17,305 vulnerabilities published in 2019
A remote code execution vulnerability exists in the way that the scripting engine handles objects in memory in Microsoft
A remote code execution vulnerability exists in the way that the scripting engine handles objects in memory in Microsoft
A remote code execution vulnerability exists in the way that the scripting engine handles objects in memory in Internet
NULL pointer dereference vulnerability in ZNC before 0.092 caused by traffic stats when there are unauthenticated connec
A double-free vulnerability exists in WebKit in Google Chrome before Blink M12 in the WebCore::CSSSelector function.
The Intercom plugin through 1.2.1 for WordPress leaks a Slack Access Token in source code. An attacker can obtain a lot
WP SlackSync plugin through 1.8.5 for WordPress leaks a Slack Access Token in source code. An attacker can obtain a lot
Slack-Chat through 1.5.5 leaks a Slack Access Token in source code. An attacker can obtain a lot of information about th
Symlink Traversal vulnerability in Belkin N900 due to misconfiguration in the SMB service.
Gauss100 OLTP database in ManageOne with versions of 6.5.0 have an out-of-bounds read vulnerability due to the insuffici
There is an out of bound read vulnerability in some Huawei products. A remote, unauthenticated attacker may send a corru
In PromiseBuiltinsAssembler::NewPromiseCapability of builtins-promise.cc, there is a possible out of bounds read in v8 J
In createProjectionMapForQuery of TvProvider.java, there is possible SQL injection. This could lead to local information
The Device Model in ACRN before 2019w25.5-140000p relies on assert calls in devicemodel/hw/pci/core.c and devicemodel/in
PHP5 before 5.4.4 allows passing invalid utf-8 strings via the xmlTextWriterWriteAttribute, which are then misparsed by
hook_file_download in the CKEditor module 7.x-1.4 for Drupal does not properly restrict access to private files, which a
Trac 0.11.6 does not properly check workflow permissions before modifying a ticket. This can be exploited by an attacker
SibSoft Xfilesharing through 2.5.1 allows op=page&tmpl=../ directory traversal to read arbitrary files.
SnowHaze before 2.6.6 is sometimes too late to honor a per-site JavaScript blocking setting, which leads to unintended J
Moodle has a database activity export permission issue where the export function of the database activity module exports
Moodle before 2.2.2 has users' private files included in course backups
Adobe Bridge CC versions 9.1 and earlier have a memory corruption vulnerability. Successful exploitation could lead to i
Adobe Bridge CC versions 9.1 and earlier have a memory corruption vulnerability. Successful exploitation could lead to i
Moodle before 2.2.2 has an external enrolment plugin context check issue where capability checks are not thorough
Insufficient input validation in Intel(R) Baseboard Management Controller firmware may allow an unauthenticated user to
Unhandled exception in Intel(R) Baseboard Management Controller firmware may allow an unauthenticated user to potentiall
Insufficient input validation in Intel(R) Baseboard Management Controller firmware may allow an unauthenticated user to
Memory corruption in Intel(R) Baseboard Management Controller firmware may allow an unauthenticated user to potentially
A flaw was found in all dpdk version 17.x.x before 17.11.8, 16.x.x before 16.11.10, 18.x.x before 18.11.4 and 19.x.x bef
An Information Disclosure vulnerability exists in Netgear WNDR4700 running firmware 1.0.0.34 in the management web inter
An issue was discovered on Zyxel GS1900 devices with firmware before 2.50(AAHH.0)C0. The firmware image contains encrypt
An issue was discovered on Zyxel GS1900 devices with firmware before 2.50(AAHH.0)C0. By sending a signal to the CLI proc
On Signify Philips Taolight Smart Wi-Fi Wiz Connected LED Bulb 9290022656 devices, an unprotected API lets remote users
Pimcore before 6.2.2 allow attackers to brute-force (guess) valid usernames by using the 'forgot password' functionality
ClamAV before 0.97.7: dbg_printhex possible information leak
Chrony before 1.29.1 has traffic amplification in cmdmon protocol
A Null pointer dereference vulnerability exists in Mozilla Network Security Services due to a missing NULL check in PK11
An access bypass issue was found in Drupal 7.x before version 7.5. If a Drupal site has the ability to attach File uploa
On version 14.0.0-14.1.0.1, BIG-IP virtual servers with TLSv1.3 enabled may experience a denial of service due to undisc
On BIG-IP 14.1.0-14.1.2, 14.0.0-14.0.1, and 13.1.0-13.1.1, undisclosed HTTP requests may consume excessive amounts of sy
When the BIG-IP APM 14.1.0-14.1.2, 14.0.0-14.0.1, 13.1.0-13.1.3.1, 12.1.0-12.1.4.1, or 11.5.1-11.6.5 system processes ce
On BIG-IP 15.0.0 and 14.1.0-14.1.0.6, under certain conditions, network protections on the management port do not follow
MiniUPnP ngiflib 0.4 has a NULL pointer dereference in GifIndexToTrueColor in ngiflib.c via a file that lacks a palette.
iTerm2 through 3.3.6 has potentially insufficient documentation about the presence of search history in com.googlecode.i
Two memory leaks in the v3d_submit_cl_ioctl() function in drivers/gpu/drm/v3d/v3d_gem.c in the Linux kernel before 5.3.1
A memory leak in the crypto_reportstat() function in drivers/virt/vboxguest/vboxguest_utils.c in the Linux kernel before
A memory leak in the unittest_data_add() function in drivers/of/unittest.c in the Linux kernel before 5.3.10 allows atta
A memory leak in the crypto_reportstat() function in crypto/crypto_user_stat.c in the Linux kernel through 5.3.11 allows
A memory leak in the gs_can_open() function in drivers/net/can/usb/gs_usb.c in the Linux kernel before 5.3.11 allows att
A memory leak in the rpmsg_eptdev_write_iter() function in drivers/rpmsg/rpmsg_char.c in the Linux kernel through 5.3.11
Scan for 2019 Vulnerabilities
CyberStrike detects these CVEs across your infrastructure automatically.
Get Started