Vulnerabilities > Critical

DATE CVE VULNERABILITY TITLE RISK
2024-01-26 CVE-2023-38323 OS Command Injection vulnerability in Opennds
An issue was discovered in OpenNDS before 10.1.3.
network
low complexity
opennds CWE-78
critical
9.8
2024-01-26 CVE-2024-0402 Path Traversal vulnerability in Gitlab
An issue has been discovered in GitLab CE/EE affecting all versions from 16.0 prior to 16.6.6, 16.7 prior to 16.7.4, and 16.8 prior to 16.8.1 which allows an authenticated user to write files to arbitrary locations on the GitLab server while creating a workspace.
network
low complexity
gitlab CWE-22
critical
9.9
2024-01-26 CVE-2024-23613 Classic Buffer Overflow vulnerability in Broadcom Symantec Deployment Solutions 7.9
A buffer overflow vulnerability exists in Symantec Deployment Solution version 7.9 when parsing UpdateComputer tokens.
network
low complexity
broadcom CWE-120
critical
9.8
2024-01-26 CVE-2024-23614 Classic Buffer Overflow vulnerability in Broadcom Symantec Messaging Gateway 9.5
A buffer overflow vulnerability exists in Symantec Messaging Gateway versions 9.5 and before.
network
low complexity
broadcom CWE-120
critical
9.8
2024-01-26 CVE-2024-23615 Classic Buffer Overflow vulnerability in Broadcom Symantec Messaging Gateway 10.5/9.5
A buffer overflow vulnerability exists in Symantec Messaging Gateway versions 10.5 and before.
network
low complexity
broadcom CWE-120
critical
9.8
2024-01-26 CVE-2024-23616 Classic Buffer Overflow vulnerability in Broadcom Symantec Server Management Suite 7.9
A buffer overflow vulnerability exists in Symantec Server Management Suite version 7.9 and before.
network
low complexity
broadcom CWE-120
critical
9.8
2024-01-26 CVE-2024-23618 Missing Authentication for Critical Function vulnerability in Commscope Arris Surfboard Sbg6950Ac2 Firmware
An arbitrary code execution vulnerability exists in Arris SURFboard SGB6950AC2 devices.
network
low complexity
commscope CWE-306
critical
9.8
2024-01-26 CVE-2024-23619 Use of Hard-coded Credentials vulnerability in IBM Merge Efilm Workstation 4.2
A hardcoded credential vulnerability exists in IBM Merge Healthcare eFilm Workstation.
network
low complexity
ibm CWE-798
critical
9.8
2024-01-26 CVE-2024-23621 Classic Buffer Overflow vulnerability in IBM Merge Efilm Workstation 4.2
A buffer overflow exists in IBM Merge Healthcare eFilm Workstation license server.
network
low complexity
ibm CWE-120
critical
9.8
2024-01-26 CVE-2024-23622 Out-of-bounds Write vulnerability in IBM Merge Efilm Workstation 4.2
A stack-based buffer overflow exists in IBM Merge Healthcare eFilm Workstation license server.
network
low complexity
ibm CWE-787
critical
9.8