Skip to main content

Threat Intelligence Database

Comprehensive database of the latest cyber threats affecting organizations worldwide. Filter and search to find specific threat intelligence relevant to your organization.

Pro Console Lifetime

Stop chasing alerts. Route them.

Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.

Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)

View Plans & Pricing

API access activates after upgrading in Console -> Billing.

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now

Filter Threats

Narrow down the results by type, severity, or affected countries

Search threats by title, CVE ID, or description. Maximum 100 characters.
Active filters (1):Package: pkg:github/frangoteam/FUXA

Threat Intelligence

Click on any threat for detailed analysis and mitigation recommendations

CVE-2026-67442 is an improper access control vulnerability in frangoteam's FUXA web-based Process Visualization software. Versions prior to 1.3.3 have an issue where deleting a role does not fully remove the role identifier from users' role arrays or runtime caches. This can cause users to retain permissions that administrators intended to revoke, leading to residual privileges and inconsistent access control states. The issue is fixed in version 1.3.3.

Join the discussion

FUXA versions 1.3.2 and earlier suffer from insufficient session expiration, allowing attackers with previously issued privileged refresh cookies or access tokens to continue minting privileged JWTs even after account deletion or role changes. This enables unauthorized persistent access to sensitive functions such as user management and backdoor account creation. The vulnerability is fixed in version 1.3.3.

Join the discussion

FUXA versions 1.3.2 and earlier contain a missing authorization vulnerability in the Node-RED integration. An unauthenticated remote attacker can obtain a signed guest token and access the Node-RED HTTP admin editor and flow deployment API without proper identity verification. This allows the attacker to deploy function nodes or invoke scripts, potentially gaining control over project data, configuration, scripts, and runtime helpers, including operating system commands if unsafe modules are enabled. The issue is fixed in version 1.3.3.

Join the discussion

CVE-2026-65985 is a Server-Side Request Forgery (SSRF) vulnerability in frangoteam's FUXA software, versions 1.3.2 and earlier. It allows an authenticated non-admin runtime user to manipulate the device-webapi-request handler to make the server issue arbitrary HTTP or HTTPS requests. The vulnerability is fixed in version 1.3.3.

Join the discussion

FUXA versions 1.3.2 and earlier have a missing authorization vulnerability in certain Socket.IO event handlers that allow unauthenticated or guest users to access device and network metadata. This issue does not expose normal device status or alarm data but reveals system-discovery information beyond what is intended for public viewing. The vulnerability is fixed in version 1.3.3.

Join the discussion

FUXA versions prior to 1.3.2 have a missing authorization vulnerability in the scheduler API endpoints. Authenticated non-admin users can create, modify, or delete scheduled device actions that normally require admin permissions. This allows unauthorized changes to device values and execution of server-side scripts, potentially affecting PLC setpoints, safety interlocks, and project data even after the user's session ends. The issue is fixed in version 1.3.2.

Join the discussion

CVE-2026-47719 is a Server-Side Request Forgery (SSRF) vulnerability in frangoteam's FUXA software, a web-based SCADA/HMI/Dashboard tool. Versions prior to 1.3.2 allow unauthenticated remote attackers to make the server perform HTTP(S) requests to arbitrary destinations by exploiting insufficient authorization checks in Socket.IO handlers. This can expose sensitive internal resources such as cloud metadata, administrative services, industrial endpoints, and ODBC data accessible from the FUXA host. The vulnerability is fixed in version 1.3.2.

Join the discussion

CVE-2026-47720 is a SQL injection vulnerability in FUXA, a web-based SCADA/HMI/Dashboard software. Versions prior to 1.3.2 have an issue in the TDengine DAQ storage connector where backslashes are not properly escaped in SQL queries. This allows a remote unauthenticated attacker to inject SQL via crafted requests, potentially exposing historical PLC tag values, device identifiers, and device names. The vulnerability is fixed in version 1.3.2.

Join the discussion

FUXA is a web-based Process Visualization (SCADA/HMI/Dashboard) software. When `secureEnabled=true`, FUXA `1.3.0-2773` still allows guest and invalid-token requests to read project, alarms, and scheduler APIs. Version 1.3.1 fixes this issue.

Join the discussion

FUXA is a web-based Process Visualization (SCADA/HMI/Dashboard) software. In fuxa-server version 1.3.0, the GET /api/project endpoint exposes sensitive project configuration data to guest-context requests even when secureEnabled is enabled. Version 1.3.1 fixes the issue.

Join the discussion

Showing 1 to 10 of 19 results

Filters:Package: pkg:github/frangoteam/FUXA
Page 1 of 2
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses