Vulnerabilities

DATE CVE VULNERABILITY TITLE RISK
2025-01-30 CVE-2025-0844 Cross-site Scripting vulnerability in Needyamin Library Card System 1.0
A vulnerability was found in needyamin Library Card System 1.0.
network
low complexity
needyamin CWE-79
6.1
2025-01-29 CVE-2025-0843 SQL Injection vulnerability in Needyamin Library Card System 1.0
A vulnerability was found in needyamin Library Card System 1.0.
network
low complexity
needyamin CWE-89
critical
9.8
2025-01-29 CVE-2025-21396 Unspecified vulnerability in Microsoft Account
Missing authorization in Microsoft Account allows an unauthorized attacker to elevate privileges over a network.
network
low complexity
microsoft
8.2
2025-01-29 CVE-2025-21415 Authentication Bypass by Spoofing vulnerability in Microsoft Azure AI Face Service
Authentication bypass by spoofing in Azure AI Face Service allows an authorized attacker to elevate privileges over a network.
network
low complexity
microsoft CWE-290
8.8
2025-01-29 CVE-2025-0842 SQL Injection vulnerability in Needyamin Library Card System 1.0
A vulnerability was found in needyamin Library Card System 1.0 and classified as critical.
network
low complexity
needyamin CWE-89
critical
9.8
2025-01-29 CVE-2025-0841 A vulnerability has been found in Aridius XYZ up to 20240927 on OpenCart and classified as critical.
network
low complexity
CWE-502
7.3
2025-01-29 CVE-2025-0840 Stack-based Buffer Overflow vulnerability in GNU Binutils
A vulnerability, which was classified as problematic, was found in GNU Binutils up to 2.43.
network
high complexity
gnu CWE-121
7.5
2025-01-29 CVE-2023-35907 Weak Password Requirements vulnerability in IBM Aspera Faspex
IBM Aspera Faspex 5.0.0 through 5.0.10 does not require that users should have strong passwords by default, which makes it easier for attackers to compromise user accounts.
network
low complexity
ibm CWE-521
critical
9.8
2025-01-29 CVE-2023-37398 Weak Password Requirements vulnerability in IBM Aspera Faspex
IBM Aspera Faspex 5.0.0 through 5.0.10 does not require that users should have strong passwords by default, which makes it easier for attackers to compromise user accounts.
network
low complexity
ibm CWE-521
critical
9.8
2025-01-29 CVE-2023-37412 Execution with Unnecessary Privileges vulnerability in IBM Aspera Faspex
IBM Aspera Faspex 5.0.0 through 5.0.10 could allow a privileged user to make system changes without proper access controls.
network
low complexity
ibm CWE-250
4.9