modified: 20 Feb 2025

    In Progress® Telerik® Document Processing Libraries, versions prior to 2025 Q1 (2025.1.205), unzipping an archive can lead to arbitrary file system access.

    Published: 12 Feb 2025
    4.1
    Medium

    CVE-2024-12629

    Last Modified: 27 Jun 2025

    In Progress® Telerik® KendoReact versions v3.5.0 through v9.4.0, an attacker can introduce or modify properties within the global prototype chain which can result in denial of service or command injection.

    Published: 12 Feb 2025
    5.1
    Medium

    CVE-2025-1195

    Last Modified: 20 Feb 2025

    A vulnerability, which was classified as problematic, has been found in code-projects Real Estate Property Management System 1.0. This issue affects some unknown processing of the file /Admin/EditCategory. The manipulation of the argument CategoryId leads to cross site scripting. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.

    Published: 12 Feb 2025
    8.1
    High

    CVE-2024-12386

    Last Modified: 8 Apr 2026

    The WP Abstracts plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.7.3. This is due to missing nonce validation on multiple functions. This makes it possible for unauthenticated attackers to delete arbitrary accounts via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.

    Published: 12 Feb 2025