17,305 vulnerabilities published in 2019
A vulnerability in the Sender Policy Framework (SPF) functionality of Cisco AsyncOS Software for Cisco Email Security Ap
A vulnerability in the web interface of Cisco IoT Field Network Director could allow an unauthenticated, remote attacker
An issue was discovered in the 3CX Phone system (web) management console 12.5.44178.1002 through 12.5 SP2. The Content.M
admin/includes/class.actions.snippet.php in the "Woody ad snippets" plugin through 2.2.5 for WordPress allows wp-admin/a
The "Security and Privacy" Encryption feature in Mailpile before 1.0.0rc4 does not exclude disabled, revoked, and expire
The Meta Box plugin before 4.16.2 for WordPress mishandles the uploading of files to custom folders.
Pallets Werkzeug before 0.15.3, when used with Docker, has insufficient debugger PIN randomness because Docker container
Wind River VxWorks 6.6, 6.7, 6.8, 6.9 and vx7 has an array index error in the IGMPv3 client component. There is an IPNET
Wind River VxWorks 6.6 through vx7 has Session Fixation in the TCP component. This is a IPNET security vulnerability: Do
An issue was discovered in GCDWebServer before 3.5.3. The method moveItem in the GCDWebUploader class checks the FileExt
The Recruitment module in Humanica Humatrix 7 1.0.0.681 and 1.0.0.203 allows remote attackers to access all candidates'
The Telenav Scout GPS Link app 1.x for iOS, as used with Toyota and Lexus vehicles, has an incorrect protection mechanis
Search Guard versions before 24.0 had an issue that values of string arrays in documents are not properly anonymized.
Search Guard versions before 23.1 had an issue that for aggregations clear text values of anonymised fields were leaked.
Istio before 1.1.13 and 1.2.x before 1.2.4 mishandles regular expressions for long URIs, leading to a denial of service
A vulnerability has been identified in SIMATIC Drive Controller family (All versions), SIMATIC ET 200SP Open Controller
Some HTTP/2 implementations are vulnerable to window size manipulation and stream prioritization manipulation, potential
Some HTTP/2 implementations are vulnerable to ping floods, potentially leading to a denial of service. The attacker send
Some HTTP/2 implementations are vulnerable to resource loops, potentially leading to a denial of service. The attacker c
Some HTTP/2 implementations are vulnerable to a reset flood, potentially leading to a denial of service. The attacker op
Some HTTP/2 implementations are vulnerable to a settings flood, potentially leading to a denial of service. The attacker
Some HTTP/2 implementations are vulnerable to unconstrained interal data buffering, potentially leading to a denial of s
Some HTTP/2 implementations are vulnerable to a flood of empty frames, potentially leading to a denial of service. The a
handle_messages in eXtl_tls.c in eXosip before 5.0.0 mishandles a negative value in a content-length header.
Zoho ManageEngine ServiceDesk Plus 10 before 10509 allows unauthenticated sensitive information leakage during Fail Over
eQ-3 Homematic CCU2 outdated base software packages allows Denial of Service. CCU2 affected versions: 2.35.16, 2.41.5, 2
A remote code execution vulnerability exists when the Microsoft XML Core Services MSXML parser processes user input. An
A remote code execution vulnerability exists in the way that the scripting engine handles objects in memory in Internet
A remote code execution vulnerability exists in Microsoft Windows that could allow remote code execution if a .LNK file
A remote code execution vulnerability exists in the way that the scripting engine handles objects in memory in Internet
A memory corruption vulnerability exists in the Windows Server DHCP service when an attacker sends specially crafted pac
A denial of service vulnerability exists in Remote Desktop Protocol (RDP) when an attacker connects to the target system
An information disclosure vulnerability exists when the Windows RDP server improperly discloses the contents of its memo
An information disclosure vulnerability exists when the Windows RDP server improperly discloses the contents of its memo
Due to incorrect string termination, Squid cachemgr.cgi 4.0 through 4.7 may access unallocated memory. On systems with m
ClickHouse MySQL client before versions 1.1.54390 had "LOAD DATA LOCAL INFILE" functionality enabled that allowed a mali
An issue was discovered in 3S-Smart CODESYS V3 products. A crafted communication request may cause uncontrolled memory a
HTTP/2 (2.4.20 through 2.4.39) very early pushes, for example configured with "H2PushResource", could lead to an overwri
drivers/net/wireless/ath/ath10k/usb.c in the Linux kernel through 5.2.8 has a NULL pointer dereference via an incomplete
Creative Cloud Desktop Application versions 4.6.1 and earlier have a security bypass vulnerability. Successful exploitat
Creative Cloud Desktop Application 4.6.1 and earlier versions have an insecure transmission of sensitive data vulnerabil
The invite-anyone plugin before 1.3.16 for WordPress has incorrect escaping of untrusted Dashboard and front-end input.
REDCap before 9.3.0 allows time-based SQL injection in the edit calendar event via the cal_id parameter, such as cal_id=
RIOT through 2019.07 contains a memory leak in the TCP implementation (gnrc_tcp), allowing an attacker to consume all me
The handshake protocol in Object Management Group (OMG) DDS Security 1.1 sends cleartext information about all of the ca
The Access Control plugin in eProsima Fast RTPS through 1.9.0 does not check partition permissions from remote participa
The Access Control plugin in eProsima Fast RTPS through 1.9.0 allows fnmatch pattern matches with topic name strings (in
The SweetXml (aka sweet_xml) package through 0.6.6 for Erlang and Elixir allows attackers to cause a denial of service (
In Envoy through 1.11.1, users may configure a route to match incoming path headers via the libstdc++ regular expression
The awesome-support plugin before 3.1.7 for WordPress has a security issue in which shortcodes are allowed in replies.
Scan for 2019 Vulnerabilities
CyberStrike detects these CVEs across your infrastructure automatically.
Get Started