CVE-2025-27451
- EPSS 0.08%
- Veröffentlicht 03.07.2025 11:27:35
- Zuletzt bearbeitet 06.02.2026 14:38:48
For failed login attempts, the application returns different error messages depending on whether the login failed due to an incorrect password or a non-existing username. This allows an attacker to guess usernames until they find an existing one.
CVE-2025-27450
- EPSS 0.03%
- Veröffentlicht 03.07.2025 11:26:33
- Zuletzt bearbeitet 06.02.2026 14:38:41
The Secure attribute is missing on multiple cookies provided by the MEAC300-FNADE4. An attacker can trick a user to establish an unencrypted HTTP connection to the server and intercept the request containing the PHPSESSID cookie.
CVE-2025-27449
- EPSS 0.15%
- Veröffentlicht 03.07.2025 11:25:45
- Zuletzt bearbeitet 06.02.2026 14:38:33
The MEAC300-FNADE4 does not implement sufficient measures to prevent multiple failed authentication attempts within a short time frame, making it susceptible to brute-force attacks.
CVE-2025-27448
- EPSS 0.06%
- Veröffentlicht 03.07.2025 11:24:00
- Zuletzt bearbeitet 06.02.2026 14:38:25
The web application is susceptible to cross-site-scripting attacks. An attacker who can create new dashboards can inject JavaScript code into the dashboard name which will be executed when the website is loaded.
CVE-2025-27447
- EPSS 0.06%
- Veröffentlicht 03.07.2025 11:23:20
- Zuletzt bearbeitet 06.02.2026 14:38:12
The web application is susceptible to cross-site-scripting attacks. An attacker can create a prepared URL, which injects JavaScript code into the website. The code is executed in the victim’s browser when an authenticated administrator clicks the l...
CVE-2025-1711
- EPSS 0.11%
- Veröffentlicht 03.07.2025 11:22:09
- Zuletzt bearbeitet 29.01.2026 18:59:16
Multiple services of the DUT as well as different scopes of the same service reuse the same credentials.
CVE-2025-1710
- EPSS 0.15%
- Veröffentlicht 03.07.2025 11:21:18
- Zuletzt bearbeitet 06.02.2026 14:38:02
The maxView Storage Manager does not implement sufficient measures to prevent multiple failed authentication attempts within a short time frame, making it susceptible to brute-force attacks.
CVE-2025-1709
- EPSS 0.08%
- Veröffentlicht 03.07.2025 11:20:20
- Zuletzt bearbeitet 06.02.2026 14:36:56
Several credentials for the local PostgreSQL database are stored in plain text (partially base64 encoded).
CVE-2025-1708
- EPSS 0.08%
- Veröffentlicht 03.07.2025 11:18:22
- Zuletzt bearbeitet 29.01.2026 17:26:39
The application is vulnerable to SQL injection attacks. An attacker is able to dump the PostgreSQL database and read its content.