17,305 vulnerabilities published in 2019
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: EJB Container). Supported ve
Vulnerability in the MySQL Connectors product of Oracle MySQL (component: Connector/ODBC). Supported versions that are a
Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Security: Encryption). Supported versions
Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Security: Encryption). Supported versions
Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Security: Encryption). Supported versions
Vulnerability in the Siebel UI Framework product of Oracle Siebel CRM (component: EAI). Supported versions that are affe
Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: C API). Supported versions that are affect
Vulnerability in the PeopleSoft Enterprise SCM eProcurement product of Oracle PeopleSoft (component: eProcurement). The
Vulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Fusion Middleware (component: BI
Vulnerability in the Oracle Application Object Library product of Oracle E-Business Suite (component: Login Help). Suppo
A vulnerability in the web-based management interface of Cisco Identity Services Engine (ISE) Software could allow an un
In WordPress before 5.2.4, unauthenticated viewing of certain content is possible because the static query property is m
Information Disclosure is possible on WAGO Series PFC100 and PFC200 devices before FW12 due to improper access control.
PluginServlet.java in Ignite Realtime Openfire through 4.4.2 does not ensure that retrieved files are located under the
In IP-AK2 Access Control Panel Version 1.04.07 and prior, the integrated web server of the affected devices could allow
The web interface of the Compal Broadband CH7465LG modem (version CH7465LG-NCIP-6.12.18.25-2p6-NOSH) is vulnerable to a
IBM Security Guardium Big Data Intelligence (SonarG) 4.0 discloses sensitive information to unauthorized users. The info
IBM API Connect version V5.0.0.0 through 5.0.8.7 could reveal sensitive information to an attacker using a specially cra
An issue was discovered in the AbuseFilter extension through 1.34 for MediaWiki. Previously hidden (restricted) AbuseFil
Elasticsearch versions 7.0.0-7.3.2 and 6.7.0-6.8.3 contain a username disclosure flaw was found in the API Key service.
ClipSoft REXPERT 1.0.0.527 and earlier version have an information disclosure issue. When requesting web page associated
Transmission before 1.92 allows attackers to prevent download of a file by corrupted data during the endgame.
Jupyter Notebook before 5.5.0 does not use a CSP header to treat served files as belonging to a separate origin. Thus, f
In JetBrains Hub versions earlier than 2019.1.11738, username enumeration was possible through password recovery.
JetBrains IntelliJ IDEA before 2019.2 allows local user privilege escalation, potentially leading to arbitrary code exec
JetBrains MPS before 2019.2.2 exposed listening ports to the network.
In JetBrains TeamCity before 2019.1.2, access could be gained to the history of builds of a deleted build configuration
In JetBrains TeamCity before 2019.1.2, secure values could be exposed to users with the "View build runtime parameters a
In JetBrains TeamCity before 2019.1.2, a non-destructive operation could be performed by a user without the correspondin
In JetBrains YouTrack before 2019.2.55152, removing tags from the issues list without the corresponding permission was p
On Coldcard MK1 and MK2 devices, a side channel for the row-based OLED display was found. The power consumption of each
ClickHouse before 19.13.5.44 allows HTTP header injection via the url table function.
A casting error in Chicken before 4.8.0 on 64-bit platform caused the random number generator to return a constant value
An issue was discovered in the Infosysta "In-App & Desktop Notifications" app 1.6.13_J8 for Jira. It is possible to obta
An issue was discovered in the Infosysta "In-App & Desktop Notifications" app before 1.6.14_J8 for Jira. It is possible
The Wireless Emergency Alerts (WEA) protocol allows remote attackers to spoof a Presidential Alert because cryptographic
Cryptocat before 2.0.22 Link Markup Decorator HTML Handling Weakness
Cryptocat before 2.0.22 has Nickname User Impersonation
TYPO3 before 4.1.14, 4.2.x before 4.2.13, 4.3.x before 4.3.4 and 4.4.x before 4.4.1 contains insecure randomness in the
TYPO3 before 4.1.14, 4.2.x before 4.2.13, 4.3.x before 4.3.4 and 4.4.x before 4.4.1 allows Spam Abuse in the native form
Cryptocat has an Unspecified Chat Participant User List Disclosure
Horde Groupware Web mail 5.1.2 has CSRF with requests to change permissions
TYPO3 before 4.2.13, 4.3.x before 4.3.4 and 4.4.x before 4.4.1 allows information disclosure in the mail header of the H
A vulnerability in the protocol detection component of Cisco Firepower Threat Defense Software, Cisco FirePOWER Services
A vulnerability in the HTTP traffic filtering component of Cisco Firepower Threat Defense Software, Cisco FirePOWER Serv
Magento 2.2 prior to 2.2.10, Magento 2.3 prior to 2.3.3 or 2.3.2-p1 uses cryptographically weak random number generator
Magento 2.1 prior to 2.1.19, Magento 2.2 prior to 2.2.10, Magento 2.3 prior to 2.3.3 uses weak cryptographic function to
An insufficient logging and monitoring vulnerability exists in Magento 1 prior to 1.9.4.3 and 1.14.4.3, Magento 2.1 prio
An issue was discovered in Joomla! before 3.9.13. A missing access check in the phputf8 mapping files could lead to a pa
Computing For Good's Basic Laboratory Information System (also known as C4G BLIS) version 3.5 and earlier suffers from a
Scan for 2019 Vulnerabilities
CyberStrike detects these CVEs across your infrastructure automatically.
Get Started