Skip to main content

Vendor/product archive

frangoteam / fuxa CVEs

Beta · best-effort

19 CVEs tagged to frangoteam / fuxa14 Critical, 5 High, 0 Medium, 0 Low, 0 Unrated.

CVE-2025-69985

Published Feb 24, 2026

FUXA 1.2.8 and prior contains an Authentication Bypass vulnerability leading to Remote Code Execution (RCE). The vulnerability exists in the server/api/jwt-helper.js middleware, w…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2026-25951

Published Feb 9, 2026

FUXA is a web-based Process Visualization (SCADA/HMI/Dashboard) software. Prior to 1.2.11, there is a flaw in the path sanitization logic allows an authenticated attacker with adm…

CVSS 8.6 · High
evidence mentions
3
Buzz score
18.9
Vendor/product tagsBeta · best-effort

CVE-2026-25939

Published Feb 9, 2026

FUXA is a web-based Process Visualization (SCADA/HMI/Dashboard) software. From 1.2.8 through version 1.2.10, an authorization bypass vulnerability in the FUXA allows an unauthent…

CVSS 9.3 · Critical
evidence mentions
3
Buzz score
18.9
Vendor/product tagsBeta · best-effort

CVE-2026-25938

Published Feb 9, 2026

FUXA is a web-based Process Visualization (SCADA/HMI/Dashboard) software. From 1.2.8 through 1.2.10, an authentication bypass vulnerability in FUXA allows an unauthenticated, remo…

CVSS 9.5 · Critical
evidence mentions
3
Buzz score
18.9
Vendor/product tagsBeta · best-effort

CVE-2026-25895

Published Feb 9, 2026

FUXA is a web-based Process Visualization (SCADA/HMI/Dashboard) software. A path traversal vulnerability in FUXA allows an unauthenticated, remote attacker to write arbitrary file…

CVSS 9.5 · Critical
evidence mentions
3
Buzz score
18.9
Vendor/product tagsBeta · best-effort

CVE-2026-25894

Published Feb 9, 2026

FUXA is a web-based Process Visualization (SCADA/HMI/Dashboard) software. An insecure default configuration in FUXA allows an unauthenticated, remote attacker to gain administrati…

CVSS 9.5 · Critical
evidence mentions
3
Buzz score
18.9
Vendor/product tagsBeta · best-effort

CVE-2026-25893

Published Feb 9, 2026

FUXA is a web-based Process Visualization (SCADA/HMI/Dashboard) software. Prior to 1.2.10, an authentication bypass vulnerability in FUXA allows an unauthenticated, remote attacke…

CVSS 10.0 · Critical
evidence mentions
2
Buzz score
16.0
Vendor/product tagsBeta · best-effort

CVE-2026-25752

Published Feb 6, 2026

FUXA is a web-based Process Visualization (SCADA/HMI/Dashboard) software. An authorization bypass vulnerability in FUXA allows an unauthenticated, remote attacker to modify device…

CVSS 9.3 · Critical
evidence mentions
2
Buzz score
16.0
Vendor/product tagsBeta · best-effort

CVE-2026-25751

Published Feb 6, 2026

FUXA is a web-based Process Visualization (SCADA/HMI/Dashboard) software. An information disclosure vulnerability in FUXA allows an unauthenticated, remote attacker to retrieve se…

CVSS 9.1 · Critical
evidence mentions
2
Buzz score
16.0
Vendor/product tagsBeta · best-effort

CVE-2025-69983

Published Feb 3, 2026

FUXA v1.2.7 allows Remote Code Execution (RCE) via the project import functionality. The application does not properly sanitize or sandbox user-supplied scripts within imported pr…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2025-69981

Published Feb 3, 2026

FUXA v1.2.7 contains an Unrestricted File Upload vulnerability in the `/api/upload` API endpoint. The endpoint lacks authentication mechanisms, allowing unauthenticated remote att…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2025-69971

Published Feb 3, 2026

FUXA v1.2.7 contains a hard-coded credential vulnerability in server/api/jwt-helper.js. The application uses a hard-coded secret key to sign and verify JWT Tokens. This allows rem…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2025-69970

Published Feb 3, 2026

FUXA v1.2.7 contains an insecure default configuration vulnerability in server/settings.default.js. The 'secureEnabled' flag is commented out by default, causing the application t…

CVSS 9.3 · Critical
Vendor/product tagsBeta · best-effort

CVE-2023-31717

Published Sep 22, 2023

A SQL Injection attack in FUXA <= 1.1.12 allows exfiltration of confidential information from the database.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2023-31716

Published Sep 22, 2023

FUXA <= 1.1.12 has a Local File Inclusion vulnerability via file=fuxa.log

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2023-33831

Published Sep 18, 2023

A remote command execution (RCE) vulnerability in the /api/runscript endpoint of FUXA 1.1.13 allows attackers to execute arbitrary commands via a crafted POST request.

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2021-45851

Published Mar 16, 2022

A Server-Side Request Forgery (SSRF) attack in FUXA 1.1.3 can be carried out leading to the obtaining of sensitive information from the server's internal environment and services,…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort
Showing 1-19 of 19 CVEsPage 1 of 1