17,305 vulnerabilities published in 2019
REMISE Payment Module (2.11, 2.12 and 2.13) version 3.0.12 and earlier allow remote attackers to [Disclosed_Information_
An issue was discovered in GitLab Community and Enterprise Edition before 11.4.13, 11.5.x before 11.5.6, and 11.6.x befo
Karotz API 12.07.19.00: Session Token Information Disclosure
IBM Watson Studio Local 1.2.3 could disclose sensitive information over the network that an attacked could use in furthe
_account_forgot_password.ajax.php in MFScripts YetiShare 3.5.2 through 4.5.3 takes a different amount of time to return
_account_forgot_password.ajax.php in MFScripts YetiShare 3.5.2 through 4.5.3 displays a message indicating whether an em
An issue was discovered in GitLab Community and Enterprise Edition before 11.4.13, 11.5.x before 11.5.6, and 11.6.x befo
An issue was discovered in GitLab Community and Enterprise Edition 11.3.x and 11.4.x before 11.4.13, 11.5.x before 11.5.
An issue was discovered in GitLab Enterprise Edition 11.2.x through 11.4.x before 11.4.13, 11.5.x before 11.5.6, and 11.
A vulnerability was found in sssd. If a user was configured with no home directory set, sssd would return '/' (the root
The Ubuntu SELinux initscript before version 1:0.10 used touch to create a lockfile in a world-writable directory. If th
NETGEAR EX7000 V1.0.0.42_1.0.94 devices allow XSS via the SSID.
IBM Cloud Automation Manager 3.1.2 could allow a malicious user on the client side (with access to client computer) to r
A vulnerability in the web-based management interface of Cisco SPA122 ATA with Router Devices could allow an unauthentic
For the printers listed a maliciously crafted print file might cause certain HP Inkjet printers to assert. Under certain
Vulnerability in the Oracle Hospitality Cruise Shipboard Property Management System component of Oracle Hospitality Appl
IBM Security Identity Manager 7.0.1 Virtual Appliance contains hard-coded credentials, such as a password or cryptograph
IBM Security Identity Governance and Intelligence 5.2 through 5.2.4.1 Virtual Appliance contains hard-coded credentials,
Denial of service issue in Micro Focus Solutions Business Manager (SBM) (formerly Serena Business Manager (SBM)) version
IBM Spectrum Protect 7.1 and 8.1 is affected by a password exposure vulnerability caused by insecure file permissions. I
A security feature bypass exists in Azure SSH Keypairs, due to a change in the provisioning logic for some Linux images
A vulnerability in the search path processing of Cisco Directory Connector could allow an authenticated, local attacker
A flaw was found in Mercurial before 4.9. It was possible to use symlinks and subrepositories to defeat Mercurial's path
Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: Replication). Supported versions that
The HPE Nonstop Maintenance Entity family of products are vulnerable to local disclosure of information, such as system
Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: Security: Privileges). Supported vers
Vulnerability in the Java SE component of Oracle Java SE (subcomponent: Security). Supported versions that are affected
The nfs-utils package in SUSE Linux Enterprise Server 12 before and including version 1.3.0-34.18.1 and in SUSE Linux En
The /usr/sbin/pinger binary packaged with squid in SUSE Linux Enterprise Server 15 before and including version 4.8-5.8.
Insufficient access control in firmware Intel(R) Ethernet 700 Series Controllers versions before 7.0 may allow a privile
Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: Packaging). Supported versions that a
An attacker could inject commands to delete files and/or delete the contents of a file on CX-Supervisor (Versions 3.42 a
A vulnerability in the web interface of Cisco TelePresence Conductor, Cisco Expressway Series, and Cisco TelePresence Vi
When CX-Supervisor (Versions 3.42 and prior) processes project files and tampers with the value of an offset, an attacke
An issue was discovered in SoX 14.4.2. lsx_make_lpf in effect_i_dsp.c has an integer overflow on the result of multiplic
An out of bounds read flaw was discovered in libssh2 before 1.8.1 when a specially crafted SFTP packet is received from
An out of bounds read flaw was discovered in libssh2 before 1.8.1 in the way SFTP packets with empty payloads are parsed
An out of bounds read flaw was discovered in libssh2 before 1.8.1 in the way SSH packets with a padding length value gre
Reflected cross site script issue in Micro Focus Solutions Business Manager (SBM) (formerly Serena Business Manager (SBM
A denial of service issue was addressed with improved validation. This issue affected versions prior to iOS 12, macOS Mo
In rw_i93_sm_detect_ndef of rw_i93.cc, there is a possible out-of-bound read due to a missing bounds check. This could l
In rw_i93_process_ext_sys_info of rw_i93.cc, there is a possible out-of-bound read due to a missing bounds check. This c
In Kubernetes v1.8.x-v1.14.x, schema info is cached by kubectl in the location specified by --cache-dir (defaulting to $
Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: WLS Core Components). S
A security feature bypass vulnerability exists in Edge that allows for bypassing Mark of the Web Tagging (MOTW). Failing
An elevation of privilege vulnerability exists when the Visual Studio updater service improperly handles file permission
A flaw was discovered in fence-agents, prior to version 4.3.4, where using non-ASCII characters in a guest VM's comment
cPanel before 64.0.21 allows demo accounts to redirect web traffic (SEC-245).
In NFC, there is a possible out of bounds read due to a missing bounds check. This could lead to local information discl
In NFC, there is a possible out of bounds read due to a missing bounds check. This could lead to local information discl
Scan for 2019 Vulnerabilities
CyberStrike detects these CVEs across your infrastructure automatically.
Get Started