17,305 vulnerabilities published in 2019
A missing permission check in Jenkins Chef Sinatra Plugin in the ChefBuilderConfiguration.DescriptorImpl#doTestConnectio
Jenkins Fabric Beta Publisher Plugin stores credentials unencrypted in job config.xml files on the Jenkins master where
Jenkins Upload to pgyer Plugin stores credentials unencrypted in job config.xml files on the Jenkins master where they c
A cross-site request forgery vulnerability in Jenkins SOASTA CloudTest Plugin in the CloudTestServer.DescriptorImpl#doVa
A missing permission check in Jenkins SOASTA CloudTest Plugin in the CloudTestServer.DescriptorImpl#doValidate form vali
A cross-site request forgery vulnerability in Jenkins Nomad Plugin in the NomadCloud.DescriptorImpl#doTestConnection for
A missing permission check in Jenkins Nomad Plugin in the NomadCloud.DescriptorImpl#doTestConnection form validation met
Jenkins Open STF Plugin stores credentials unencrypted in its global configuration file on the Jenkins master where they
Jenkins Perfecto Mobile Plugin stores credentials unencrypted in its global configuration file on the Jenkins master whe
Jenkins TestFairy Plugin stores credentials unencrypted in job config.xml files on the Jenkins master where they can be
Jenkins Crowd Integration Plugin stores credentials unencrypted in the global config.xml configuration file on the Jenki
A cross-site request forgery vulnerability in Jenkins openid Plugin in the OpenIdSsoSecurityRealm.DescriptorImpl#doValid
A missing permission check in Jenkins openid Plugin in the OpenIdSsoSecurityRealm.DescriptorImpl#doValidate form validat
A cross-site request forgery vulnerability in Jenkins jenkins-reviewbot Plugin in the ReviewboardDescriptor#doTestConnec
A missing permission check in Jenkins jenkins-reviewbot Plugin in the ReviewboardDescriptor#doTestConnection form valida
A cross-site request forgery vulnerability in Jenkins Netsparker Cloud Scan Plugin 1.1.5 and older in the NCScanBuilder.
A missing permission check in Jenkins Netsparker Cloud Scan Plugin 1.1.5 and older in the NCScanBuilder.DescriptorImpl#d
A cross-site request forgery vulnerability in Jenkins Kmap Plugin in KmapJenkinsBuilder.DescriptorImpl form validation m
A missing permission check in Jenkins Kmap Plugin in KmapJenkinsBuilder.DescriptorImpl form validation methods allows at
In trytond/model/modelstorage.py in Tryton 4.2 before 4.2.21, 4.4 before 4.4.19, 4.6 before 4.6.14, 4.8 before 4.8.10, a
An issue was discovered in Poppler 0.74.0. There is a heap-based buffer over-read in the function PSOutputDev::checkPage
An issue was discovered in Poppler 0.74.0. There is a NULL pointer dereference in the function SplashClip::clipAALine at
An issue was discovered in OpenStack Neutron 11.x before 11.0.7, 12.x before 12.0.6, and 13.x before 13.0.3. By creating
A URL spoofing vulnerability was found in all international versions of Xiaomi Mi browser 10.5.6-g (aka the MIUI native
An issue was discovered in Uniqkey Password Manager 1.14. Upon entering new credentials to a site that is not registered
An issue was discovered in Uniqkey Password Manager 1.14. When entering new credentials to a site that isn't registered
In GraphicsMagick 1.4 snapshot-20190322 Q8, there is a memory leak in the function ReadMPCImage of coders/mpc.c, which a
An information disclosure vulnerability exists when the Windows GDI component improperly discloses the contents of its m
FontInfoScanner::scanFonts in FontInfo.cc in Poppler 0.75.0 has infinite recursion, leading to a call to the error funct
An information disclosure vulnerability exists in the way that the Windows SMB Server handles certain requests, aka 'Win
An information disclosure vulnerability exists in the way that the Windows SMB Server handles certain requests, aka 'Win
An information disclosure vulnerability exists when the scripting engine does not properly handle objects in memory in M
A tampering vulnerability exists in the NuGet Package Manager for Linux and Mac that could allow an authenticated attack
A security feature bypass vulnerability exists when Internet Explorer fails to validate the correct Security Zone of req
An information disclosure vulnerability exists when the Windows GDI component improperly discloses the contents of its m
An information disclosure vulnerability exists in the way Azure WaLinuxAgent creates swap files on resource disks, aka '
An information disclosure vulnerability exists in the way that the Windows SMB Server handles certain requests, aka 'Win
A directory traversal vulnerability in the file browser component on the Zyxel NAS 326 version 5.21 and below allows a l
Improper access control in the Discuss App of Odoo Community 12.0 and earlier, and Odoo Enterprise 12.0 and earlier allo
Users with Site-level permissions can access files containing the username-encrypted passwords of Security Console Globa
Incorrect Access Controls of Security Officer (SO) in PKCS11 R2 provider that ships with the Utimaco CryptoServer HSM pr
A tampering vulnerability exists when Microsoft browsers do not properly validate input under specific conditions, aka '
An information disclosure vulnerability exists when the Windows GDI component improperly discloses the contents of its m
An information disclosure vulnerability exists when Microsoft Edge improperly handles objects in memory, aka 'Microsoft
An information disclosure vulnerability exists when the scripting engine does not properly handle objects in memory, aka
An information disclosure vulnerability exists when the Windows GDI component improperly discloses the contents of its m
A spoofing vulnerability that could allow a security feature bypass exists in when Azure DevOps Server does not properly
Crafted packets destined to the management interface (fxp0) of an SRX340 or SRX345 services gateway may create a denial
A heap address information leak while using L2CAP_GET_CONF_OPT was discovered in the Linux kernel before 5.1-rc1.
A heap data infoleak in multiple locations including L2CAP_PARSE_CONF_RSP was found in the Linux kernel before 5.1-rc1.
Scan for 2019 Vulnerabilities
CyberStrike detects these CVEs across your infrastructure automatically.
Get Started