17,305 vulnerabilities published in 2019
In createSessionInternal of PackageInstallerService.java, there is a possible permissions bypass. This could lead to loc
In the Bootloader, there is a possible kernel command injection due to missing command sanitization. This could lead to
Insufficient access control in system firmware for Intel(R) Xeon(R) Scalable Processors, 2nd Generation Intel(R) Xeon(R)
Insufficient access control in firmware for Intel(R) Ethernet 700 Series Controllers before version 7.0 may allow a priv
Insufficient memory protection in Intel(R) TXT for certain Intel(R) Core Processors and Intel(R) Xeon(R) Processors may
Insufficient memory protection in System Management Mode (SMM) and Intel(R) TXT for certain Intel(R) Xeon(R) Processors
The AX.25 daemon (ax25d) in ax25-tools before 0.0.8-13 does not check the return value of a setuid call. The setuid call
Symantec Endpoint Protection, prior to 14.2 RU2, may be susceptible to an unsigned code execution vulnerability, which m
NVIDIA NVFlash, NVUFlash Tool prior to v5.588.0 and GPUModeSwitch Tool prior to 2019-11, NVIDIA kernel mode driver (nvfl
A vulnerability in the CLI of Cisco Unity Express could allow an authenticated, local attacker to inject arbitrary comma
A vulnerability in Cisco DNA Spaces: Connector could allow an authenticated, local attacker to elevate privileges and ex
A vulnerability in Cisco DNA Spaces: Connector could allow an authenticated, local attacker to perform a command injecti
Kaspersky Secure Connection, Kaspersky Internet Security, Kaspersky Total Security, Kaspersky Security Cloud prior to ve
In the Linux kernel 5.3.10, there is a use-after-free (read) in the perf_trace_lock_acquire function (related to include
In Apache SpamAssassin before 3.4.3, nefarious CF files can be configured to run system commands without any output or e
Improper conditions check in voltage settings for some Intel(R) Processors may allow a privileged user to potentially en
Improper input validation in firmware for Intel(R) NUC(R) may allow a privileged user to potentially enable escalation o
Integer overflow in firmware for Intel(R) NUC(R) may allow a privileged user to potentially enable escalation of privile
Out of bounds write in firmware for Intel(R) NUC(R) may allow a privileged user to potentially enable escalation of priv
Insufficient input validation in the subsystem for Intel(R) CSME before versions 11.8.70, 11.11.70, 11.22.70, 12.0.45, 1
Logic issue in subsystem for Intel(R) CSME before versions 12.0.45, 13.0.10 and 14.0.10 may allow a privileged user to p
Insufficient session validation in the subsystem for Intel(R) CSME before versions 11.8.70, 12.0.45, 13.0.10 and 14.0.10
Insufficient input validation in subsystem for Intel(R) CSME before versions 12.0.45 and 13.0.10 may allow a privileged
Authentication bypass in the subsystem for Intel(R) CSME before versions 11.8.70, 11.11.70, 11.22.70, 12.0.45, 13.0.10 a
When processing project files, the application (Omron CX-Programmer v9.70 and prior and Common Components January 2019 a
Vulnerability in the RDBMS DataPump component of Oracle Database Server. Supported versions that are affected are 11.2.0
The Simple - Better Banking application 2.45.0 through 2.45.3 (fixed in 2.46.0) for Android was affected by an informati
An issue was discovered in MISP 2.4.108. Organization admins could reset credentials for site admins (organization admin
OnApp before 5.0.0-88, 5.5.0-93, and 6.0.0-196 allows an attacker to run arbitrary commands with root privileges on serv
An out-of-bounds read vulnerability has been identified in Fuji Electric Alpha7 PC Loader Versions 1.1 and prior, which
A vulnerability in Cisco Small Business SPA500 Series IP Phones could allow a physically proximate attacker to execute a
In Valve Steam Client for Windows through 2019-08-07, HKLM\SOFTWARE\Wow6432Node\Valve\Steam has explicit "Full control"
A vulnerability has been identified in SCALANCE SC-600 (V2.0). An authenticated attacker with access to port 22/tcp as w
On STMicroelectronics STM32F7 devices, Proprietary Code Read Out Protection (PCROP) (a software IP protection method) ca
On NXP Kinetis KV1x, Kinetis KV3x, and Kinetis K8x devices, Flash Access Controls (FAC) (a software IP protection method
The PKI keys exported using the command "run request security pki key-pair export" on Junos OS may have insecure file pe
An issue was discovered on Fujitsu Wireless Keyboard Set LX390 GK381 devices. Because of the lack of proper encryption o
In Magento prior to 1.9.4.3, Magento prior to 1.14.4.3, Magento 2.2 prior to 2.2.10, and Magento 2.3 prior to 2.3.3 or 2
The admin sys mode is now conditional and dedicated for the special case. By default, since [email protected] no instance
DLL Search Order Hijacking vulnerability in the Microsoft Windows client in McAfee Tech Check 3.0.0.17 and earlier allow
An issue was discovered in Xen through 4.12.x allowing x86 PV guest OS users to gain host OS privileges by leveraging ra
Barco ClickShare Button R9861500D01 devices before 1.10.0.13 have Missing Support for Integrity Check. The ClickShare Bu
DBA-1510P firmware 1.70b009 and earlier allows authenticated attackers to execute arbitrary OS commands via Command Line
A reachable Object::dictLookup assertion in Poppler 0.72.0 allows attackers to cause a denial of service due to the lack
An attempted excessive memory allocation was discovered in the function tinyexr::AllocateImage in tinyexr.h in tinyexr v
An issue was discovered in libming 0.4.8. There is a heap-based buffer over-read in the function writePNG in the file ut
There is an information leak vulnerability in some Huawei HG products. An attacker may obtain information about the HG d
An issue was discovered in Bento4 1.5.1-627. The AP4_StcoAtom class in Core/Ap4StcoAtom.cpp has an attempted excessive m
The SaveUserSettings service in Content Manager in SDL Web 8.5.0 has an XXE Vulnerability that allows reading sensitive
In Poppler 0.72.0, PDFDoc::setup in PDFDoc.cc allows attackers to cause a denial-of-service (application crash caused by
Scan for 2019 Vulnerabilities
CyberStrike detects these CVEs across your infrastructure automatically.
Get Started