17,305 vulnerabilities published in 2019
Vulnerability in the Oracle Outside In Technology component of Oracle Fusion Middleware (subcomponent: Outside In Filter
Vulnerability in the Oracle Outside In Technology component of Oracle Fusion Middleware (subcomponent: Outside In Filter
Vulnerability in the Oracle Outside In Technology component of Oracle Fusion Middleware (subcomponent: Outside In Filter
Auth0 Passport-SharePoint before 0.4.0 does not validate the JWT signature of an Access Token before processing. This al
Discourse before 2.3.0 and 2.4.x before 2.4.0.beta3 lacks a confirmation screen when logging in via an email link.
In cPanel before 70.0.23, OpenID providers can inject arbitrary data into cPanel session files (SEC-368).
cPanel before 64.0.21 allows demo accounts to execute code via the BoxTrapper API (SEC-238).
An Insecure Direct Object Reference (IDOR) vulnerability exists in the order processing workflow of Magento 2.1 prior to
Multiple vulnerabilities in the smart tunnel functionality of Cisco Adaptive Security Appliance (ASA) could allow an aut
A remote authorization bypass vulnerability was discovered in HPE 3PAR StoreServ Management and Core Software Media vers
An elevation of privilege vulnerability exists due to a stack corruption in Windows Subsystem for Linux. An attacker who
An elevation of privilege vulnerability exists in Git for Visual Studio when it improperly parses configuration files. A
In LockTaskController.lockKeyguardIfNeeded of the LockTaskController.java, there was a difference in the handling of the
In ChangeDefaultDialerDialog.java, there is a possible escalation of privilege due to an overlay attack. This could lead
In Apache Commons Beanutils 1.9.2, a special BeanIntrospector class was added which allows suppressing the ability for a
The webtoffee "WordPress Users & WooCommerce Customers Import Export" plugin 1.3.0 for WordPress allows CSV injection in
connect-pg-simple before 6.0.1 allows SQL injection if tableName or schemaName is untrusted data.
In System Settings, there is a possible permissions bypass due to a cached Linux user ID. This could lead to a local per
In NFC, there is a possible out of bounds write due to a missing bounds check. This could lead to a to local escalation
In NFC, there is a possible out of bounds write due to a missing bounds check. This could lead to a to local escalation
In NFC server, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalatio
In Platform, there is a possible bypass of user interaction requirements due to background app interception. This could
JetBrains ReSharper installers for versions before 2019.2 had a DLL Hijacking vulnerability.
It was found that the fix for CVE-2014-0114 had been reverted in JBoss Operations Network 3 (JON). This flaw allows atta
IBM MQ 8.0.0.4 - 8.0.0.12, 9.0.0.0 - 9.0.0.6, 9.1.0.0 - 9.1.0.2, and 9.1.0 - 9.1.2 AMQP Listeners could allow an unautho
The vulnerability is limited to the installers of Dell Encryption Enterprise versions prior to 10.4.0 and Dell Endpoint
A denial of service vulnerability exists when Windows improperly handles hard links, aka 'Microsoft Windows Denial of Se
Vulnerability in the Oracle Outside In Technology product of Oracle Fusion Middleware (component: Outside In Filters). T
Vulnerability in the Oracle Outside In Technology product of Oracle Fusion Middleware (component: Outside In Filters). T
Vulnerability in the Oracle Outside In Technology product of Oracle Fusion Middleware (component: Outside In Filters). T
Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). Supported versions that ar
Vulnerability in the Oracle Outside In Technology product of Oracle Fusion Middleware (component: Outside In Filters). T
Vulnerability in the Oracle Outside In Technology product of Oracle Fusion Middleware (component: Outside In Filters). T
Vulnerability in the Oracle Outside In Technology product of Oracle Fusion Middleware (component: Outside In Filters). T
The url_redirect (aka URL redirect) extension through 1.2.1 for TYPO3 fails to properly sanitize user input and is susce
eQ-3 HomeMatic CCU3 firmware 3.41.11 allows session fixation. An attacker can create session IDs and send them to the vi
In JetBrains Toolbox App before 1.15.5666 for Windows, privilege escalation was possible.
autojump before 21.5.8 allows local users to gain privileges via a Trojan horse custom_install directory in the current
cartridges/openshift-origin-cartridge-mongodb-2.2/info/bin/dump.sh in OpenShift does not properly create files in /tmp.
Arbitrary buffer write issue while processing sequence header during HEVC or AVC encoding. in Snapdragon Auto, Snapdrago
Chartkick.js 3.1.0 through 3.1.3, as used in the Chartkick gem before 3.3.0 for Ruby, allows prototype pollution.
Code42 app through version 7.0.2 for Windows has an Untrusted Search Path. In certain situations, a non-administrative a
Code42 server through 7.0.2 for Windows has an Untrusted Search Path. In certain situations, a non-administrative attack
Unbound 1.6.4 through 1.9.4 contain a vulnerability in the ipsec module that can cause shell code execution after receiv
evolution-data-server3 3.0.3 through 3.2.1 used insecure (non-SSL) connection when attempting to store sent email messag
LiteManager 4.5.0 has weak permissions (Everyone: Full Control) in the "LiteManagerFree - Server" folder, as demonstrate
Orca has arbitrary code execution due to insecure Python module load
Symantec Messaging Gateway, prior to 10.7.3, may be susceptible to a server-side request forgery (SSRF) exploit, which i
An insecure file access vulnerability exists in CA Client Automation 14.0, 14.1, 14.2, and 14.3 Agent for Windows that c
Signal Desktop before 1.29.1 on Windows allows local users to gain privileges by creating a Trojan horse %SYSTEMDRIVE%\n
Scan for 2019 Vulnerabilities
CyberStrike detects these CVEs across your infrastructure automatically.
Get Started