17,305 vulnerabilities published in 2019
An issue was discovered in the MailPoet Newsletters (aka wysija-newsletters) plugin before 2.8.2 for WordPress. The plug
The Customer Context Filter in Atlassian Jira Service Desk Server and Jira Service Desk Data Center before 3.9.17, from
In Tasy EMR, Tasy WebPortal Versions 3.02.1757 and prior, there is an information exposure vulnerability which may allow
IBM Cognos Controller stores sensitive information in URL parameters. This may lead to information disclosure if unautho
A vulnerability in the web conference chat component of MiCollab, versions 7.3 PR6 (7.3.0.601) and earlier, and 8.0 (8.0
includes/class-coming-soon-creator.php in the igniteup plugin through 3.4 for WordPress allows information disclosure.
Systematic IRIS WebForms 5.4 is vulnerable to directory traversal. By manipulating variables that reference files with .
An information disclosure vulnerability exists when the Windows TCP/IP stack improperly handles IPv6 flowlabel filled in
A remote file include (RFI) issue was discovered in Enghouse Web Chat 6.2.284.34. One can replace the localhost attribut
SAP UI5 HTTP Handler (corrected in SAP_UI versions 7.5, 7.51, 7.52, 7.53, 7.54 and SAP UI_700 version 2.0) allows an att
Information Disclosure vulnerability in McAfee Advanced Threat Defense (ATD) prior to 4.8 allows remote authenticated at
Information Disclosure vulnerability in McAfee Advanced Threat Defense (ATD prior to 4.8 allows remote authenticated att
Pomelo v2.2.5 allows external control of critical state data. A malicious user input can corrupt arbitrary methods and a
Moodle before 2.2.2 has Personal information disclosure, when administrative setting users name display is set to first
Out of bound read in Intel(R) Baseboard Management Controller firmware may allow an unauthenticated user to potentially
Insufficient access control in Intel(R) Baseboard Management Controller firmware may allow an unauthenticated user to po
An issue was discovered in the rack-cors (aka Rack CORS Middleware) gem before 1.0.4 for Ruby. It allows ../ directory t
An issue was discovered in the AbuseFilter extension through 1.34 for MediaWiki. Once a specific abuse filter has (accid
permission and access control vulnerability, which exists in V2.1.14 and below versions of C520V21 smart camera devices.
When updating a Process Group via the API in NiFi versions 1.3.0 to 1.9.2, the response to the request includes all of i
9base 1:6-6 and 1:6-7 insecurely creates temporary files which results in predictable filenames.
An issue was discovered in Symfony 4.2.0 to 4.2.11 and 4.3.0 to 4.3.7. The ability to enumerate users was possible due t
When a Beckhoff TwinCAT Runtime receives a malformed UDP packet, the ADS Discovery Service shuts down. Note that the Twi
IBM Tivoli Netcool Impact 7.1.0 through 7.1.0.16 generates an error message that includes sensitive information about it
The Mijosoft MijoSearch component 2.0.1 and earlier for Joomla! allows remote attackers to obtain sensitive information
Embedthis GoAhead before 5.0.1 mishandles redirected HTTP requests with a large Host header. The GoAhead WebsRedirect us
Authentication Bypass vulnerability in the Microsoft Windows client in McAfee Client Proxy (MCP) prior to 3.0.0 allows l
UI spoofing in Chromium in Google Chrome prior to 77.0.3865.75 allowed a remote attacker to spoof notifications via a cr
Inappropriate implementation in TLS in Google Chrome prior to 77.0.3865.75 allowed a remote attacker to spoof client IP
Inappropriate implementation in JavaScript in Google Chrome prior to 72.0.3626.81 allowed a remote attacker to leak cros
Insufficient policy enforcement in JavaScript in Google Chrome prior to 78.0.3904.70 allowed a remote attacker to leak c
Nokia IMPACT < 18A has path traversal that may lead to RCE if chained with CVE-2019-1743
Various methods in WEBrick::HTTPRequest in Ruby 1.9.2 and 1.8.7 and earlier do not validate the X-Forwarded-For, X-Forwa
A vulnerability in web interface of the Cisco Webex Event Center, Cisco Webex Meeting Center, Cisco Webex Support Center
A vulnerability in the antispam protection mechanisms of Cisco AsyncOS Software for Cisco Email Security Appliance (ESA)
A vulnerability in the web-based management interface of certain Cisco Small Business RV Series Routers could allow an u
A vulnerability in the access-control logic of the NETCONF over Secure Shell (SSH) of Cisco IOS XR Software may allow co
A vulnerability in the loading mechanism of specific dynamic link libraries in Cisco Webex Teams for Windows could allow
An issue was discovered in GitLab Community and Enterprise Edition 11.3 to 12.3 in the protected environments feature. I
An issue was discovered in GitLab Community and Enterprise Edition 11.3 through 12.4 when moving an issue to a public pr
An issue was discovered in GitLab Community and Enterprise Edition 8.17 through 12.4 in the Search feature provided by E
An issue was discovered in Squid 3.x and 4.x through 4.8. It allows attackers to smuggle HTTP requests through frontend
Ruby through 2.4.7, 2.5.x through 2.5.6, and 2.6.x through 2.6.4 allows HTTP Response Splitting. If a program using WEBr
dirmngr before 2.1.0 improperly handles certain system calls, which allows remote attackers to cause a denial of service
PackageKit 0.6.17 allows installation of unsigned RPM packages as though they were signed which may allow installation o
In Octopus Deploy before 2019.10.7, in a configuration where SSL offloading is enabled, the CSRF cookie was sometimes se
In app/Controller/TagsController.php in MISP 2.4.118, users can bypass intended restrictions on tagging data.
cabextract before 1.6 does not properly check for leading slashes when extracting files, which allows remote attackers t
The Anhui Huami Mi Fit application before 4.0.11 for Android has an Unencrypted Update Check.
The CBC Gem application before 9.24.1 for Android and before 9.26.0 for iOS has Unencrypted Analytics.
Scan for 2019 Vulnerabilities
CyberStrike detects these CVEs across your infrastructure automatically.
Get Started