CVE Tools

Frangoteam

29 CVEs tracked since 2023. Since Sep 2023, none of them reached CISA KEV.

Frangoteam CVEs per month

Sep 2023 to Aug 2026. Point at a month, or focus the strip and use the arrow keys.
Frangoteam CVEs per month, with the share now in CISA KEV
MonthCVEsIn CISA KEV
2023-0950
2023-10null or fewer
2023-11null or fewer
2023-12null or fewer
2024-01null or fewer
2024-02null or fewer
2024-03null or fewer
2024-04null or fewer
2024-05null or fewer
2024-06null or fewer
2024-07null or fewer
2024-08null or fewer
2024-09null or fewer
2024-10null or fewer
2024-11null or fewer
2024-12null or fewer
2025-01null or fewer
2025-02null or fewer
2025-03null or fewer
2025-04null or fewer
2025-05null or fewer
2025-06null or fewer
2025-07null or fewer
2025-08null or fewer
2025-09null or fewer
2025-10null or fewer
2025-11null or fewer
2025-12null or fewer
2026-01null or fewer
2026-02130
2026-03null or fewer
2026-04null or fewer
2026-05null or fewer
2026-06null or fewer
2026-07null or fewer
2026-08110

Products

The products that kept showing up in Frangoteam's monthly top three, with their CVEs summed over those months.

  1. Fuxa293 months

Latest CVEs

The 15 most recently published vulnerabilities affecting Frangoteam.

  1. CVE-2026-67442FUXA Business Logic Flaw: Role Deletion Without User Assignment Cleanup2.0
  2. CVE-2026-65984FUXA: JWT lifecycle flaws allow deleted or demoted users to retain privileged sessions—
  3. CVE-2026-67443FUXA: Unauthenticated guest JWT bypasses Node-RED secure-mode authorization gate (Remote Script Execution)—
  4. CVE-2026-65985FUXA: SSRF hardening for `device-webapi-request`—
  5. CVE-2026-67440FUXA: Unauthenticated Socket.IO read events—
  6. CVE-2026-47721FUXA: Scheduler API missing admin check enables operator-to-admin escalation via scheduled device actions6.3
  7. CVE-2026-47719FUXA: Unauthenticated SSRF via Socket.IO DEVICE_WEBAPI_REQUEST and DEVICE_PROPERTY with response reading8.2
  8. CVE-2026-47720FUXA: SQL injection in TDengine DAQ connector via backslash bypass of escapeTdString5.3
  9. CVE-2026-47718FUXA provides guest and invalid-token access to protected read APIs in secure mode—
  10. CVE-2026-47717FUXA's Unauthenticated Project Data Disclosure Exposes Server-Side Scripts and Device Configurations7.5
  11. CVE-2026-72586frangoteam FUXA - Missing Authentication on DAQ_QUERY Socket.IO Event Handler7.5
  12. CVE-2026-43947FUXA Vulnerable to Unauthenticated Remote Code Execution via Script Test Mode Authorization Bypass—
  13. CVE-2026-43946FUXA has an unauthenticated arbitrary tag value disclosure via /api/getTagValue—
  14. CVE-2026-43945FUXA Vulnerable to Pre-auth RCE via Path Manipulation & Configuration Injection—
  15. CVE-2026-13207Frangoteam FUXA SCADA/HMI Authentication Bypass by Spoofing7.5

The record

Peak rank
#73 in Feb 2026
Busiest month shown
Feb 2026, 13 CVEs
Months with a KEV entry
0 since Sep 2023
Monthly snapshots
3 since 2023
Frangoteam's full record, month by month

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store