Vulnerabilities > Critical

DATE CVE VULNERABILITY TITLE RISK
2024-02-02 CVE-2024-22901 Unspecified vulnerability in Vinchin Backup and Recovery
Vinchin Backup & Recovery v7.2 was discovered to use default MYSQL credentials.
network
low complexity
vinchin
critical
9.8
2024-02-02 CVE-2024-22902 Unspecified vulnerability in Vinchin Backup and Recovery
Vinchin Backup & Recovery v7.2 was discovered to be configured with default root credentials.
network
low complexity
vinchin
critical
9.8
2024-02-02 CVE-2024-23746 Code Injection vulnerability in Miro 0.8.18
Miro Desktop 0.8.18 on macOS allows local Electron code injection via a complex series of steps that might be usable in some environments (bypass a kTCCServiceSystemPolicyAppBundles requirement via a file copy, an app.app/Contents rename, an asar modification, and a rename back to app.app/Contents).
network
low complexity
miro CWE-94
critical
9.8
2024-02-02 CVE-2023-50940 Incorrect Comparison vulnerability in IBM Powersc 1.3/2.0/2.1
IBM PowerSC 1.3, 2.0, and 2.1 uses Cross-Origin Resource Sharing (CORS) which could allow an attacker to carry out privileged actions and retrieve sensitive information as the domain name is not being limited to only trusted domains.
network
low complexity
ibm CWE-697
critical
9.8
2024-02-02 CVE-2024-21764 Use of Hard-coded Credentials vulnerability in Rapidscada Rapid Scada
In Rapid Software LLC's Rapid SCADA versions prior to Version 5.8.4, the product uses hard-coded credentials, which may allow an attacker to connect to a specific port.
network
low complexity
rapidscada CWE-798
critical
9.8
2024-02-01 CVE-2023-46706 Use of Hard-coded Credentials vulnerability in Machinesense Feverwarn Firmware
Multiple MachineSense devices have credentials unable to be changed by the user or administrator.
network
low complexity
machinesense CWE-798
critical
9.8
2024-02-01 CVE-2023-49617 Missing Authentication for Critical Function vulnerability in Machinesense Feverwarn Firmware
The MachineSense application programmable interface (API) is improperly protected and can be accessed without authentication.
network
low complexity
machinesense CWE-306
critical
9.1
2024-02-01 CVE-2023-4472 Incorrect Usage of Seeds in Pseudo-Random Number Generator (PRNG) vulnerability in Objectplanet Opinio
Objectplanet Opinio version 7.22 and prior uses a cryptographically weak pseudo-random number generator (PRNG) coupled to a predictable seed, which could lead to an unauthenticated account takeover of any user on the application.
network
low complexity
objectplanet CWE-335
critical
9.8
2024-02-01 CVE-2024-1039 Improper Authentication vulnerability in Gesslergmbh Web-Master Firmware 7.9
Gessler GmbH WEB-MASTER has a restoration account that uses weak hard coded credentials and if exploited could allow an attacker control over the web management of the device.
network
low complexity
gesslergmbh CWE-287
critical
9.8
2024-02-01 CVE-2023-5841 Out-of-bounds Write vulnerability in Openexr
Due to a failure in validating the number of scanline samples of a OpenEXR file containing deep scanline data, Academy Software Foundation OpenEX image parsing library version 3.2.1 and prior is susceptible to a heap-based buffer overflow vulnerability.
network
low complexity
openexr CWE-787
critical
9.1