17,305 vulnerabilities published in 2019
On BIG-IP 11.5.1-11.6.4, iRules performing HTTP header manipulation may cause an interruption to service when processing
Incorrect handling of user input in ZIP extraction was detected in JetBrains TeamCity. The issue was fixed in TeamCity 2
A vulnerability in the FTP daemon on MikroTik routers through 6.44.3 could allow remote attackers to exhaust all availab
An issue was discovered in Bento4 1.5.1.0. A memory allocation failure is unhandled in Core/Ap4SdpAtom.cpp and leads to
Improper download file verification vulnerability in VAIO Update 7.3.0.03150 and earlier allows remote attackers to cond
Invoxia NVX220 devices allow access to /bin/sh via escape from a restricted CLI, leading to disclosure of password hashe
The Odoo Community Association (OCA) dbfilter_from_header module makes Odoo 8.x, 9.x, 10.x, and 11.x vulnerable to ReDoS
An issue was discovered in SWIFT Alliance Web Platform 7.1.23. A log injection (and an arbitrary log filename) can be ac
lib/DocumentToText.php in OpenCats before 0.9.4-3 has XXE that allows remote users to read files on the underlying opera
The Linux kernel 4.x (starting from 4.1) and 5.x before 5.0.8 allows Information Exposure (partial kernel address disclo
A vulnerability in the web interface of Cisco Small Business 200, 300, and 500 Series Managed Switches could allow an un
A vulnerability in the Secure Sockets Layer (SSL) input packet processor of Cisco Small Business 200, 300, and 500 Serie
In save_attr_seq of sdp_discovery.cc, there is a possible out-of-bound read due to a missing bounds check. This could le
Sonatype Nexus Repository Manager before 3.17.0 has a weak default of giving any unauthenticated user read permissions o
Sony BRAVIA Smart TV devices allow remote attackers to cause a denial of service (device hang) via a crafted web page ov
Sony Bravia Smart TV devices allow remote attackers to cause a denial of service (device hang or reboot) via a SYN flood
Lack of authentication in case-exporting components in DDRT Dashcom Live through 2019-05-08 allows anyone to remotely ac
Lack of authentication in file-viewing components in DDRT Dashcom Live 2019-05-09 allows anyone to remotely access all c
In PrestaShop before 1.7.6.0 RC2, the id_address_delivery and id_address_invoice parameters are affected by an Insecure
An issue was discovered in OWASP ModSecurity Core Rule Set (CRS) 3.0.2. Use of X.Filename instead of X_Filename can bypa
In WESEEK GROWI before 3.5.0, the site-wide basic authentication can be bypassed by adding a URL parameter access_token
In WESEEK GROWI before 3.5.0, a remote attacker can obtain the password hash of the creator of a page by leveraging wiki
TRENDnet TEW-827DRU with firmware up to and including 2.04B03 allows an unauthenticated attacker to execute setup wizard
main/streams/xp_socket.c in PHP 7.x before 2017-03-07 misparses fsockopen calls, such as by interpreting fsockopen('127.
An issue was discovered in the America's Army Proving Grounds platform for the Unreal Engine. With a false packet sent v
An Incorrect Access Control vulnerability was found in Wikimedia MediaWiki 1.18.0 through 1.32.1. It is possible to bypa
Wikimedia MediaWiki 1.27.0 through 1.32.1 might allow DoS. Passing invalid titles to the API could cause a DoS by queryi
Wikimedia MediaWiki 1.23.0 through 1.32.1 has an information leak. Privileged API responses that include whether a recen
GitLab EE, versions 8.3 up to 11.x before 11.3.11, 11.4 before 11.4.8, and 11.5 before 11.5.1, is vulnerable to an insec
GitLab EE, versions 11.x before 11.3.11, 11.4 before 11.4.8, and 11.5 before 11.5.1, is vulnerable to an insecure direct
The SAP Gateway, versions 7.5, 7.51, 7.52 and 7.53, allows an attacker to inject content which is displayed in the form
SAP Commerce Cloud (previously known as SAP Hybris Commerce), (HY_COM, versions 6.3, 6.4, 6.5, 6.6, 6.7, 1808, 1811), al
mq_parse_http in mongoose.c in Mongoose 6.15 has a heap-based buffer over-read.
Any URLs with download_attachment.php under templates or home folders can allow arbitrary files downloaded without login
On Junos devices with the BGP graceful restart helper mode enabled or the BGP graceful restart mechanism enabled, a cert
The srxpfe process may crash on SRX Series services gateways when the UTM module processes a specific fragmented HTTP pa
IBM Jazz for Service Management 1.1.3 and 1.1.3.2 stores sensitive information in URL parameters. This may lead to infor
A vulnerability has been identified in All other SIPROTEC 5 device types with CPU variants CP300 and CP100 and the respe
A vulnerability has been identified in All other SIPROTEC 5 device types with CPU variants CP300 and CP100 and the respe
libnmap < v0.6.3 is affected by: XML Injection. The impact is: Denial of service (DoS) by consuming resources. The compo
Linaro/OP-TEE OP-TEE 3.3.0 and earlier is affected by: Rounding error. The impact is: Potentially leaking code and/or da
mz-automation libiec61850 1.3.2 1.3.1 1.3.0 is affected by: Buffer Overflow. The impact is: Software crash. The componen
A denial of service vulnerability exists in Windows DNS Server when it fails to properly handle DNS queries, aka 'Window
A denial of service vulnerability exists when SymCrypt improperly handles a specially crafted digital signature.An attac
A remote code execution vulnerability exists in the way the scripting engine handles objects in memory in Microsoft brow
A remote code execution vulnerability exists in the way that the scripting engine handles objects in memory in Internet
An authentication bypass vulnerability exists in Windows Communication Foundation (WCF) and Windows Identity Foundation
A remote code execution vulnerability exists in the way that the scripting engine handles objects in memory in Internet
A remote code execution vulnerability exists in the way that the scripting engine handles objects in memory in Internet
A remote code execution vulnerability exists in the way that the Chakra scripting engine handles objects in memory in Mi
Scan for 2019 Vulnerabilities
CyberStrike detects these CVEs across your infrastructure automatically.
Get Started