Vulnerability index

Browse CVEs

38 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Maxtime HIGH 7.2
CVE-2025-26349

A CWE-23 "Relative Path Traversal" in the file upload mechanism in Q-Free MaxTime less than or equal to version 2.11.0 allows an authenticated remote…

Fix: after 2.11.0
Fix from $1,950 2025-02-12
Maxtime CRITICAL 9.8
CVE-2025-26339

A CWE-306 "Missing Authentication for Critical Function" in maxtime/handleRoute.lua in Q-Free MaxTime less than or equal to version 2.11.0 allows an …

Fix: after 2.11.0
Fix from $2,300 2025-02-12
Maxtime CRITICAL 9.8
CVE-2025-26341

A CWE-306 "Missing Authentication for Critical Function" in maxprofile/accounts/routes.lua in Q-Free MaxTime less than or equal to version 2.11.0 all…

Fix: after 2.11.0
Fix from $2,300 2025-02-12
Maxtime CRITICAL 9.8
CVE-2025-26342

A CWE-306 "Missing Authentication for Critical Function" in maxprofile/accounts/routes.lua in Q-Free MaxTime less than or equal to version 2.11.0 all…

Fix: after 2.11.0
Fix from $2,300 2025-02-12
Maxtime HIGH 8.8
CVE-2025-26340

A CWE-321 "Use of Hard-coded Cryptographic Key" in the JWT signing in Q-Free MaxTime less than or equal to version 2.11.0 allows an unauthenticated r…

Fix: after 2.11.0
Fix from $1,950 2025-02-12
Maxtime CRITICAL 9.8
CVE-2025-1100

A CWE-259 "Use of Hard-coded Password" for the root account in Q-Free MaxTime less than or equal to version 2.11.0 allows an unauthenticated remote a…

Fix: after 2.11.0
Fix from $2,300 2025-02-12
Maxtime HIGH 7.1
CVE-2025-1102

A CWE-346 "Origin Validation Error" in the CORS configuration in Q-Free MaxTime less than or equal to version 2.11.0 allows an unauthenticated remote…

Fix: after 2.11.0
Fix from $1,950 2025-02-12
Maxtime MEDIUM 5.3
CVE-2025-1101

A CWE-204 "Observable Response Discrepancy" in the login page in Q-Free MaxTime less than or equal to version 2.11.0 allows an unauthenticated remote…

Fix: after 2.11.0
Fix from $1,600 2025-02-12