NA - CVE-2024-57436 - RuoYi v4.8.0 was discovered to allow...
RuoYi v4.8.0 was discovered to allow unauthorized attackers to view the session ID of the admin in the system monitoring. This issue can allow attackers to impersonate Admin users via using a...
NA - CVE-2024-57439 - An issue in the reset password interface of...
An issue in the reset password interface of ruoyi v4.8.0 allows attackers with Admin privileges to cause a Denial of Service (DoS) by duplicating the login name of the account.
NA - CVE-2025-24374 - Twig is a template language for PHP. When using...
Twig is a template language for PHP. When using the ?? operator, output escaping was missing for the expression on the left side of the operator. This vulnerability is fixed in 3.19.0.
NA - CVE-2025-24792 - Snowflake PHP PDO Driver is a driver that uses...
Snowflake PHP PDO Driver is a driver that uses the PHP Data Objects (PDO) extension to connect to the Snowflake database. Snowflake discovered and remediated a vulnerability in the Snowflake PHP...
Medium - CVE-2023-35907 - IBM Aspera Faspex 5.0.0 through 5.0.10 does not...
IBM Aspera Faspex 5.0.0 through 5.0.10 does not require that users should have strong passwords by default, which makes it easier for attackers to compromise user accounts.
Medium - CVE-2023-37398 - IBM Aspera Faspex 5.0.0 through 5.0.10 does not...
IBM Aspera Faspex 5.0.0 through 5.0.10 does not require that users should have strong passwords by default, which makes it easier for attackers to compromise user accounts.