17,305 vulnerabilities published in 2019
parse-server before 3.6.0 allows account enumeration.
Discourse before 2.3.0 and 2.4.x before 2.4.0.beta3 lacks a confirmation screen when logging in via a user-api OTP.
HumHub Social Network Kit Enterprise v1.3.13 allows remote attackers to find the user accounts existing on any Social Ne
edx-platform before 2016-06-10 allows account activation with a spoofed e-mail address.
An issue was discovered in PrinterOn Central Print Services (CPS) through 4.1.4. An unauthenticated attacker can view de
cPanel before 80.0.5 allows local code execution in the context of a different cPanel account because of insecure cpphp
cPanel before 80.0.5 allows demo accounts to modify arbitrary files via the extractfile API1 call (SEC-496).
cPanel before 78.0.2 does not properly restrict demo accounts from writing to files via the DCV UAPI (SEC-473).
cPanel before 74.0.0 allows Apache HTTP Server configuration injection because of DocumentRoot variable interpolation (S
cPanel before 74.0.0 insecurely stores phpMyAdmin session files (SEC-418).
The bin/mkvhostspasswd script in cPanel before 11.54.0.4 discloses password hashes (SEC-73).
cPanel before 64.0.21 allows demo accounts to execute Cpanel::SPFUI API commands (SEC-246).
cPanel before 64.0.21 allows demo accounts to execute SSH API commands (SEC-248).
cPanel before 64.0.21 allows certain file-read operations via a Serverinfo_manpage API call (SEC-252).
cPanel before 64.0.21 allows attackers to read a user's crontab file during a short time interval upon a cPAddon upgrade
A path disclosure vulnerability exists in Magento 2.1 prior to 2.1.18, Magento 2.2 prior to 2.2.9, Magento 2.3 prior to
A cryptograhic flaw in Magento 2.1 prior to 2.1.18, Magento 2.2 prior to 2.2.9, Magento 2.3 prior to 2.3.2 could be abus
An insecure direct object reference (IDOR) vulnerability exists in the RSS feeds of Magento 2.1 prior to 2.1.18, Magento
Samples of disabled downloadable products are accessible in Magento Open Source prior to 1.9.4.2, and Magento Commerce p
Names of disabled downloadable products could be disclosed due to inadequate validation of user input in Magento Open So
cPanel before 60.0.15 does not ensure that system accounts lack a valid password, so that logins are impossible (CPANEL-
Jenkins TestLink Plugin 3.16 and earlier stores credentials unencrypted in its global configuration file on the Jenkins
Wind River VxWorks 6.5, 6.6, 6.7, 6.8, 6.9.3 and 6.9.4 has a Memory Leak in the IGMPv3 client component. There is an IPN
Search Guard versions before 24.0 had an issue that field caps and mapping API leak field names (but not values) for fie
The login.jsp resource in Jira before version 7.13.4, and from version 8.0.0 before version 8.2.2 allows remote attacker
In Joomla! before 3.9.11, inadequate checks in com_contact could allow mail submission in disabled forms.
Under certain conditions, SAP BusinessObjects Business Intelligence Platform (BI Workspace), versions 4.1, 4.2, 4.3, all
During an OData V2/V4 request in SAP Gateway, versions 750, 751, 752, 753, the HTTP Header attributes cache-control and
The FV Flowplayer Video Player plugin before 7.3.15.727 for WordPress allows guests to obtain the email subscription lis
In ClickHouse before 18.12.13, functions for loading CatBoost models allowed path traversal and reading arbitrary files
Zabbix through 4.4.0alpha1 allows User Enumeration. With login requests, it is possible to enumerate application usernam
The Recruitment module in Humanica Humatrix 7 1.0.0.203 and 1.0.0.681 allows an unauthenticated attacker to access all c
An information leakage vulnerability in Iomega and LenovoEMC NAS products could allow disclosure of some device details
plugin/Audit/Objects/AuditTable.php in YouPHPTube through 7.2 allows SQL Injection.
IBM API Connect 2018.1 through 2018.4.1.6 may inadvertently leak sensitive details about internal servers and network vi
Adobe Acrobat and Reader versions 2019.012.20035 and earlier, 2019.012.20035 and earlier, 2017.011.30142 and earlier, 20
An exploitable information disclosure vulnerability exists in the Weave Legacy Pairing functionality of Nest Cam IQ Indo
The total-security plugin before 3.4.1 for WordPress has a settings-change vulnerability.
In CentOS-WebPanel.com (aka CWP) CentOS Web Panel 0.9.8.848, the Login process allows attackers to check whether a usern
AjaxDomainServlet in Zoho ManageEngine ServiceDesk Plus 10 allows User Enumeration. NOTE: the vendor's position is that
Leakage of stack traces in remote access to backup & restore in earlier versions than ProSyst mBS SDK 8.2.6 and Bosch Io
The wp-support-plus-responsive-ticket-system plugin before 4.2 for WordPress has full path disclosure.
The advanced-ajax-page-loader plugin before 2.7.7 for WordPress has no protection against the reading of uploaded files
The Privacy > Phone Number feature in the Telegram app 5.10 for Android and iOS provides an incorrect indication that th
Several worklog rest resources in Jira before version 7.13.7, and from version 8.0.0 before version 8.3.2 allow remote a
The /rest/issueNav/1/issueTable resource in Jira before version 8.3.2 allows remote attackers to enumerate usernames via
Swoole before 4.2.13 allows directory traversal in swPort_http_static_handler.
comelz Quark before 2019-03-26 allows directory traversal to locations outside of the project directory.
An information exposure vulnerability in FortiOS 6.2.3, 6.2.0 and below may allow an unauthenticated attacker to gain pl
An issue was discovered in the hyper crate before 0.9.18 for Rust. It mishandles newlines in headers.
Scan for 2019 Vulnerabilities
CyberStrike detects these CVEs across your infrastructure automatically.
Get Started