CVE-2026-25939
- EPSS 11.39%
- Veröffentlicht 09.02.2026 22:21:03
- Zuletzt bearbeitet 13.02.2026 20:31:09
FUXA is a web-based Process Visualization (SCADA/HMI/Dashboard) software. From 1.2.8 through version 1.2.10, an authorization bypass vulnerability in the FUXA allows an unauthenticated, remote attacker to create and modify arbitrary schedulers, expo...
CVE-2026-25938
- EPSS 0.98%
- Veröffentlicht 09.02.2026 22:18:15
- Zuletzt bearbeitet 13.02.2026 20:31:47
FUXA is a web-based Process Visualization (SCADA/HMI/Dashboard) software. From 1.2.8 through 1.2.10, an authentication bypass vulnerability in FUXA allows an unauthenticated, remote attacker to execute arbitrary code on the server when the Node-RED p...
CVE-2026-25752
- EPSS 0.48%
- Veröffentlicht 06.02.2026 19:16:10
- Zuletzt bearbeitet 10.02.2026 14:31:52
FUXA is a web-based Process Visualization (SCADA/HMI/Dashboard) software. An authorization bypass vulnerability in FUXA allows an unauthenticated, remote attacker to modify device tags via WebSockets. Exploitation allows an unauthenticated, remote at...
CVE-2026-25751
- EPSS 0.27%
- Veröffentlicht 06.02.2026 19:16:10
- Zuletzt bearbeitet 10.02.2026 14:33:38
FUXA is a web-based Process Visualization (SCADA/HMI/Dashboard) software. An information disclosure vulnerability in FUXA allows an unauthenticated, remote attacker to retrieve sensitive administrative database credentials. Exploitation allows an una...
CVE-2025-69983
- EPSS 0.42%
- Veröffentlicht 03.02.2026 00:00:00
- Zuletzt bearbeitet 11.02.2026 18:16:05
FUXA v1.2.7 allows Remote Code Execution (RCE) via the project import functionality. The application does not properly sanitize or sandbox user-supplied scripts within imported project files. An attacker can upload a malicious project containing syst...
CVE-2025-69981
- EPSS 0.73%
- Veröffentlicht 03.02.2026 00:00:00
- Zuletzt bearbeitet 11.02.2026 18:16:05
FUXA v1.2.7 contains an Unrestricted File Upload vulnerability in the `/api/upload` API endpoint. The endpoint lacks authentication mechanisms, allowing unauthenticated remote attackers to upload arbitrary files. This can be exploited to overwrite cr...
CVE-2025-69971
- EPSS 2.04%
- Veröffentlicht 03.02.2026 00:00:00
- Zuletzt bearbeitet 28.02.2026 04:16:17
FUXA v1.2.7 contains a hard-coded credential vulnerability in server/api/jwt-helper.js. The application uses a hard-coded secret key to sign and verify JWT Tokens. This allows remote attackers to forge valid admin tokens and bypass authentication to ...
CVE-2025-69970
- EPSS 0.46%
- Veröffentlicht 03.02.2026 00:00:00
- Zuletzt bearbeitet 10.02.2026 14:47:43
FUXA v1.2.7 contains an insecure default configuration vulnerability in server/settings.default.js. The 'secureEnabled' flag is commented out by default, causing the application to initialize with authentication disabled. This allows unauthenticated ...
CVE-2023-31719
- EPSS 27.23%
- Veröffentlicht 22.09.2023 00:15:11
- Zuletzt bearbeitet 21.11.2024 08:02:12
FUXA <= 1.1.12 is vulnerable to SQL Injection via /api/signin.
CVE-2023-31718
- EPSS 1.48%
- Veröffentlicht 22.09.2023 00:15:11
- Zuletzt bearbeitet 21.11.2024 08:02:12
FUXA <= 1.1.12 is vulnerable to Local via Inclusion via /api/download.