17,305 vulnerabilities published in 2019
Airsonic 10.2.1 uses Spring's default remember-me mechanism based on MD5, with a fixed key of airsonic in GlobalSecurity
In Airsonic 10.2.1, RecoverController.java generates passwords via org.apache.commons.lang.RandomStringUtils, which uses
pubRsaDecryptSignedElementExt in MatrixSSL 4.0.1 Open, as used in Inside Secure TLS Toolkit, has a stack-based buffer ov
Hanwha Techwin SRN-4000, SRN-4000 firmware versions prior to SRN4000_v2.16_170401, A specially crafted http request and
An arbitrary memory write vulnerability exists in the dual_onsrv.exe module in Honeywell Experion PKS R40x before R400.6
A file inclusion vulnerability exists in the confd.exe module in Honeywell Experion PKS R40x before R400.6, R41x before
In GraphicsMagick 1.4 snapshot-20190322 Q8, there is a stack-based buffer overflow in the function SVGStartElement of co
The VStarCam vstc.vscam.client library and vstc.vscam shared object, as used in the Eye4 application (for Android, iOS,
application\admin\controller\User.php in ThinkAdmin V4.0 does not prevent continued use of an administrator's cookie-bas
A memory corruption vulnerability exists in the Windows DHCP client when an attacker sends specially crafted DHCP respon
A memory corruption vulnerability exists in the Windows DHCP client when an attacker sends specially crafted DHCP respon
A memory corruption vulnerability exists in the Windows DHCP client when an attacker sends specially crafted DHCP respon
Advantech WebAccess 8.3.4 is vulnerable to file upload attacks via unauthenticated RPC call. An unauthenticated, remote
Roxy Fileman 1.4.5 allows attackers to execute renamefile.php (aka Rename File), createdir.php (aka Create Directory), f
Architectural Information System 1.0 and earlier versions have a Stack-based buffer overflow, allows remote attackers to
A stack-based buffer overflow in Forcepoint Email Security version 8.5 allows an attacker to craft malicious input and p
An elevation of privilege vulnerability exists in the Microsoft Server Message Block (SMB) Server when an attacker with
An elevation of privilege vulnerability exists when Windows Admin Center improperly impersonates operations in certain s
A configuration issue has been discovered in Forcepoint Email Security 8.4.x and 8.5.x: the product is left in a vulnera
An unauthenticated user can execute SQL statements that allow arbitrary read access to the underlying database, which ca
An issue was discovered in Joomla! before 3.9.5. The Media Manager component does not properly sanitize the folder param
The getgrouplist function in the GNU C library (glibc) before version 2.3.5, when invoked with a zero argument, writes t
A certain sequence of valid BGP or IPv6 BFD packets may trigger a stack based buffer overflow in the Junos OS Packet For
When configuring a stateless firewall filter in Junos OS, terms named using the format "internal-n" (e.g. "internal-1",
libxslt through 1.1.33 allows bypass of a protection mechanism because callers of xsltCheckRead and xsltCheckWrite permi
The .NET SDK WebForm Viewer in SAP Crystal Reports for Visual Studio (fixed in version 2010) discloses sensitive databas
lighttpd before 1.4.54 has a signed integer overflow, which might allow remote attackers to cause a denial of service (a
HP LaserJet Enterprise printers, HP PageWide Enterprise printers, HP LaserJet Managed printers, HP Officejet Enterprise
On D-Link DAP-1530 (A1) before firmware version 1.06b01, DAP-1610 (A1) before firmware version 1.06b01, DWR-111 (A1) bef
All versions of SilverStripe 3 prior to 3.6.7 and 3.7.3, and all versions of SilverStripe 4 prior to 4.0.7, 4.1.5, 4.2.4
An issue was discovered in JFrog Artifactory 6.7.3. By default, the access-admin account is used to reset the password o
Auth0 Auth0-WCF-Service-JWT before 1.0.4 leaks the expected JWT signature in an error message when it cannot successfull
An authentication bypass vulnerability in all versions of ValuePLUS Integrated University Management System (IUMS) allow
A buffer overflow has been found in the Zephyr Project's getaddrinfo() implementation in 1.9.0 and 1.10.0.
Within multiple XEROX products a vulnerability allows remote command execution on the Linux system, as the "nobody" user
Moxa IKS-G6824A series Versions 4.5 and prior, EDS-405A series Version 3.8 and prior, EDS-408A series Version 3.8 and pr
IBM BigFix WebUI Profile Management 6 and Software Distribution 23 is vulnerable to SQL injection. A remote attacker cou
IBM API Connect 5.0.0.0 and 5.0.8.6 Developer Portal can be exploited by app developers to download arbitrary files from
Platform dependent weakness. This issue only impacts iSeries platforms. On these platforms, in BIG-IP (LTM, AAM, AFM, An
SQL Injection exists in the Tribulant Slideshow Gallery plugin 1.6.8 for WordPress via the wp-admin/admin.php?page=slide
madskristensen Miniblog.Core through 2019-01-16 allows remote attackers to execute arbitrary ASPX code via an IMG elemen
JFrog Artifactory Pro 6.5.9 has Incorrect Access Control.
A vulnerability has been identified in Spectrum Power 4 (with Web Office Portal). An attacker with network access to the
Apache PDFBox 2.0.14 does not properly initialize the XML parser, which allows context-dependent attackers to conduct XM
An issue was discovered in GitLab Community and Enterprise Edition before 11.6.10, 11.7.x before 11.7.6, and 11.8.x befo
An issue was discovered in GitLab Community and Enterprise Edition 10.x (starting from 10.8) and 11.x before 11.6.10, 11
Contao before 3.5.39 and 4.x before 4.7.3 has a Weak Password Recovery Mechanism for a Forgotten Password.
Contao 4.7 allows Use of a Key Past its Expiration Date.
A vulnerability in the sysadmin virtual machine (VM) on Cisco ASR 9000 Series Aggregation Services Routers running Cisco
An issue was discovered in Motorola CX2 1.01 and M2 1.01. There is a command injection in the function downloadFirmware
Scan for 2019 Vulnerabilities
CyberStrike detects these CVEs across your infrastructure automatically.
Get Started