17,305 vulnerabilities published in 2019
Cloud Native Computing Foundation (CNCF) CNI (Container Networking Interface) 0.7.4 has a network firewall misconfigurat
The Serialize.deserialize() method in CoAPthon3 1.0 and 1.0.1 mishandles certain exceptions, leading to a denial of serv
Detcon Sitewatch Gateway, all versions without cellular, an attacker can edit settings on the device using a specially c
The Serialize.deserialize() method in CoAPthon 3.1, 4.0.0, 4.0.1, and 4.0.2 mishandles certain exceptions, leading to a
Path traversal vulnerability in http-live-simulator npm package version 1.0.5 allows arbitrary path to be accessed on th
SQLite 3.25.2, when queries are run on a table with a malformed PRIMARY KEY, allows remote attackers to cause a denial o
An out-of-bounds read was addressed with improved bounds checking. This issue affected versions prior to iOS 12, macOS M
An out-of-bounds read was addressed with improved input validation. This issue affected versions prior to iOS 11.4.1, ma
A spoofing issue existed in the handling of URLs. This issue was addressed with improved input validation. This issue af
A null pointer dereference was addressed with improved validation. This issue affected versions prior to macOS High Sier
Clearing a history item may not clear visits with redirect chains. The issue was addressed with improved data deletion.
A memory corruption issue was addressed with improved input validation. This issue affected versions prior to iOS 12.1.
A logic issue was addressed with improved state management. This issue affected versions prior to iOS 12.1, macOS Mojave
An issue existed in the method for determining prime numbers. This issue was addressed by using pseudorandom bases for t
A certificate validation issue existed in configuration profiles. This was addressed with additional checks. This issue
Vordel XML Gateway (acquired by Axway) version 7.2.2 could allow remote attackers to cause a denial of service via a spe
Suricata version 4.0.4 incorrectly handles the parsing of the SSH banner. A malformed SSH banner can cause the parsing c
GitLab Community and Enterprise Edition before 11.3.14, 11.4.x before 11.4.12, and 11.5.x before 11.5.5 allows Directory
Advantech WebAccess/SCADA, Versions 8.3.5 and prior. An improper access control vulnerability may allow an attacker to c
A directory traversal vulnerability in Trend Micro Apex One, OfficeScan (versions XG and 11.0), and Worry-Free Business
A directory traversal vulnerability exists in the confd.exe module in Honeywell Experion PKS R40x before R400.6, R41x be
In Apache HTTP Server 2.4 releases 2.4.37 and 2.4.38, a bug in mod_ssl when using per-location client certificate verifi
In Apache HTTP Server 2.4 release 2.4.38 and prior, a race condition in mod_auth_digest when running in a threaded serve
A remote code execution vulnerability exists in the way that the Chakra scripting engine handles objects in memory in Mi
A remote code execution vulnerability exists in the way that Windows Deployment Services TFTP Server handles objects in
A remote code execution vulnerability exists in the way the scripting engine handles objects in memory in Microsoft brow
A remote code execution vulnerability exists in the way that the Chakra scripting engine handles objects in memory in Mi
A remote code execution vulnerability exists in the way that the ChakraCore scripting engine handles objects in memory,
A remote code execution vulnerability exists in the way that the VBScript engine handles objects in memory, aka 'Windows
A remote code execution vulnerability exists in the way that the VBScript engine handles objects in memory, aka 'Windows
A remote code execution vulnerability exists in the way that the VBScript engine handles objects in memory, aka 'Windows
A remote code execution vulnerability exists in the way that the scripting engine handles objects in memory in Internet
A remote code execution vulnerability exists when Internet Explorer improperly accesses objects in memory, aka 'Internet
A remote code execution vulnerability exists in the way that the scripting engine handles objects in memory in Microsoft
A remote code execution vulnerability exists in the way that the scripting engine handles objects in memory in Microsoft
A remote code execution vulnerability exists in the way that the scripting engine handles objects in memory in Microsoft
A remote code execution vulnerability exists in the way that the scripting engine handles objects in memory in Microsoft
A remote code execution vulnerability exists when Microsoft Edge improperly accesses objects in memory, aka 'Microsoft E
A remote code execution vulnerability exists in the way that Microsoft browsers access objects in memory, aka 'Microsoft
A remote code execution vulnerability exists in the way that the scripting engine handles objects in memory in Internet
A remote code execution vulnerability exists in the way that the ActiveX Data objects (ADO) handles objects in memory, a
In Wireshark 2.4.0 to 2.4.13, 2.6.0 to 2.6.7, and 3.0.0, the GSS-API dissector could crash. This was addressed in epan/d
In Wireshark 2.4.0 to 2.4.13, 2.6.0 to 2.6.7, and 3.0.0, the NetScaler file parser could crash. This was addressed in wi
In Wireshark 2.4.0 to 2.4.13, 2.6.0 to 2.6.7, and 3.0.0, the DOF dissector could crash. This was addressed in epan/disse
In Wireshark 3.0.0, the IEEE 802.11 dissector could go into an infinite loop. This was addressed in epan/dissectors/pack
In Wireshark 3.0.0, the GSUP dissector could go into an infinite loop. This was addressed in epan/dissectors/packet-gsm_
In Wireshark 2.4.0 to 2.4.13, 2.6.0 to 2.6.7, and 3.0.0, the SRVLOC dissector could crash. This was addressed in epan/di
In Wireshark 3.0.0, the Rbm dissector could go into an infinite loop. This was addressed in epan/dissectors/file-rbm.c b
In Wireshark 2.4.0 to 2.4.13, 2.6.0 to 2.6.7, and 3.0.0, the LDSS dissector could crash. This was addressed in epan/diss
In Wireshark 3.0.0, the TSDNS dissector could crash. This was addressed in epan/dissectors/packet-tsdns.c by splitting s
Scan for 2019 Vulnerabilities
CyberStrike detects these CVEs across your infrastructure automatically.
Get Started