Vulnerabilities > Critical

DATE CVE VULNERABILITY TITLE RISK
2024-02-01 CVE-2024-1039 Improper Authentication vulnerability in Gesslergmbh Web-Master Firmware 7.9
Gessler GmbH WEB-MASTER has a restoration account that uses weak hard coded credentials and if exploited could allow an attacker control over the web management of the device.
network
low complexity
gesslergmbh CWE-287
critical
9.8
2024-02-01 CVE-2023-5841 Out-of-bounds Write vulnerability in Openexr
Due to a failure in validating the number of scanline samples of a OpenEXR file containing deep scanline data, Academy Software Foundation OpenEX image parsing library version 3.2.1 and prior is susceptible to a heap-based buffer overflow vulnerability.
network
low complexity
openexr CWE-787
critical
9.1
2024-02-01 CVE-2024-23832 Unspecified vulnerability in Joinmastodon Mastodon
Mastodon is a free, open-source social network server based on ActivityPub Mastodon allows configuration of LDAP for authentication.
network
low complexity
joinmastodon
critical
9.8
2024-02-01 CVE-2024-24561 Out-of-bounds Write vulnerability in Vyperlang Vyper
Vyper is a pythonic Smart Contract Language for the ethereum virtual machine.
network
low complexity
vyperlang CWE-787
critical
9.8
2024-02-01 CVE-2024-24754 Unspecified vulnerability in Mnapoli Bref
Bref enable serverless PHP on AWS Lambda.
network
low complexity
mnapoli
critical
9.8
2024-02-01 CVE-2023-6078 OS Command Injection vulnerability in 3DS Biovia Materials Studio 2021/2023
An OS Command Injection vulnerability exists in BIOVIA Materials Studio products from Release BIOVIA 2021 through Release BIOVIA 2023.
network
low complexity
3ds CWE-78
critical
9.8
2024-01-31 CVE-2024-23652 Unspecified vulnerability in Mobyproject Buildkit
BuildKit is a toolkit for converting source code to build artifacts in an efficient, expressive and repeatable manner.
network
low complexity
mobyproject
critical
9.1
2024-01-31 CVE-2024-23653 Unspecified vulnerability in Mobyproject Buildkit
BuildKit is a toolkit for converting source code to build artifacts in an efficient, expressive and repeatable manner.
network
low complexity
mobyproject
critical
9.8
2024-01-31 CVE-2022-47072 SQL Injection vulnerability in Sparxsystems Enterprise Architect 16.0.1605
SQL injection vulnerability in Enterprise Architect 16.0.1605 32-bit allows attackers to run arbitrary SQL commands via the Find parameter in the Select Classifier dialog box..
network
low complexity
sparxsystems CWE-89
critical
9.8
2024-01-31 CVE-2024-1117 Unspecified vulnerability in Openbi
A vulnerability was found in openBI up to 1.0.8.
network
low complexity
openbi
critical
9.8