1751
|
4.4 |
MEDIUM
Network
|
-
|
-
|
IBM Aspera Faspex 5.0.0 through 5.0.10 could allow a privileged user to make system changes without proper access controls.
|
CWE-250
Execution with Unnecessary Privileges
|
CVE-2023-37412
|
2025-01-30 02:15 |
2025-01-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
1752
|
5.9 |
MEDIUM
Network
|
-
|
-
|
IBM Aspera Faspex 5.0.0 through 5.0.10 does not require that users should have strong passwords by default, which makes it easier for attackers to compromise user accounts.
|
CWE-521
Weak Password Requirements
|
CVE-2023-37398
|
2025-01-30 02:15 |
2025-01-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
1753
|
5.9 |
MEDIUM
Network
|
-
|
-
|
IBM Aspera Faspex 5.0.0 through 5.0.10 does not require that users should have strong passwords by default, which makes it easier for attackers to compromise user accounts.
|
CWE-521
Weak Password Requirements
|
CVE-2023-35907
|
2025-01-30 02:15 |
2025-01-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
1754
|
- |
|
-
|
-
|
This issue was addressed with improved redaction of sensitive information. This issue is fixed in macOS Sequoia 15.3. An app may be able to access user-sensitive data.
|
-
|
CVE-2025-24101
|
2025-01-30 02:15 |
2025-01-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
1755
|
- |
|
-
|
-
|
Snowflake PHP PDO Driver is a driver that uses the PHP Data Objects (PDO) extension to connect to the Snowflake database. Snowflake discovered and remediated a vulnerability in the Snowflake PHP PDO …
|
CWE-195
|
CVE-2025-24792
|
2025-01-30 01:15 |
2025-01-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
1756
|
- |
|
-
|
-
|
Twig is a template language for PHP. When using the ?? operator, output escaping was missing for the expression on the left side of the operator. This vulnerability is fixed in 3.19.0.
|
CWE-74
Injection
|
CVE-2025-24374
|
2025-01-30 01:15 |
2025-01-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
1757
|
- |
|
-
|
-
|
A reflected cross-site scripting (XSS) vulnerability in Audemium ERP <=0.9.0 allows remote attackers to execute an arbitrary JavaScript payload in the web browser of a user by including a malicious p…
|
-
|
CVE-2025-22917
|
2025-01-30 01:15 |
2025-01-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
1758
|
- |
|
-
|
-
|
The TP-Link Archer A20 v3 router is vulnerable to Cross-site Scripting (XSS) due to improper handling of directory listing paths in the web interface. When a specially crafted URL is visited, the rou…
|
-
|
CVE-2024-57514
|
2025-01-30 01:15 |
2025-01-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
1759
|
- |
|
-
|
-
|
Buffer Overflow vulnerability in D-Link DSR-150, DSR-150N, DSR-250, DSR-250N, DSR-500N, DSR-1000N from 3.13 to 3.17B901C allows unauthenticated users to execute remote code execution.
|
-
|
CVE-2024-57376
|
2025-01-30 01:15 |
2025-01-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
1760
|
9.9 |
CRITICAL
Network
|
-
|
-
|
A vulnerability in the REST API of Cisco Meeting Management could allow a remote, authenticated attacker with low privileges to elevate privileges to administrator on an affected device.
This vuln…
|
CWE-274
Improper Handling of Insufficient Privileges
|
CVE-2025-20156
|
2025-01-30 01:15 |
2025-01-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|