Product
frangoteam fuxa
19 known vulnerabilities across versions
Vulnerabilities are listed by affected version. Select any CVE for the full briefing and its intelligence graph.
CVE-2025-69985
CVE-2026-25951
CVE-2026-25939
CVE-2026-25938
CVE-2026-25895
CVE-2026-25894
CVE-2026-25893
CVE-2026-25752
CVE-2026-25751
CVE-2025-69983
CVE-2025-69981
CVE-2025-69971
CVE-2025-69970
CVE-2023-31719
CVE-2023-31718
CVE-2023-31717
CVE-2023-31716
CVE-2023-33831
CVE-2021-45851
<= 1.2.8
FUXA 1.2.8 and prior contains an Authentication Bypass vulnerability leading to Remote Code Execution (RCE). The vulnerability exi
< 1.2.11
FUXA is a web-based Process Visualization (SCADA/HMI/Dashboard) software. Prior to 1.2.11, there is a flaw in the path sanitizatio
>= 1.2.8 and < 1.2.11
FUXA is a web-based Process Visualization (SCADA/HMI/Dashboard) software. From 1.2.8 through version 1.2.10, an authorization byp
>= 1.2.8 and < 1.2.11
FUXA is a web-based Process Visualization (SCADA/HMI/Dashboard) software. From 1.2.8 through 1.2.10, an authentication bypass vuln
< 1.2.10
FUXA is a web-based Process Visualization (SCADA/HMI/Dashboard) software. A path traversal vulnerability in FUXA allows an unauthe
< 1.2.10
FUXA is a web-based Process Visualization (SCADA/HMI/Dashboard) software. An insecure default configuration in FUXA allows an unau
< 1.2.10
FUXA is a web-based Process Visualization (SCADA/HMI/Dashboard) software. Prior to 1.2.10, an authentication bypass vulnerability
< 1.2.10
FUXA is a web-based Process Visualization (SCADA/HMI/Dashboard) software. An authorization bypass vulnerability in FUXA allows an
< 1.2.10
FUXA is a web-based Process Visualization (SCADA/HMI/Dashboard) software. An information disclosure vulnerability in FUXA allows a
all versions
FUXA v1.2.7 allows Remote Code Execution (RCE) via the project import functionality. The application does not properly sanitize or
all versions
FUXA v1.2.7 contains an Unrestricted File Upload vulnerability in the
/api/upload API endpoint. The endpoint lacks authenticatioall versions
FUXA v1.2.7 contains a hard-coded credential vulnerability in server/api/jwt-helper.js. The application uses a hard-coded secret k
all versions
FUXA v1.2.7 contains an insecure default configuration vulnerability in server/settings.default.js. The 'secureEnabled' flag is co
<= 1.1.12
FUXA <= 1.1.12 is vulnerable to SQL Injection via /api/signin.
<= 1.1.12
FUXA <= 1.1.12 is vulnerable to Local via Inclusion via /api/download.
<= 1.1.12
A SQL Injection attack in FUXA <= 1.1.12 allows exfiltration of confidential information from the database.
<= 1.1.12
FUXA <= 1.1.12 has a Local File Inclusion vulnerability via file=fuxa.log
all versions
A remote command execution (RCE) vulnerability in the /api/runscript endpoint of FUXA 1.1.13 allows attackers to execute arbitrary
all versions
A Server-Side Request Forgery (SSRF) attack in FUXA 1.1.3 can be carried out leading to the obtaining of sensitive information fro