NA - CVE-2025-26370 - A CWE-862 "Missing Authorization" in...
A CWE-862 "Missing Authorization" in maxprofile/user-groups/routes.lua in Q-Free MaxTime less than or equal to version 2.11.0 allows an authenticated (low-privileged) attacker to remove privileges...
NA - CVE-2025-26371 - A CWE-862 "Missing Authorization" in...
A CWE-862 "Missing Authorization" in maxprofile/user-groups/routes.lua in Q-Free MaxTime less than or equal to version 2.11.0 allows an authenticated (low-privileged) attacker to add users to...
NA - CVE-2025-26372 - A CWE-862 "Missing Authorization" in...
A CWE-862 "Missing Authorization" in maxprofile/user-groups/routes.lua in Q-Free MaxTime less than or equal to version 2.11.0 allows an authenticated (low-privileged) attacker to remove users from...
NA - CVE-2025-26373 - A CWE-862 "Missing Authorization" in...
A CWE-862 "Missing Authorization" in maxprofile/users/routes.lua (user endpoint) in Q-Free MaxTime less than or equal to version 2.11.0 allows an authenticated (low-privileged) attacker to...
NA - CVE-2025-26374 - A CWE-862 "Missing Authorization" in...
A CWE-862 "Missing Authorization" in maxprofile/users/routes.lua (users endpoint) in Q-Free MaxTime less than or equal to version 2.11.0 allows an authenticated (low-privileged) attacker to...
NA - CVE-2025-26375 - A CWE-862 "Missing Authorization" in...
A CWE-862 "Missing Authorization" in maxprofile/users/routes.lua in Q-Free MaxTime less than or equal to version 2.11.0 allows an authenticated (low-privileged) attacker to create users with...
NA - CVE-2025-26376 - A CWE-862 "Missing Authorization" in...
A CWE-862 "Missing Authorization" in maxprofile/users/routes.lua in Q-Free MaxTime less than or equal to version 2.11.0 allows an authenticated (low-privileged) attacker to modify user data via...
NA - CVE-2025-26377 - A CWE-862 "Missing Authorization" in...
A CWE-862 "Missing Authorization" in maxprofile/users/routes.lua in Q-Free MaxTime less than or equal to version 2.11.0 allows an authenticated (low-privileged) attacker to remove users via crafted...
NA - CVE-2025-26378 - A CWE-862 "Missing Authorization" in...
A CWE-862 "Missing Authorization" in maxprofile/users/routes.lua in Q-Free MaxTime less than or equal to version 2.11.0 allows an authenticated (low-privileged) attacker to reset passwords,...
NA - CVE-2024-12251 - In Progress® Telerik® UI for WinUI versions...
In Progress® Telerik® UI for WinUI versions prior to 2025 Q1 (3.0.0), a command injection attack is possible through improper neutralization of hyperlink elements.