q-free CVE Vulnerabilities & Metrics

Focus on q-free vulnerabilities and metrics.

Last updated: 25 Nov 2025, 23:25 UTC

About q-free Security Exposure

This page consolidates all known Common Vulnerabilities and Exposures (CVEs) associated with q-free. We track both calendar-based metrics (using fixed periods) and rolling metrics (using gliding windows) to give you a comprehensive view of security trends and risk evolution. Use these insights to assess risk and plan your patching strategy.

For a broader perspective on cybersecurity threats, explore the comprehensive list of CVEs by vendor and product. Stay updated on critical vulnerabilities affecting major software and hardware providers.

Global CVE Overview

Total q-free CVEs: 18
Earliest CVE date: 12 Feb 2025, 14:15 UTC
Latest CVE date: 12 Feb 2025, 14:15 UTC

Latest CVE reference: CVE-2025-26377

Rolling Stats

30-day Count (Rolling): 0
365-day Count (Rolling): 18

Calendar-based Variation

Calendar-based Variation compares a fixed calendar period (e.g., this month versus the same month last year), while Rolling Growth Rate uses a continuous window (e.g., last 30 days versus the previous 30 days) to capture trends independent of calendar boundaries.

Variations & Growth

Month Variation (Calendar): 0%
Year Variation (Calendar): 0%

Month Growth Rate (30-day Rolling): 0.0%
Year Growth Rate (365-day Rolling): 0.0%

Monthly CVE Trends (current vs previous Year)

Annual CVE Trends (Last 20 Years)

Critical q-free CVEs (CVSS ≥ 9) Over 20 Years

CVSS Stats

Average CVSS: 0.0

Max CVSS: 0

Critical CVEs (≥9): 0

CVSS Range vs. Count

Range Count
0.0-3.9 18
4.0-6.9 0
7.0-8.9 0
9.0-10.0 0

CVSS Distribution Chart

Top 5 Highest CVSS q-free CVEs

These are the five CVEs with the highest CVSS scores for q-free, sorted by severity first and recency.

All CVEs for q-free

CVE-2025-26377 q-free vulnerability CVSS: 0 12 Feb 2025, 14:15 UTC

A CWE-862 "Missing Authorization" in maxprofile/users/routes.lua in Q-Free MaxTime less than or equal to version 2.11.0 allows an authenticated (low-privileged) attacker to remove users via crafted HTTP requests.

CVE-2025-26373 q-free vulnerability CVSS: 0 12 Feb 2025, 14:15 UTC

A CWE-862 "Missing Authorization" in maxprofile/users/routes.lua (user endpoint) in Q-Free MaxTime less than or equal to version 2.11.0 allows an authenticated (low-privileged) attacker to enumerate users via crafted HTTP requests.

CVE-2025-26370 q-free vulnerability CVSS: 0 12 Feb 2025, 14:15 UTC

A CWE-862 "Missing Authorization" in maxprofile/user-groups/routes.lua in Q-Free MaxTime less than or equal to version 2.11.0 allows an authenticated (low-privileged) attacker to remove privileges from user groups via crafted HTTP requests.

CVE-2025-26366 q-free vulnerability CVSS: 0 12 Feb 2025, 14:15 UTC

A CWE-306 "Missing Authentication for Critical Function" in maxprofile/setup/routes.lua in Q-Free MaxTime less than or equal to version 2.11.0 allows an unauthenticated remote attacker to disable front panel authentication via crafted HTTP requests.

CVE-2025-26365 q-free vulnerability CVSS: 0 12 Feb 2025, 14:15 UTC

A CWE-306 "Missing Authentication for Critical Function" in maxprofile/setup/routes.lua in Q-Free MaxTime less than or equal to version 2.11.0 allows an unauthenticated remote attacker to enable front panel authentication via crafted HTTP requests.

CVE-2025-26364 q-free vulnerability CVSS: 0 12 Feb 2025, 14:15 UTC

A CWE-306 "Missing Authentication for Critical Function" in maxprofile/setup/routes.lua in Q-Free MaxTime less than or equal to version 2.11.0 allows an unauthenticated remote attacker to disable an authentication profile server via crafted HTTP requests.

