17,305 vulnerabilities published in 2019
cgi-bin/qcmap_web_cgi on JioFi 4G M2S 1.0.2 devices allows a DoS (Hang) via the mask POST parameter.
JioFi 4G M2S 1.0.2 devices have CSRF via the SSID name and Security Key field under Edit Wi-Fi Settings (aka a SetWiFi_S
cgi-bin/webscr?cmd=_cart in the WooCommerce PayPal Checkout Payment Gateway plugin 1.6.8 for WordPress allows Parameter
PDFDoc::markObject in PDFDoc.cc in Poppler 0.74.0 mishandles dict marking, leading to stack consumption in the function
An issue was discovered in lib\cdt\dttree.c in libcdt.a in graphviz 2.40.1. Stack consumption occurs because of recursiv
A vulnerability was found in PowerDNS Authoritative Server before 4.0.7 and before 4.1.7. An insufficient validation of
Open Whisper Signal (aka Signal-Desktop) through 1.23.1 and the Signal Private Messenger application through 4.35.3 for
In DedeCMS 5.7SP2, member/resetpassword.php allows remote authenticated users to reset the passwords of arbitrary users
ManageEngine ServiceDesk Plus before 9314 contains a local file inclusion vulnerability in the defModule parameter in De
Mitigates a directory traversal issue in ArcSight Logger versions prior to 6.7.
Mitigates a potential information leakage issue in ArcSight Logger versions prior to 6.7.
A flaw was found in Moodle versions 3.1 to 3.1.15 and earlier unsupported versions. The mybackpack functionality allowed
The SCTP socket buffer used by a userspace application is not accounted by the cgroups subsystem. An attacker can use th
Authentication Bypass vulnerability in McAfee Network Security Manager (NSM) 9.1 < 9.1.7.75.2 and 9.2 < 9.2.7.31 (9.2 Up
The Conexus telemetry protocol utilized within Medtronic MyCareLink Monitor versions 24950 and 24952, CareLink Monitor v
ZNC before 1.7.3-rc1 allows an existing remote user to cause a Denial of Service (crash) via invalid encoding.
PowerAct Pro Master Agent for Windows Version 5.13 and earlier allows authenticated attackers to bypass access restricti
An issue was discovered on ABUS Secvest wireless alarm system FUAA50000 3.01.01 in conjunction with Secvest remote contr
In Eclipse Mosquitto version 1.0 to 1.5.5 (inclusive) when a client publishes a retained message to a topic, then has it
WECON Technology PI Studio HMI versions 4.1.9 and prior and PI Studio versions 4.2.34 and prior lacks proper validation
A vulnerability in the Web Services Management Agent (WSMA) function of Cisco IOS XE Software could allow an authenticat
PHP Scripts Mall Amazon Affiliate Store 2.1.6 allows Parameter Tampering of the payment amount.
An Integer Signedness issue (for a return code) in the res_pjsip_sdp_rtp module in Digium Asterisk versions 15.7.1 and e
A vulnerability in Jenkins ECS Publisher Plugin 1.0.0 and earlier allows attackers with Item/Extended Read permission, o
A cross-site request forgery vulnerability in Jenkins Fortify on Demand Uploader Plugin 3.0.10 and earlier allows attack
A missing permission check in Jenkins Fortify on Demand Uploader Plugin 3.0.10 and earlier allows attackers with Overall
The administration backup restore resource in Atlassian Crowd before version 3.0.2 and from version 3.1.0 before version
An issue was discovered in the Harmis JE Messenger component 1.2.2 for Joomla!. It is possible to read information that
Grandstream GWN7000 before 1.0.6.32 and GWN7610 before 1.0.8.18 devices allow remote authenticated users to discover pas
In all Kubernetes versions prior to v1.11.8, v1.12.6, and v1.13.4, users that are authorized to make patch requests to t
Cross-site scripting (XSS) vulnerability in SYNO.Core.PersonalNotification.Event in Synology DiskStation Manager (DSM) b
Incorrect default permissions vulnerability in synouser.conf in Synology Diskstation Manager (DSM) before 6.2-23739-1 al
Incorrect default permissions vulnerability in synouser.conf in Synology Router Manager (SRM) before 1.1.7-6941-1 allows
A remote denial-of-service vulnerability exists in the way the Nouveau Display Driver (the default Ubuntu Nvidia display
IBM WebSphere Application Server Admin Console 7.5, 8.0, 8.5, and 9.0 is vulnerable to a potential denial of service, ca
A vulnerability in SonicWall SonicOS and SonicOSv, allow authenticated read-only admin to leave the firewall in an unsta
LocaleLowercase in MagickCore/locale.c in ImageMagick before 7.0.8-32 allows out-of-bounds access, leading to a SIGSEGV.
An inconsistent user interface issue was addressed with improved state management. This issue affected versions prior to
An inconsistent user interface issue was addressed with improved state management. This issue affected versions prior to
A memory corruption issue was addressed with improved memory handling. This issue affected versions prior to iOS 11.4.1,
Multiple memory corruption issues were addressed with improved input validation. This issue affected versions prior to i
Multiple memory corruption issues were addressed with improved input validation. This issue affected versions prior to i
An input validation issue was addressed with improved input validation. This issue affected versions prior to iOS 12, tv
An inconsistent user interface issue was addressed with improved state management. This issue affected versions prior to
A denial of service issue was addressed with improved validation. This issue affected versions prior to iOS 12.1, macOS
A logic issue was addressed with improved state management. This issue affected versions prior to iOS 12.1.
An inconsistent user interface issue was addressed with improved state management. This issue affected versions prior to
A denial of service issue was addressed with improved validation. This issue affected versions prior to macOS Mojave 10.
A resource exhaustion issue was addressed with improved input validation. This issue affected versions prior to iOS 12.1
A spoofing issue existed in the handling of URLs. This issue was addressed with improved input validation. This issue af
Scan for 2019 Vulnerabilities
CyberStrike detects these CVEs across your infrastructure automatically.
Get Started