17,305 vulnerabilities published in 2019
Insufficient data validation in crosh could lead to a command injection under chronos privileges in Networking in Google
A vulnerability in the Redis implementation used by the Cisco Policy Suite for Mobile and Cisco Policy Suite Diameter Ro
Improper file verification in install routine for Intel(R) SGX SDK and Platform Software for Windows before 2.2.100 may
A type confusion vulnerability exists when processing project files in CX-Supervisor (Versions 3.42 and prior). An attac
An attacker could inject commands to launch programs and create, write, and read files on CX-Supervisor (Versions 3.42 a
Session fixation exists in ZoneMinder through 1.32.3, as an attacker can fixate his own session cookies to the next logg
An SSRF issue was discovered in 42Gears SureMDM before 2018-11-27 via the /api/DownloadUrlResponse.ashx "url" parameter.
Symantec Ghost Solution Suite (GSS) versions prior to 3.3 RU1 may be susceptible to a DLL hijacking vulnerability, which
In savePhotoFromUriToUri of ContactPhotoUtils.java in Android-7.0, Android-7.1.1, Android-7.1.2, Android-8.0, Android-8.
An access of uninitialized pointer vulnerability in CX-Supervisor (Versions 3.42 and prior) could lead to type confusion
A vulnerability in the client application for iOS of Cisco Webex Teams could allow an authenticated, remote attacker to
Supportutils, before version 3.1-5.7.1, when run with command line argument -A searched the file system for a ndspath bi
An out of bounds read flaw was discovered in libssh2 before 1.8.1 in the way SSH_MSG_CHANNEL_REQUEST packets with an exi
A successful exploit of these vulnerabilities requires the local user to load a crafted DLL file in the system directory
HP Support Assistant before 8.7.50.3 allows an unauthorized person with local access to load arbitrary code.
The Pronestor PNHM (aka Health Monitoring or HealthMonitor) add-in before 8.1.13.0 for Outlook has "BUILTIN\Users:(I)(F)
In the configuration of NFC modules on certain devices, there is a possible failure to distinguish individual devices du
Vulnerability in the Oracle Retail Convenience Store Back Office component of Oracle Retail Applications (subcomponent:
Vulnerability in the Oracle Retail Point-of-Service component of Oracle Retail Applications (subcomponent: Infrastructur
Vulnerability in the Oracle Outside In Technology component of Oracle Fusion Middleware (subcomponent: Outside In Filter
Vulnerability in the Oracle VM VirtualBox component of Oracle Virtualization (subcomponent: Core). Supported versions th
Rapid7 Metasploit Framework suffers from an instance of CWE-22, Improper Limitation of a Pathname to a Restricted Direct
In SmsDefaultDialog.onStart of SmsDefaultDialog.java, there is a possible escalation of privilege due to an overlay atta
An issue was discovered in GNOME gvfs 1.29.4 through 1.41.2. daemon/gvfsbackendadmin.c mishandles file ownership because
It is possible for an attacker with regular user access to the web application of Pydio through 8.2.2 to trick an admini
Improper permissions in the installer for Intel(R) Turbo Boost Max Technology 3.0 driver version 1.0.0.1035 and before m
Spring Security, versions 4.2.x up to 4.2.12, and older unsupported versions support plain text passwords using Plaintex
In the ABB IDAL FTP server, an authenticated attacker can traverse to arbitrary directories on the hard disk with "CWD .
SQL injection vulnerability in synophoto_csPhotoDB.php in Synology Photo Station before 6.8.11-3489 and before 6.3-2977
OS command injection vulnerability in drivers_syno_import_user.php in Synology Calendar before 2.3.1-0617 allows remote
Optergy Proton/Enterprise devices have Hard-coded Credentials.
WavesSysSvc in Waves MAXX Audio allows privilege escalation because the General registry key has Full Control access for
A vulnerability in the loading mechanism of specific dynamic link libraries in Cisco Jabber for Windows could allow an a
In HT2 Labs Learning Locker 3.15.1, it's possible to inject malicious HTML and JavaScript code into the DOM of the websi
Zoho ManageEngine ADManager Plus 6.6.5, ADSelfService Plus 5.7, and DesktopCentral 10.0.380 have Insecure Permissions, l
Vulnerability in the Oracle Application Testing Suite component of Oracle Enterprise Manager Products Suite (subcomponen
Vulnerability in the Oracle Outside In Technology component of Oracle Fusion Middleware (subcomponent: Outside In Filter
Vulnerability in the Oracle Outside In Technology component of Oracle Fusion Middleware (subcomponent: Outside In Filter
Vulnerability in the Oracle Outside In Technology component of Oracle Fusion Middleware (subcomponent: Outside In Filter
Vulnerability in the Oracle Outside In Technology component of Oracle Fusion Middleware (subcomponent: Outside In Filter
Vulnerability in the Oracle Solaris component of Oracle Sun Systems Products Suite (subcomponent: Filesystem). Supported
Vulnerability in the Oracle Solaris component of Oracle Sun Systems Products Suite (subcomponent: Gnuplot). The supporte
Vulnerability in the Oracle Outside In Technology component of Oracle Fusion Middleware (subcomponent: Outside In Filter
Vulnerability in the Oracle Outside In Technology component of Oracle Fusion Middleware (subcomponent: Outside In Filter
Vulnerability in the Oracle Outside In Technology component of Oracle Fusion Middleware (subcomponent: Outside In Filter
Vulnerability in the Oracle Outside In Technology component of Oracle Fusion Middleware (subcomponent: Outside In Filter
Auth0 Passport-SharePoint before 0.4.0 does not validate the JWT signature of an Access Token before processing. This al
Discourse before 2.3.0 and 2.4.x before 2.4.0.beta3 lacks a confirmation screen when logging in via an email link.
In cPanel before 70.0.23, OpenID providers can inject arbitrary data into cPanel session files (SEC-368).
cPanel before 64.0.21 allows demo accounts to execute code via the BoxTrapper API (SEC-238).
Scan for 2019 Vulnerabilities
CyberStrike detects these CVEs across your infrastructure automatically.
Get Started