17,305 vulnerabilities published in 2019
A flaw during verification of certain S/MIME signatures causes emails to be shown in Thunderbird as having a valid digit
Cross-origin images can be read in violation of the same-origin policy by exporting an image after using createImageBitm
Firefox will accept any registered Program ID as an external protocol handler and offer to launch this local application
If WebRTC permission is requested from documents with data: or blob: URLs, the permission notifications do not properly
dhcp.c in dhcpcd before 7.2.1 contains a 1-byte read overflow with DHO_OPTSOVERLOADED.
IBM Emptoris Contract Management 10.0.0 and 10.1.3.0 could disclose sensitive information from detailed information from
routers/ajaxRouter.php in doorGets 7.0 has a web site physical path leakage vulnerability, as demonstrated by an ajax/in
Crestron AM-100 with firmware 1.6.0.2 and AM-101 with firmware 2.7.0.2 allow any user to obtain the presentation passcod
Crestron AM-100 with firmware 1.6.0.2 and AM-101 with firmware 2.7.0.2 allows anyone to bypass the presentation code sim
Crestron AM-100 with firmware 1.6.0.2 and AM-101 with firmware 2.7.0.2 allows anyone to bypass the presentation code sen
A vulnerability in the web-based management interface of Cisco Application Policy Infrastructure Controller (APIC) Softw
A vulnerability in the remote access VPN session manager of Cisco Adaptive Security Appliance (ASA) Software could allow
A vulnerability in the Deterministic Random Bit Generator (DRBG), also known as Pseudorandom Number Generator (PRNG), us
A vulnerability in certain attachment detection mechanisms of the Cisco Email Security Appliance (ESA) could allow an un
On BIG-IP 13.0.0-13.1.1.4, 12.1.0-12.1.4, 11.6.1-11.6.3.4, and 11.5.2-11.5.8, SNMP may expose sensitive configuration ob
An exploitable information disclosure vulnerability exists in the ACEManager functionality of Sierra Wireless AirLink ES
An issue was discovered in the Ascensia Contour NEXT ONE application for iOS and Android before 2019-01-15. An attacker
The WebUI of PHOENIX CONTACT FL SWITCH 3xxx, 4xxx, 48xx versions 1.0 to 1.34 leaks private information in firmware image
IBM Cloud App Management V2018.2.0, V2018.4.0, and V2018.4.1 could allow an attacker to obtain sensitive configuration i
Information exposure through the directory listing in npm's harp module allows to access files that are supposed to be i
Path traversal using symlink in npm harp module versions <= 0.29.0.
An issue was discovered in WSO2 API Manager 2.6.0. Uploaded documents for API documentation are available to an unauthen
The Spotfire library component of TIBCO Software Inc.'s TIBCO Spotfire Analytics Platform for AWS Marketplace, and TIBCO
An Information Exposure issue (issue 1 of 2) was discovered in GitLab Community and Enterprise Edition before 11.7.8, 11
A security feature bypass vulnerability exists in Windows Defender Application Control (WDAC) which could allow an attac
An elevation of privilege vulnerability exists in Microsoft Azure Active Directory Connect build 1.3.20.0, which allows
An issue was discovered in OpenEMR before 5.0.1 Patch 7. Directory Traversal exists via docid=../ to /portal/lib/downloa
IBM Cloud Private Kubernetes API server 2.1.0, 3.1.0, 3.1.1, and 3.1.2 can be used as an HTTP proxy to not only cluster
GAT-Ship Web Module through 1.30 allows remote attackers to obtain potentially sensitive information via {} in a ws/gats
IBM Storwize V7000 Unified (2073) 1.6 configuration may allow an attacker to reveal the server version in default instal
WordPress 4.7.2 mishandles listings of post authors, which allows remote attackers to obtain sensitive information (Path
The ManageFilters.jspa resource in Jira before version 7.13.3 and from version 8.0.0 before version 8.1.1 allows remote
The /rest/api/2/user/picker rest resource in Jira before version 7.13.3, from version 8.0.0 before version 8.0.4, and fr
OX Software GmbH OX App Suite 7.8.4 and earlier is affected by: Information Exposure.
Open-Xchange GmbH OX App Suite 7.8.3 and earlier is affected by: Content Spoofing.
A Environment (CWE-2) vulnerability exists in SoMachine Basic, all versions, and Modicon M221(all references, all versio
A CWE-807: Reliance on Untrusted Inputs in a Security Decision vulnerability exists in all versions of the Modicon M580,
An issue was discovered in ZOHO ManageEngine Applications Manager 12.3. It is possible for an unauthenticated user to vi
An issue was discovered in Bitdefender Engines before 7.76662. A vulnerability has been discovered in the iso.xmd parser
An issue was discovered in Bitdefender Engines before 7.76675. A vulnerability has been discovered in the rar.xmd parser
An issue was discovered in Bitdefender Engines before 7.76808. A vulnerability has been discovered in the dalvik.xmd par
Computrols CBAS 18.0.0 allows Username Enumeration.
In Webbukkit Dynmap 3.0-beta-3 or below, due to a missing login check in servlet/MapStorageHandler.java, an attacker can
An Information Exposure vulnerability in Fortinet FortiOS 6.0.1, 5.6.5 and below, allow attackers to learn private IP as
A potential improper access control vulnerability exists in the JSON-RPC interface of the Bosch Smart Home Controller (S
FileRun 2019.05.21 allows images/extjs Directory Listing. This issue has been fixed in FileRun 2019.06.01.
FileRun 2019.05.21 allows css/ext-ux Directory Listing. This issue has been fixed in FileRun 2019.06.01.
FileRun 2019.05.21 allows customizables/plugins/audio_player Directory Listing. This issue has been fixed in FileRun 201
An issue was discovered in Synacor Zimbra Collaboration Suite 8.6.x before 8.6.0 Patch 11, 8.7.x before 8.7.11 Patch 6,
An unauthenticated attacker can obtain information about the Pydio 8.2.2 configuration including session timeout, librar
Scan for 2019 Vulnerabilities
CyberStrike detects these CVEs across your infrastructure automatically.
Get Started