17,305 vulnerabilities published in 2019
A vulnerability in the London Trust Media Private Internet Access (PIA) VPN Client v0.9.8 beta (build 02099) for macOS c
A vulnerability in the London Trust Media Private Internet Access (PIA) VPN Client v82 for Linux and macOS could allow a
Vulnerability in the PeopleSoft Enterprise PT PeopleTools component of Oracle PeopleSoft Products (subcomponent: Applica
Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: Replication). Supported versions that
Comodo Antivirus through 12.0.0.6870, Comodo Firewall through 12.0.0.6870, and Comodo Internet Security Premium through
A crafted self-referential DOS partition table will cause all Das U-Boot versions through 2019.07-rc4 to infinitely recu
IBM i2 Intelligent Analyis Platform 9.0.0 through 9.1.1 is vulnerable to an XML External Entity Injection (XXE) attack w
IBM Daeja ViewONE Professional, Standard & Virtual 5.0.5 and 5.0.6 is vulnerable to an XML External Entity Injection (XX
The SSL certificate-storage feature in cPanel before 78.0.18 allows unsafe file operations in the context of the root ac
A flaw was found in the Linux kernel's freescale hypervisor manager implementation, kernel versions 5.0.x up to, excludi
An Integer underflow in VLC Media Player versions < 3.0.7 leads to an out-of-band read.
cPanel before 70.0.23 allows arbitrary file-chmod operations during legacy incremental backups (SEC-338).
Wind River VxWorks 6.6, 6.7, 6.8, 6.9.3, 6.9.4, and Vx7 has Incorrect Access Control in IPv4 assignment by the ipdhcpc D
After user deletion in MongoDB Server the improper invalidation of authorization sessions allows an authenticated user's
NVIDIA Windows GPU Display Driver (all versions) contains a vulnerability in the kernel mode layer (nvlddmkm.sys) handle
When PHP EXIF extension is parsing EXIF information from an image, e.g. via exif_read_data() function, in PHP versions 7
When PHP EXIF extension is parsing EXIF information from an image, e.g. via exif_read_data() function, in PHP versions 7
Artifex MuPDF before 1.16.0 has a heap-based buffer over-read in fz_chartorune in fitz/string.c because pdf/pdf-op-filte
Clickjack vulnerability in Adminstrator web console in McAfee Web Gateway (MWG) 7.8.2.x prior to 7.8.2.12 allows remote
An elevation of privilege vulnerability exists when the MpSigStub.exe for Defender allows file deletion in arbitrary loc
Use of uninitialized stack variables in the start_decoder function in stb_vorbis through 2019-03-04 allows an attacker t
An out-of-bounds read of a global buffer in the draw_line function in stb_vorbis through 2019-03-04 allows an attacker t
Attackers may misuse an HTTP/REST endpoint of SAP HANA Extended Application Services (Advanced model), before version 1.
An issue was discovered in GitLab Enterprise Edition 11.x and 12.x before 12.0.9, 12.1.x before 12.1.9, and 12.2.x befor
HCL AppScan Source before 9.03.13 is susceptible to XML External Entity (XXE) attacks in multiple locations. In particul
IBM Security Directory Server 6.4.0 does not properly neutralize special elements that are used in XML, allowing attacke
Vulnerability in the Oracle Hospitality Reporting and Analytics component of Oracle Food and Beverage Applications. The
Vulnerability in the Oracle Hospitality Cruise Dining Room Management product of Oracle Hospitality Applications (compon
A Local Privilege Escalation vulnerability exists in GlobalProtect Agent for Linux and Mac OS X version 5.0.4 and earlie
Versions 10.0, 11.0 and 12.0 of the Trend Micro Deep Security Agent are vulnerable to an arbitrary file delete attack, w
rpcbind 0.2.0 allows local users to write to arbitrary files or gain privileges via a symlink attack on (1) /tmp/portmap
An exploitable unverified password change vulnerability exists in the ACEManager upload.cgi functionality of Sierra Wire
An insecurity temporary file vulnerability exists in RHQ Mongo DB Drift Server through 2013-09-25 when unpacking zipped
NVIDIA Virtual GPU Manager, all versions, contains a vulnerability in which it may grant a guest access to memory that i
The MsIo64.sys and MsIo32.sys drivers in Patriot Viper RGB before 1.1 allow local users (including low integrity process
IBM Spectrum Protect Plus 10.1.0 through 10.1.4 uses insecure file permissions on restored files and directories in Wind
SAP BusinessObjects Business Intelligence Platform (Web Intelligence HTML interface), corrected in versions 4.1 and 4.2,
Improper directory permissions in Intel(R) PROSet/Wireless WiFi Software before version 21.40 may allow an authenticated
Improper directory permissions in Intel(R) PROSet/Wireless WiFi Software before version 21.40 may allow an authenticated
Insufficient session validation in Intel(R) Baseboard Management Controller firmware may allow an unauthenticated user t
A flaw was discovered in ibus in versions before 1.5.22 that allows any unprivileged user to monitor and send method cal
openvas-scanner before 2011-09-11 creates a temporary file insecurely when generating OVAL system characteristics docume
Hardlink before 0.1.2 operates on full file system objects path names which can allow a local attacker to use this flaw
Dell Command Configure versions prior to 4.2.1 contain an uncontrolled search path vulnerability. A locally authenticate
Monkey HTTP Daemon has local security bypass
Crafted image that has a valid signature from a non-QC entity can be loaded which can read/write memory that belongs to
Jenkins WebSphere Deployer Plugin 1.6.1 and earlier allows users with Overall/Read access to disable SSL/TLS certificate
NLSSRV32.EXE in Nalpeiron Licensing Service 7.3.4.0, as used with Nitro PDF and other products, allows Elevation of Priv
A memory corruption issue was addressed with improved state management. This issue is fixed in iOS 12.2, macOS Mojave 10
An out-of-bounds read was addressed with improved bounds checking. This issue is fixed in iOS 12.3, macOS Mojave 10.14.5
Scan for 2019 Vulnerabilities
CyberStrike detects these CVEs across your infrastructure automatically.
Get Started