Vulnerability index

Browse CVEs

38 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

HIGH 7.2 CVE-2025-26349 A CWE-23 "Relative Path Traversal" in the file upload mechanism in Q-Free MaxTime less than or equal to version 2.11.0 allows an authenticated remote… Maxtime after 2.11.0 Fix from $1,9502025-02-12 CRITICAL 9.8 CVE-2025-26339 A CWE-306 "Missing Authentication for Critical Function" in maxtime/handleRoute.lua in Q-Free MaxTime less than or equal to version 2.11.0 allows an … Maxtime after 2.11.0 Fix from $2,3002025-02-12 CRITICAL 9.8 CVE-2025-26341 A CWE-306 "Missing Authentication for Critical Function" in maxprofile/accounts/routes.lua in Q-Free MaxTime less than or equal to version 2.11.0 all… Maxtime after 2.11.0 Fix from $2,3002025-02-12 CRITICAL 9.8 CVE-2025-26342 A CWE-306 "Missing Authentication for Critical Function" in maxprofile/accounts/routes.lua in Q-Free MaxTime less than or equal to version 2.11.0 all… Maxtime after 2.11.0 Fix from $2,3002025-02-12 HIGH 8.8 CVE-2025-26340 A CWE-321 "Use of Hard-coded Cryptographic Key" in the JWT signing in Q-Free MaxTime less than or equal to version 2.11.0 allows an unauthenticated r… Maxtime after 2.11.0 Fix from $1,9502025-02-12 CRITICAL 9.8 CVE-2025-1100 A CWE-259 "Use of Hard-coded Password" for the root account in Q-Free MaxTime less than or equal to version 2.11.0 allows an unauthenticated remote a… Maxtime after 2.11.0 Fix from $2,3002025-02-12 HIGH 7.1 CVE-2025-1102 A CWE-346 "Origin Validation Error" in the CORS configuration in Q-Free MaxTime less than or equal to version 2.11.0 allows an unauthenticated remote… Maxtime after 2.11.0 Fix from $1,9502025-02-12 MEDIUM 5.3 CVE-2025-1101 A CWE-204 "Observable Response Discrepancy" in the login page in Q-Free MaxTime less than or equal to version 2.11.0 allows an unauthenticated remote… Maxtime after 2.11.0 Fix from $1,6002025-02-12