17,305 vulnerabilities published in 2019
NLTK Downloader before 3.4.5 is vulnerable to a directory traversal, allowing attackers to write arbitrary files via a .
Improper Verification of a Cryptographic Signature in OpenPGP.js <=4.1.2 allows an attacker to forge signed messages by
Improper Verification of a Cryptographic Signature in OpenPGP.js <=4.1.2 allows an attacker to pass off unsigned data as
The wp-file-upload plugin before 3.4.1 for WordPress has insufficient restrictions on upload of .php.js files.
The wpgform plugin before 0.94 for WordPress has eval injection in the CAPTCHA calculation.
The webp-express plugin before 0.14.11 for WordPress has insufficient protection against arbitrary file reading.
The wp-file-upload plugin before 2.5.0 for WordPress has insufficient restrictions on upload of .php files.
The wp-file-upload plugin before 2.7.1 for WordPress has insufficient restrictions on upload of .js files.
The wp-file-upload plugin before 3.0.0 for WordPress has insufficient restrictions on upload of php, js, pht, php3, php4
The onelogin-saml-sso plugin before 2.2.0 for WordPress has a hardcoded @@@nopass@@@ password for just-in-time provision
In GalliumOS 3.0, CONFIG_SECURITY_YAMA is disabled but /etc/sysctl.d/10-ptrace.conf tries to set /proc/sys/kernel/yama/p
The import-users-from-csv-with-meta plugin before 1.14.2.1 for WordPress has directory traversal.
An issue was discovered in OpenWrt libuci (aka Library for the Unified Configuration Interface) before 15.05.1 as used o
openITCOCKPIT before 3.7.1 allows deletion of files, aka RVID 4-445b21.
Cuberite before 2019-06-11 allows webadmin directory traversal via ....// because the protection mechanism simply remove
Path traversal vulnerability in Micro Focus Verastream Host Integrator (VHI), versions 7.7 SP2 and earlier, The vulnerab
An issue was discovered in xfs_setattr_nonsize in fs/xfs/xfs_iops.c in the Linux kernel through 5.2.9. XFS partially wed
An issue was discovered in Kaseya Virtual System Administrator (VSA) through 9.4.0.37. It has a critical information dis
rustls-mio/examples/tlsserver.rs in the rustls crate before 0.16.0 for Rust allows attackers to cause a denial of servic
An issue was discovered in the tar crate before 0.4.16 for Rust. Arbitrary file overwrite can occur via a symlink or har
An issue was discovered in the yaml-rust crate before 0.4.1 for Rust. There is uncontrolled recursion during deserializa
An issue was discovered in the trust-dns-proto crate before 0.5.0-alpha.3 for Rust. There is infinite recursion because
An issue was discovered in the orion crate before 0.11.2 for Rust. reset() calls cause incorrect results.
An issue was discovered in the simd-json crate before 0.1.15 for Rust. There is an out-of-bounds read and an incorrect c
An issue was discovered in the memoffset crate before 0.5.0 for Rust. offset_of and span_of can cause exposure of uninit
An issue was discovered in the asn1_der crate before 0.6.2 for Rust. Attackers can trigger memory exhaustion by supplyin
Limesurvey before 3.17.10 does not validate both the MIME type and file extension of an image.
An issue was discovered in the cookie crate before 0.7.6 for Rust. Large integers in the Max-Age of a cookie cause a pan
An issue was discovered in the untrusted crate before 0.6.2 for Rust. Error handling can trigger an integer underflow an
An issue was discovered in the ammonia crate before 2.1.0 for Rust. There is uncontrolled recursion during HTML DOM tree
An issue was discovered in the protobuf crate before 2.6.0 for Rust. Attackers can exhaust all memory via Vec::reserve c
An issue was discovered in the libp2p-core crate before 0.8.1 for Rust. Attackers can spoof ed25519 signatures.
An issue was discovered in the pancurses crate through 0.16.1 for Rust. printw and mvprintw have format string vulnerabi
An issue was discovered in the ncurses crate through 5.99.0 for Rust. There are format string issues in printw functions
OpenBSD kernel version <= 6.5 can be forced to create long chains of TCP SACK holes that causes very expensive calls to
The link-log plugin before 2.0 for WordPress has HTTP Response Splitting.
The sell-downloads plugin before 1.0.8 for WordPress has insufficient restrictions on brute-force guessing of purchase I
The woocommerce-catalog-enquiry plugin before 3.1.0 for WordPress has an incorrect wp_upload directory for file uploads.
In the TCP implementation (gnrc_tcp) in RIOT through 2019.07, the parser for TCP options does not terminate on all input
An issue was discovered in Suricata 4.1.3. If the function filetracker_newchunk encounters an unsafe "Some(sfcm) => { ft
An issue was discovered in Suricata 4.1.3. If the network packet does not have the right length, the parser tries to acc
An issue was discovered in Suricata 4.1.3. The function process_reply_record_v3 lacks a check for the length of reply.da
An issue was discovered in Suricata 4.1.3. The function ftp_pasv_response lacks a check for the length of part1 and part
An issue was discovered in Suricata 4.1.3. The code mishandles the case of sending a network packet with the right type,
Various Lexmark printers contain a denial of service vulnerability in the SNMP service that can be exploited to crash th
nse_libssh2.cc in Nmap 7.70 is subject to a denial of service condition due to a double free when an SSH connection fail
The web api server on Port 8080 of ASUS HG100 firmware up to 1.05.12, which is vulnerable to Slowloris HTTP Denial of Se
A broken access control vulnerability found in Advan VD-1 firmware versions up to 230. An attacker can send a POST reque
A relative path traversal vulnerability found in Advan VD-1 firmware versions up to 230. It allows attackers to download
libZetta.rs through 0.1.2 has an integer overflow in the zpool parser (for error stats) that leads to a panic.
Scan for 2019 Vulnerabilities
CyberStrike detects these CVEs across your infrastructure automatically.
Get Started