17,305 vulnerabilities published in 2019
BWA (aka Burrow-Wheeler Aligner) before 2019-01-23 has a stack-based buffer overflow in the bns_restore function in bnts
Western Bridge Cobub Razor 0.8.0 has a file upload vulnerability via the web/assets/swf/uploadify.php URI, as demonstrat
An elevation of privilege vulnerability exists in the Call Dispatcher in Provisio SiteKiosk before 9.7.4905.
ZZZCMS zzzphp v1.6.3 allows remote attackers to execute arbitrary PHP code via a .php URL in the plugins/ueditor/php/con
Robocode through 1.9.3.5 allows remote attackers to cause external service interaction (DNS), as demonstrated by a query
Grandstream GAC2500 1.0.3.35, GXP2200 1.0.3.27, GVC3202 1.0.3.51, GXV3275 before 1.0.3.219 Beta, and GXV3240 before 1.0.
On Grandstream GXV3611IR_HD before 1.0.3.23 devices, the root account lacks a password.
Domoticz before 4.10578 allows SQL Injection via the idx parameter in CWebServer::GetFloorplanImage in WebServer.cpp.
treeRead in hdf/btree.c in libmysofa before 0.7 does not properly validate multiplications and additions.
Application/Admin/Controller/ConfigController.class.php in 74cms v5.0.1 allows remote attackers to execute arbitrary PHP
An issue was discovered in OverIT Geocall 6.3 before build 2:346977. An unauthenticated servlet allows an attacker to ob
VMware vCloud Director for Service Providers 9.5.x prior to 9.5.0.3 update resolves a Remote Session Hijack vulnerabilit
EMC NetWorker may potentially be vulnerable to an unauthenticated remote code execution vulnerability in the Networker C
A Malformed Input String to /cgi-bin/delete_CA on Grandstream GXP16xx VoIP 1.0.4.128 phones allows attackers to delete c
Shell Metacharacter Injection in the SSH configuration interface on Grandstream GXP16xx VoIP 1.0.4.128 phones allows att
An issue was discovered in TONGDA Office Anywhere 10.18.190121. There is a SQL Injection vulnerability via the general/a
The BluStar component in Mitel InAttend before 2.5 SP3 and CMG before 8.4 SP3 Suite Servers has a default password, whic
In the wp-google-maps plugin before 7.11.18 for WordPress, includes/class.rest-api.php in the REST API does not sanitize
A vulnerability in SonicWall SonicOS and SonicOSv with management enabled system on specific configuration allow unprivi
MKCMS V5.0 has SQL injection via the bplay.php play parameter.
S-CMS PHP v1.0 has SQL injection via the 4/js/scms.php?action=unlike id parameter.
Detcon Sitewatch Gateway, all versions without cellular, Passwords are presented in plaintext in a file that is accessib
SuiteCRM before 7.8.28, 7.9.x and 7.10.x before 7.10.15, and 7.11.x before 7.11.3 allows SQL Injection.
Plataformatec Devise version 4.5.0 and earlier, using the lockable module contains a CWE-367 vulnerability in The `Devis
Multiple memory corruption issues were addressed with improved memory handling. This issue affected versions prior to ma
A memory corruption issue was addressed with improved memory handling. This issue affected versions prior to macOS High
Multiple memory corruption issues were addressed with improved memory handling. This issue affected versions prior to ma
Multiple memory corruption issues were addressed with improved memory handling. This issue affected versions prior to ma
Multiple memory corruption issues were addressed with improved memory handling. This issue affected versions prior to ma
Multiple memory corruption issues were addressed with improved memory handling. This issue affected versions prior to ma
An input validation issue was addressed with improved input validation. This issue affected versions prior to macOS Moja
A memory corruption issue was addressed with improved memory handling. This issue affected versions prior to iOS 12, mac
A memory corruption issue was addressed with improved memory handling. This issue affected versions prior to iOS 12, mac
A configuration issue was addressed with additional restrictions. This issue affected versions prior to macOS Mojave 10.
A memory corruption issue was addressed with improved input validation. This issue affected versions prior to iOS 12.1.
AxiomSL's Axiom java applet module (used for editing uploaded Excel files and associated Java RMI services) 9.5.3 and ea
Arbitrary code execution (via backdoor code) was discovered in bootstrap-sass 3.2.0.3, when downloaded from rubygems.org
nbla/logger.cpp in libnnabla.a in Sony Neural Network Libraries (aka nnabla) through v1.0.14 relies on the HOME environm
htp_parse_authorization_digest in htp_parsers.c in LibHTP 0.5.26 allows remote attackers to cause a heap-based buffer ov
Suricata version 4.0.4 incorrectly handles the parsing of an EtherNet/IP PDU. A malformed PDU can cause the parsing code
XXE issue in Airsonic before 10.1.2 during parse.
A vulnerability was found in Rockwell Automation RSLinx Classic versions 4.10.00 and prior. An input validation issue in
The ARM-based hardware debugging feature on Raspberry Pi 3 module B+ and possibly other devices allows non-secure EL1 co
Rockwell Automation PowerFlex 525 AC Drives 5.001 and earlier allow remote attackers to cause a denial of service by cra
In Teeworlds 0.7.2, there is a failed bounds check in CDataFileReader::GetData() and CDataFileReader::ReplaceData() and
In Teeworlds 0.7.2, there is an integer overflow in CDataFileReader::Open() in engine/shared/datafile.cpp that can lead
In Teeworlds 0.7.2, there is an integer overflow in CMap::Load() in engine/shared/map.cpp that can lead to a buffer over
An issue was discovered on Glory RBW-100 devices with firmware ISP-K05-02 7.0.0. A hard-coded username and password were
Advantech WebAccess/SCADA, Versions 8.3.5 and prior. Multiple stack-based buffer overflow vulnerabilities, caused by a l
Advantech WebAccess/SCADA, Versions 8.3.5 and prior. Multiple command injection vulnerabilities, caused by a lack of pro
Scan for 2019 Vulnerabilities
CyberStrike detects these CVEs across your infrastructure automatically.
Get Started