17,305 vulnerabilities published in 2019
A plaintext password vulnerability in the Zyxel NAS 326 through 5.21 allows an elevated privileged user to get the admin
Shell Metacharacter Injection in the package installer on Zyxel NAS 326 version 5.21 and below allows an authenticated a
An eval injection vulnerability in the Python web server routing on the Zyxel NAS 326 version 5.21 and below allows a re
GAT-Ship Web Module before 1.40 suffers from a vulnerability allowing authenticated attackers to upload any file type to
Improper access control in the Helpdesk App of Odoo Enterprise 10.0 through 12.0 allows remote authenticated attackers t
VMware Workstation (15.x before 15.0.3, 14.x before 14.1.6) running on Windows does not handle paths appropriately. Succ
VMware Workstation (15.x before 15.0.3, 14.x before 14.1.6) running on Windows does not handle COM classes appropriately
A remote code execution vulnerability exists when the Microsoft XML Core Services MSXML parser processes user input, aka
A remote code execution vulnerability exists when the Microsoft XML Core Services MSXML parser processes user input, aka
A remote code execution vulnerability exists when the Microsoft XML Core Services MSXML parser processes user input, aka
A remote code execution vulnerability exists when the Microsoft XML Core Services MSXML parser processes user input, aka
A remote code execution vulnerability exists when OLE automation improperly handles objects in memory, aka 'OLE Automati
A remote code execution vulnerability exists when the Microsoft XML Core Services MSXML parser processes user input, aka
A remote code execution vulnerability exists in the way that the VBScript engine handles objects in memory, aka 'Windows
A remote code execution vulnerability exists when the IOleCvt interface renders ASP webpage content, aka 'Windows IOleCv
A remote code execution vulnerability exists in the way that the Windows Graphics Device Interface (GDI) handles objects
An issue was discovered in Rancher 2 through 2.1.5. Any project member with access to the default namespace can mount th
In Ubiquiti Networks EdgeSwitch X v1.1.0 and prior, a privileged user can execute arbitrary shell commands over the SSH
In Ubiquiti Networks EdgeSwitch X v1.1.0 and prior, an authenticated user can execute arbitrary shell commands over the
A number of HTTP endpoints in the Airflow webserver (both RBAC and classic) did not have adequate protection and were vu
Kentico CMS before 11.0.45 allows unrestricted upload of a file with a dangerous type.
ABAP BASIS function modules INST_CREATE_R3_RFC_DEST, INST_CREATE_TCPIP_RFCDEST, and INST_CREATE_TCPIP_RFC_DEST in SAP BA
SPIP 3.1 before 3.1.10 and 3.2 before 3.2.4 allows authenticated visitors to execute arbitrary code on the host server b
FastAdmin V1.0.0.20190111_beta has a CSRF vulnerability to add a new admin user via the admin/auth/admin/add?dialog=1 UR
MKCMS V5.0 has a CSRF vulnerability to add a new admin user via the ucenter/userinfo.php URI.
UiPath Orchestrator through 2018.2.4 allows any authenticated user to change the information of arbitrary users (even ad
The Boa server configuration on DASAN H660RM devices with firmware 1.03-0022 logs POST data to the /tmp/boa-temp file, w
An issue was discovered in CMS Made Simple 2.2.8. In the module FrontEndUsers (in the file class.FrontEndUsersManipulate
An issue was discovered in the firewall3 component in Inteno IOPSYS 1.0 through 3.16. The attacker must make a JSON-RPC
AVEVA Wonderware System Platform 2017 Update 2 and prior uses an ArchestrA network user account for authentication of sy
Heap-based Buffer Overflow in Graphite2 library in Firefox before 54 in lz4::decompress function.
Subrion CMS 4.1.5 has CSRF in blog/delete/.
Heap-based Buffer Overflow write in Graphite2 library in Firefox before 54 in lz4::decompress src/Decompressor.
Use of uninitialized memory in Graphite2 library in Firefox before 54 in graphite2::GlyphCache::Loader::read_glyph funct
models/repo_mirror.go in Gitea before 1.7.6 and 1.8.x before 1.8-RC3 mishandles mirror repo URL settings, leading to rem
The WP Fastest Cache plugin 0.8.8.5 for WordPress has CSRF via the wp-admin/admin.php wpfastestcacheoptions page.
There is a CSRF vulnerability in the mndpsingh287 File Manager plugin 3.0 for WordPress via the page=wp_file_manager_roo
A vulnerability has been identified in SINEMA Remote Connect Server (All versions < V2.0). Due to insufficient checking
Contao 4.7 allows CSRF.
A vulnerability in the web-based management interface of Cisco Wireless LAN Controller (WLC) Software could allow an una
A missing permission check in Jenkins GitLab Plugin 1.5.11 and earlier in the GitLabConnectionConfig#doTestConnection fo
Jenkins jira-ext Plugin 0.8 and earlier stored credentials unencrypted in its global configuration file on the Jenkins m
Jenkins Azure PublisherSettings Credentials Plugin 1.2 and earlier stored credentials unencrypted in the credentials.xml
Confluence Server and Data Center had a path traversal vulnerability in the downloadallattachments resource. A remote at
Dell SupportAssist Client versions prior to 3.2.0.90 contain an improper origin validation vulnerability. An unauthentic
MKCMS 5.0 allows remote attackers to take over arbitrary user accounts by posting a username and e-mail address to ucent
libavcodec/hevcdec.c in FFmpeg 3.4 and 4.1.2 mishandles detection of duplicate first slices, which allows remote attacke
The studio profile decoder in libavcodec/mpeg4videodec.c in FFmpeg 4.0 before 4.0.4 and 4.1 before 4.1.2 allows remote a
In floor0_inverse1 of floor0.c, there is a possible out of bounds write due to an incorrect bounds check. This could lea
In numerous hand-crafted functions in libmpeg2, NEON registers are not preserved. This could lead to remote code executi
Scan for 2019 Vulnerabilities
CyberStrike detects these CVEs across your infrastructure automatically.
Get Started