Vulmon
Recent Vulnerabilities
Product List
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
CVE-2025-26378 vulnerabilities and exploits
(subscribe to this query)
8.8
CVSSv3
CVE-2025-26378
A CWE-862 "Missing Authorization" in maxprofile/users/routes.lua in Q-Free MaxTime less than or equal to version 2.11.0 allows an authenticated (low-privileged) malicious user to reset passwords, including the ones of administrator accounts, via crafted HTTP requests.
Q-free Maxtime
Preferred Score:
CVSSv3
CVSSv2
CVSSv3
CVSSv4
EPSS
VMScore
Recommendations:
CVE-2024-9182
CVE-2025-4761
CVE-2025-1289
XML injection
d-link
CVE-2025-4427
camera
local
genesis64
ibm
CVE-2025-47161
spotipy
CVE-2023-21563
Home
/
Search Results
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started