17,305 vulnerabilities published in 2019
iBall Baton iB-WRB302N20122017 devices have improper access control over the UART interface, allowing physical attackers
HP has identified a security vulnerability with some versions of Workstation BIOS (UEFI Firmware) where the runtime BIOS
NETGEAR Insight Cloud with firmware before Insight 5.6 allows remote authenticated users to achieve command injection.
There is a man-in-the-middle (MITM) vulnerability on Huawei P30 smartphones versions before ELE-AL00 9.1.0.162(C01E160R1
There is an improper authentication vulnerability in some Huawei AP products before version V200R009C00SPC800. Due to th
A denial of service vulnerability exists when Microsoft Hyper-V on a host server fails to properly validate input from a
A denial of service vulnerability exists when Microsoft Hyper-V on a host server fails to properly validate input from a
A denial of service vulnerability exists when Microsoft Hyper-V on a host server fails to properly validate input from a
An authenticated attacker in SAP E-Commerce (Business-to-Consumer application), versions 7.3, 7.31, 7.32, 7.33, 7.54, ca
An issue was discovered in versions earlier than 1.3.0-66872 for Polycom RealPresence Debut that allows attackers to arb
An issue was discovered on Actiontec T2200H T2200H-31.128L.08 devices, as distributed by Telus. By attaching a UART adap
An authentication bypass vulnerability in the password reset functionality in Zoho ManageEngine ADSelfService Plus befor
An issue was discovered on Phoenix Contact AXC F 2152 (No.2404267) before 2019.0 LTS and AXC F 2152 STARTERKIT (No.10465
IBM Security Access Manager 9.0.1 through 9.0.6 could allow a remote attacker to conduct phishing attacks, using an open
Information Disclosure vulnerability in the Agent Handler in McAfee ePolicy Orchestrator (ePO) 5.9.x and 5.10.0 prior to
A vulnerability in the implementation of Border Gateway Protocol (BGP) functionality in Cisco IOS XR Software could allo
Improper authentication in firmware for Intel(R) SSD DC S4500 Series and Intel(R) SSD DC S4600 Series before SCV10150 ma
A denial of service vulnerability exists when Microsoft Hyper-V on a host server fails to properly validate input from a
In parse_hid_report_descriptor in drivers/input/tablet/gtco.c in the Linux kernel through 5.2.1, a malicious USB device
LineageOS 16.0 and earlier is affected by: Incorrect Access Control. The impact is: The property checked by `adb root` c
Vulnerability in the Java VM component of Oracle Database Server. Supported versions that are affected are 11.2.0.4, 12.
Vulnerability in the Oracle GraalVM Enterprise Edition component of Oracle GraalVM (subcomponent: Java). The supported v
Authentication protection bypass vulnerability in McAfee Data Loss Prevention (DLPe) for Windows 11.x prior to 11.3.0 al
In the Linux kernel before 5.2.3, set_geometry in drivers/block/floppy.c does not validate the sect and head fields, as
Improper sanitization of HTML in directory names in the Nextcloud Android app prior to version 3.7.0 allowed to style th
Bypassing lock protection exists in Nextcloud Android app 3.6.0 when creating a multi-account and aborting the process.
cPanel before 74.0.8 allows arbitrary file-write operations in the context of the root account during WHM Force Password
The "addon domain conversion" feature in cPanel before 67.9999.103 can copy all MySQL databases to the new account (SEC-
Select Dell Client Commercial and Consumer platforms contain an Improper Access Vulnerability. An unauthenticated attack
Buffer overflow in PTP (Picture Transfer Protocol) of EOS series digital cameras (EOS-1D X firmware version 2.1.0 and ea
cPanel before 58.0.4 allows a file-ownership change (to nobody) via rearrangeacct (SEC-134).
The "HTML Include and replace macro" plugin before 1.5.0 for Confluence Server allows a bypass of the includeScripts=fal
A vulnerability was reported in various BIOS versions of older ThinkPad systems that could allow a user with administrat
Metasys® ADS/ADX servers and NAE/NIE/NCE engines prior to 9.0 make use of a shared RSA key pair for certain encryption o
Metasys® ADS/ADX servers and NAE/NIE/NCE engines prior to 9.0 make use of a hardcoded RC2 key for certain encryption ope
A vulnerability within the Endpoint Learning feature of Cisco Nexus 9000 Series Switches running in Application Centric
On Keeper K5 20.1.0.25 and 20.1.0.63 devices, remote code execution can occur by inserting an SD card containing a file
A vulnerability in the filesystem of Cisco IOS XE Software could allow an authenticated, local attacker with physical ac
In libhidcommand_jni, there is a possible out of bounds write due to a missing bounds check. This could lead to local es
An issue was discovered in Espressif ESP-IDF 2.x, 3.0.x through 3.0.9, 3.1.x through 3.1.6, 3.2.x through 3.2.3, and 3.3
An issue was discovered in Xen through 4.11.x allowing x86 PV guest OS users to cause a denial of service or gain privil
An issue was discovered in the RENPHO application 3.0.0 for iOS. It transmits JSON data unencrypted to a server without
An Improper Certificate Validation weakness in the SRX Series Application Identification (app-id) signature update clien
An information disclosure vulnerability exists when the Windows Hyper-V Network Switch on a host operating system fails
A security feature bypass vulnerability exists in Windows 10 Mobile when Cortana allows a user to access files and folde
Vulnerability in the Java VM component of Oracle Database Server. Supported versions that are affected are 11.2.0.4, 12.
Vulnerability in the Oracle Hospitality Reporting and Analytics component of Oracle Food and Beverage Applications. The
Vulnerability in the Java SE, Java SE Embedded product of Oracle Java SE (component: Kerberos). Supported versions that
Vulnerability in the Primavera P6 Enterprise Project Portfolio Management product of Oracle Construction and Engineering
Vulnerability in the Java SE, Java SE Embedded product of Oracle Java SE (component: Networking). Supported versions tha
Scan for 2019 Vulnerabilities
CyberStrike detects these CVEs across your infrastructure automatically.
Get Started