17,305 vulnerabilities published in 2019
An issue was discovered in the security-framework crate before 0.1.12 for Rust. Hostname verification for certificates d
cli/lib/main.js in Entropic before 2019-06-13 does not reject / and \ in command names, which might allow a directory tr
Various Lexmark products have Incorrect Access Control (issue 1 of 2).
Various Lexmark products have Incorrect Access Control (issue 2 of 2).
The legacy finger service (TCP port 79) is enabled by default on various older Lexmark devices.
/payu/icpcheckout/ in the WooCommerce PayU India Payment Gateway plugin 2.1.1 for WordPress allows Parameter Tampering i
cgi-bin/webscr?cmd=_cart in the WooCommerce PayPal Checkout Payment Gateway plugin 1.6.17 for WordPress allows Parameter
Log viewer in totemomail 6.0.0 build 570 allows access to sessionIDs of high privileged users by leveraging access to a
A vulnerability in the implementation of the Simple Network Management Protocol (SNMP) Access Control List (ACL) feature
Incorrect scoping of kill operations in MongoDB Server's packaged SysV init scripts allow users with write access to the
A path traversal vulnerability in <= v0.9.7 of statichttpserver npm module allows attackers to list files in arbitrary f
On BIG-IP 14.1.0-14.1.0.5, 14.0.0-14.0.0.4, 13.0.0-13.1.2, 12.1.0-12.1.4.1, 11.5.2-11.6.4, when processing authenticatio
In Knowage through 6.1.1, the sign up page does not invalidate a valid CAPTCHA token. This allows for CAPTCHA bypass in
An exploitable information disclosure vulnerability exists in the packet-parsing functionality of Blynk-Library v0.6.1.
In Knowage through 6.1.1, an unauthenticated user can enumerated valid usernames via the ChangePwdServlet page.
In Counter-Strike: Global Offensive before 8/29/2019, community game servers can display unsafe HTML in a disconnection
Silver Peak EdgeConnect SD-WAN before 8.1.7.x allows remote attackers to obtain potentially sensitive stack traces by se
An issue was discovered in Plataformatec Devise before 4.7.1. It confirms accounts upon receiving a request with a blank
An issue was discovered in LibreNMS through 1.47. Information disclosure can occur: an attacker can fingerprint the exac
Seneca < 3.9.0 contains a vulnerability that could lead to exposing environment variables to unauthorized users.
An authorization issue was discovered in the GitLab CE/EE CI badge images endpoint which could result in disclosure of t
An issue was discovered in GitLab Community and Enterprise Edition before 11.8.9, 11.9.x before 11.9.10, and 11.10.x bef
An issue was discovered in GitLab Community and Enterprise Edition before 11.5.8, 11.6.x before 11.6.6, and 11.7.x befor
A path disclosure vulnerability was found in Limesurvey before 3.17.14 that allows a remote attacker to discover the pat
Limesurvey before 3.17.14 does not enforce SSL/TLS usage in the default configuration.
Limesurvey before 3.17.14 allows remote attackers to bruteforce the login form and enumerate usernames when the LDAP aut
OnCommand Workflow Automation versions prior to 5.0 shipped without certain HTTP Security headers configured which could
An issue was discovered in Couchbase Server 5.5.x through 5.5.3 and 6.0.0. The Memcached "connections" stat block comman
OpenSSL 1.1.1 introduced a rewritten random number generator (RNG). This was intended to include protection in the event
In Couchbase Server 6.0.0 and 5.5.0, the eventing service exposes system diagnostic profile via an HTTP endpoint that do
In Mendix 7.23.5 and earlier, issue in XML import mappings allow DOCTYPE declarations in the XML input that is potential
The /rest/api/1.0/render resource in Jira before version 8.4.0 allows remote anonymous attackers to determine if an atta
The /rest/api/latest/groupuserpicker resource in Jira before version 8.4.0 allows remote attackers to enumerate username
McAfee Web Gateway (MWG) earlier than 7.8.2.13 is vulnerable to a remote attacker exploiting CVE-2019-9511, potentially
Easy!Appointments 1.3.2 plugin for WordPress allows Sensitive Information Disclosure (Username and Password Hash).
OpenCV 4.1.1 has an out-of-bounds read in hal_baseline::v_load in core/hal/intrin_sse.hpp when called from computeSSDMea
Cobham Sea Tel v170 224521 through v194 225444 devices allow attackers to obtain potentially sensitive information, such
An issue was discovered in GitLab Community and Enterprise Edition 11.9.x and 11.10.x before 11.10.1. Merge requests cre
An issue was discovered in GitLab Community and Enterprise Edition through 12.2.1. Embedded images and media files in ma
An issue was discovered in GitLab Community and Enterprise Edition 11.2 through 12.2.1. Insufficient permission checks w
An issue was discovered in GitLab Community and Enterprise Edition 12.0 through 12.2.1. Non-members were able to comment
An issue was discovered in GitLab Community and Enterprise Edition 12.2 through 12.2.1. The project import API could be
An issue was discovered in GitLab Community and Enterprise Edition 12.0 through 12.2.1. Under certain conditions, merge
An issue was discovered in GitLab Community and Enterprise Edition 7.9 through 12.2.1. EXIF Geolocation data was not bei
Online upgrade information in some firmware packages of Dahua products is not encrypted. Attackers can obtain this infor
IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 could allow a remote attacker to traverse directories on the sys
SPIP before 3.1.11 and 3.2 before 3.2.5 provides different error messages from the password-reminder page depending on w
A vulnerability in the statistics collection service of Cisco HyperFlex Software could allow an unauthenticated, remote
Some Dahua products have information leakage issues. Attackers can obtain the IP address and device model information of
Pydio 6.0.8 mishandles error reporting when a directory allows unauthenticated uploads, and the remote-upload option is
Scan for 2019 Vulnerabilities
CyberStrike detects these CVEs across your infrastructure automatically.
Get Started