CVE-2025-26363 q-free vulnerability CVSS: 0 12 Feb 2025, 14:15 UTC

A CWE-306 "Missing Authentication for Critical Function" in maxprofile/setup/routes.lua in Q-Free MaxTime less than or equal to version 2.11.0 allows an unauthenticated remote attacker to enable an authentication profile server via crafted HTTP requests.

CVE-2025-26362 q-free vulnerability CVSS: 0 12 Feb 2025, 14:15 UTC

A CWE-306 "Missing Authentication for Critical Function" in maxprofile/setup/routes.lua in Q-Free MaxTime less than or equal to version 2.11.0 allows an unauthenticated remote attacker to set an arbitrary authentication profile server via crafted HTTP requests.

CVE-2025-26361 q-free vulnerability CVSS: 0 12 Feb 2025, 14:15 UTC

A CWE-306 "Missing Authentication for Critical Function" in maxprofile/setup/routes.lua in Q-Free MaxTime less than or equal to version 2.11.0 allows an unauthenticated remote attacker to factory reset the device via crafted HTTP requests.

CVE-2025-26360 q-free vulnerability CVSS: 0 12 Feb 2025, 14:15 UTC

A CWE-306 "Missing Authentication for Critical Function" in maxprofile/persistance/routes.lua in Q-Free MaxTime less than or equal to version 2.11.0 allows an unauthenticated remote attacker to delete dashboards via crafted HTTP requests.

CVE-2025-26359 q-free vulnerability CVSS: 0 12 Feb 2025, 14:15 UTC

A CWE-306 "Missing Authentication for Critical Function" in maxprofile/accounts/routes.lua in Q-Free MaxTime less than or equal to version 2.11.0 allows an unauthenticated remote attacker to reset user PINs via crafted HTTP requests.

CVE-2025-26358 q-free vulnerability CVSS: 0 12 Feb 2025, 14:15 UTC

A CWE-15 "External Control of System or Configuration Setting" in ldbMT.so in Q-Free MaxTime less than or equal to version 2.11.0 allows an authenticated remote attacker to modify system configuration via crafted HTTP requests.

CVE-2025-26357 q-free vulnerability CVSS: 0 12 Feb 2025, 14:15 UTC

A CWE-35 "Path Traversal" in maxtime/api/database/database.lua in Q-Free MaxTime less than or equal to version 2.11.0 allows an authenticated remote attacker to read sensitive files via crafted HTTP requests.

CVE-2025-26356 q-free vulnerability CVSS: 0 12 Feb 2025, 14:15 UTC

A CWE-35 "Path Traversal" in maxtime/api/database/database.lua (setActive endpoint) in Q-Free MaxTime less than or equal to version 2.11.0 allows an authenticated remote attacker to overwrite sensitive files via crafted HTTP requests.

CVE-2025-26355 q-free vulnerability CVSS: 0 12 Feb 2025, 14:15 UTC

A CWE-35 "Path Traversal" in maxtime/api/database/database.lua in Q-Free MaxTime less than or equal to version 2.11.0 allows an authenticated remote attacker to delete sensitive files via crafted HTTP requests.

CVE-2025-26354 q-free vulnerability CVSS: 0 12 Feb 2025, 14:15 UTC

A CWE-35 "Path Traversal" in maxtime/api/database/database.lua (copy endpoint) in Q-Free MaxTime less than or equal to version 2.11.0 allows an authenticated remote attacker to overwrite sensitive files via crafted HTTP requests.

CVE-2025-26353 q-free vulnerability CVSS: 0 12 Feb 2025, 14:15 UTC

A CWE-35 "Path Traversal" in maxtime/api/sql/sql.lua in Q-Free MaxTime less than or equal to version 2.11.0 allows an authenticated remote attacker to read sensitive files via crafted HTTP requests.

CVE-2025-26352 q-free vulnerability CVSS: 0 12 Feb 2025, 14:15 UTC

A CWE-35 "Path Traversal" in the template deletion mechanism in Q-Free MaxTime less than or equal to version 2.11.0 allows an authenticated remote attacker to delete sensitive files via crafted HTTP requests.