17,305 vulnerabilities published in 2019
When using the Azure backend with a shared access signature (SAS), Terraform versions prior to 0.12.17 may transmit the
webauth before 4.6.1 has authentication credential disclosure
The asn1_signature function in asn1.c in Cameron Hamilton-Rich axTLS through 2.1.5 has a Buffer Overflow that allows rem
process_certificate in tls1.c in Cameron Hamilton-Rich axTLS through 2.1.5 has a Buffer Overflow via a crafted TLS certi
A denial-of-service vulnerability exists in the processing of multi-part/form-data requests in the base GoAhead web serv
An exploitable denial-of-service vulnerability exists in the UDPRelay functionality of Shadowsocks-libev 3.3.2. When uti
TrevorC2 v1.1/v1.2 fails to prevent fingerprinting primarily via a discrepancy between response headers when responding
In Mcrouter prior to v0.41.0, the deprecated ASCII parser would allocate a buffer to a user-specified length with no max
In Mcrouter prior to v0.41.0, a large struct input provided to the Carbon protocol reader could result in stack exhausti
This improper access control vulnerability in Helpdesk allows attackers to access the system logs. To fix the vulnerabil
The AsyncResponseWrapperImpl class in Apache Olingo versions 4.0.0 to 4.6.0 reads the Retry-After header and passes it t
An issue was discovered in Decentralized Anonymous Payment System (DAPS) through 2019-08-26. The content to be signed is
In Wireshark 3.0.0 to 3.0.6 and 2.6.0 to 2.6.12, the CMS dissector could crash. This was addressed in epan/dissectors/as
The validators package 0.12.2 through 0.12.5 for Python enters an infinite loop when validators.domain is called with a
Insufficient checks in the finite state machine of the ShapeShift KeepKey hardware wallet before firmware 6.2.2 allow a
In nfcManager_routeAid and nfcManager_unrouteAid of NativeNfcManager.cpp, there is possible memory reuse due to a use af
In handleRun of TextLine.java, there is a possible application crash due to improper input validation. This could lead t
An issue was discovered in T24 in TEMENOS Channels R15.01. The login page presents JavaScript functions to access a docu
Off-by-one error in the readBuf function in listener.cpp in libcapsinetwork and monopd before 0.9.8, allows remote attac
SQLite 3.30.1 mishandles certain SELECT statements with a nonexistent VIEW, leading to an application crash.
mod_wsgi module before 3.4 for Apache, when used in embedded mode, might allow remote attackers to obtain sensitive info
openstack-utils openstack-db has insecure password creation
Katello has a Denial of Service vulnerability in API OAuth authentication
kde-workspace before 4.10.5 has a memory leak in plasma desktop
A denial of service vulnerability has been reported in Lenovo Energy Management Driver for Windows 10 versions prior to
The modoboa-dmarc plugin 1.1.0 for Modoboa is vulnerable to an XML External Entity Injection (XXE) attack when processin
A denial of service vulnerability exists in Remote Desktop Protocol (RDP) when an attacker connects to the target system
A remote code execution vulnerability exists in the way that the VBScript engine handles objects in memory, aka 'VBScrip
An information disclosure vulnerability exists when the Windows Remote Desktop Protocol (RDP) fails to properly handle o
Type confusion in xsltNumberFormatGetMultipleLevel prior to libxslt 1.1.33 could allow attackers to potentially exploit
On Moxa EDS-G508E, EDS-G512E, and EDS-G516E devices (with firmware through 6.0), denial of service can occur via PROFINE
RubyGem omniauth-facebook has an access token security vulnerability
An issue was discovered in Xen through 4.12.x allowing x86 HVM/PVH guest OS users to cause a denial of service (guest OS
AirLive POE-2600HD allows remote attackers to cause a denial of service (device reset) via a long URL.
An issue was discovered in Squiz Matrix CMS 5.5.0 prior to 5.5.0.3, 5.5.1 prior to 5.5.1.8, 5.5.2 prior to 5.5.2.4, and
An issue was discovered in the BSON ObjectID (aka bson-objectid) package 1.3.0 for Node.js. ObjectID() allows an attacke
SAP Enable Now, before version 1911, leaks information about network configuration in the server error messages, leading
SAP Enable Now, before version 1911, leaks information about the existence of a particular user which can be used to con
Unauthorized file download vulnerability in all supported versions of Micro Focus AcuToWeb. The vulnerability could be e
An exploitable information disclosure vulnerability exists in the DICOM packet-parsing functionality of LEADTOOLS libltd
An exploitable denial-of-service vulnerability exists in the Dicom-packet parsing functionality of LEADTOOLS libltdic.so
The Alias feature in SnakeYAML before 1.26 allows entity expansion during a load operation, a related issue to CVE-2003-
Infinite loop while decoding compressed data can lead to overrun condition in Snapdragon Auto, Snapdragon Compute, Snapd
Out of bound read would occur while trying to read action category and action ID without validating the action length of
While Skipping unknown IES, EMM is reading the buffer even if the no of bytes to read are more than message length which
A vulnerability has been identified in EN100 Ethernet module DNP3 variant (All versions), EN100 Ethernet module IEC 6185
A vulnerability has been identified in SPPA-T3000 MS3000 Migration Server (All versions). An attacker with network acces
A vulnerability has been identified in SPPA-T3000 MS3000 Migration Server (All versions). An attacker with network acces
A vulnerability has been identified in SPPA-T3000 MS3000 Migration Server (All versions). An attacker with network acces
A vulnerability has been identified in SPPA-T3000 MS3000 Migration Server (All versions). An attacker with network acces
Scan for 2019 Vulnerabilities
CyberStrike detects these CVEs across your infrastructure automatically.
Get Started