17,305 vulnerabilities published in 2019
Anviz access control devices expose private Information (pin code and name) by allowing remote attackers to query this i
In jpv (aka Json Pattern Validator) before 2.1.1, compareCommon() can be bypassed because certain internal attributes ca
A vulnerability exists in libgwenhywfar through 4.12.0 due to the usage of outdated bundled CA certificates.
Improper Check for filenames with overly long extensions in PostMaster (sending in email) or uploading files (e.g. attac
A Security Bypass vulnerability exists in the phpCAS 1.2.2 library from the jasig project due to the way proxying of ser
In Puma before versions 3.12.2 and 4.3.1, a poorly-behaved client could use keepalive requests to monopolize Puma's reac
SROS 2 0.8.1 (which provides the tools that generate and distribute keys for Robot Operating System 2 and uses the under
SROS 2 0.8.1 (after CVE-2019-19625 is mitigated) leaks ROS 2 node-related information regardless of the rtps_protection_
There is an overflow bug in the x64_64 Montgomery squaring procedure used in exponentiation with 512-bit moduli. No EC a
The Last.fm desktop app (Last.fm Scrobbler) through 2.1.39 on macOS makes HTTP requests that include an API key without
All Samba versions 4.x.x before 4.9.17, 4.10.x before 4.10.11 and 4.11.x before 4.11.3 have an issue, where the (poorly
Foreman has improper input validation which could lead to partial Denial of Service
wolfSSL and wolfCrypt 4.1.0 and earlier (formerly known as CyaSSL) generate biased DSA nonces. This allows a remote atta
A vulnerability has been identified in Desigo PX automation controllers PXC00-E.D, PXC50-E.D, PXC100-E.D, PXC200-E.D wit
A vulnerability has been identified in EN100 Ethernet module DNP3 variant (All versions), EN100 Ethernet module IEC 6185
A vulnerability has been identified in SPPA-T3000 Application Server (All versions < Service Pack R8.2 SP2). The Applica
A vulnerability has been identified in SPPA-T3000 Application Server (All versions < Service Pack R8.2 SP2). The Applica
A vulnerability has been identified in SPPA-T3000 MS3000 Migration Server (All versions). An attacker with network acces
A vulnerability has been identified in SPPA-T3000 Application Server (All versions < Service Pack R8.2 SP2). An attacker
A vulnerability has been identified in SPPA-T3000 Application Server (All versions < Service Pack R8.2 SP2). An attacker
A vulnerability has been identified in SPPA-T3000 Application Server (All versions < Service Pack R8.2 SP2). An attacker
A vulnerability has been identified in SPPA-T3000 Application Server (All versions < Service Pack R8.2 SP2). An attacker
A vulnerability has been identified in SPPA-T3000 Application Server (All versions < Service Pack R8.2 SP2). An attacker
A vulnerability has been identified in Control Center Server (CCS) (All versions < V1.5.0). The SFTP service (default po
In Dovecot before 2.3.9.2, an attacker can crash a push-notification driver with a crafted email when push notifications
Some Huawei smart phones have a null pointer dereference vulnerability. An attacker crafts specific packets and sends to
Barco ClickShare Button R9861500D01 devices before 1.9.0 allow Information Exposure. The encrypted ClickShare Button fir
Improper conditions check in multiple Intel® Processors may allow an authenticated user to potentially enable partial es
In Apache Incubator Superset before 0.31 user could query database metadata information from a database he has no access
In Apache Incubator Superset before 0.32, a user can view database names that he has no access to on a dropdown list in
Contao 4.0 through 4.8.5 has Insecure Permissions. Back end users can manipulate the details view URL to show pages and
Jenkins SCTMExecutor Plugin 2.2 and earlier transmits previously configured service credentials in plain text as part of
Contao 4.8.4 and 4.8.5 has Improper Encoding or Escaping of Output. It is possible to inject insert tags into the login
In Joomla! before 3.9.14, a missing access check in framework files could lead to a path disclosure.
This issue was addressed with improved checks. This issue is fixed in iOS 12.4, macOS Mojave 10.14.6. A remote attacker
An inconsistent user interface issue was addressed with improved state management. This issue is fixed in macOS Mojave 1
A logic issue existed with the display of notification previews. This issue was addressed with improved validation. This
The issue was addressed with improved handling of service worker lifetime. This issue is fixed in Safari 13.0.1. Service
"Clear History and Website Data" did not clear the history. The issue was addressed with improved data deletion. This is
An exploitable information exposure vulnerability exists in the iocheckd service "I/O-Check" functionality of WAGO PFC20
An improper access control vulnerability exists in Gitlab EE <v12.3.3, <v12.2.7, & <v12.1.13 that allowed the group sear
A flaw was found in Ansible Tower, versions 3.6.x before 3.6.2 and 3.5.x before 3.5.4, when /websocket is requested and
On BIG-IP versions 15.0.0-15.0.1, 14.1.0-14.1.2.2, 14.0.0-14.0.1, and 13.1.0-13.1.3.1, the TMM process may restart when
On BIG-IP versions 15.0.0-15.0.1.1, 14.1.0-14.1.2, 14.0.0-14.0.1, 13.1.0-13.1.3.1, the Traffic Management Microkernel (T
All versions up to V4.01.01.02 of ZTE ZXCLOUD GoldenData VAP product have a file reading vulnerability. Attackers could
SQLite 3.30.1 mishandles certain parser-tree rewriting, related to expr.c, vdbeaux.c, and window.c. This is caused by in
In wolfSSL before 4.3.0, wc_ecc_mulmod_ex does not properly resist side-channel attacks.
An issue was discovered in wolfSSL before 4.3.0 in a non-default configuration where DSA is enabled. DSA signing uses th
The WordPress plugin, Email Subscribers & Newsletters, before 4.2.3 had a flaw that allowed for unauthenticated option c
The WordPress plugin, Email Subscribers & Newsletters, before 4.2.3 had a flaw that allowed unauthenticated file downloa
Scan for 2019 Vulnerabilities
CyberStrike detects these CVEs across your infrastructure automatically.
Get Started