17,305 vulnerabilities published in 2019
Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: Web Services). Supporte
An issue was discovered in EthereumJ 1.8.2. There is Unsafe Deserialization in ois.readObject in mine/Ethash.java and de
Check Point Endpoint Security Client for Windows, with the VPN blade, before version E80.83, starts a process without us
On Shenzhen Cylan Clever Dog Smart Camera DOG-2W and DOG-2W-V4 devices, an attacker on the network can login remotely to
OpenStack Magnum passes OpenStack credentials into the Heat templates creating its instances. While these should just be
The default configuration of glot-www through 2018-05-19 allows remote attackers to execute arbitrary code because glot-
SQL injection vulnerability in ChronoScan version 1.5.4.3 and earlier allows an unauthenticated attacker to execute arbi
Akamai CloudTest before 58.30 allows remote code execution.
The QMP migrate command in QEMU version 4.0.0 and earlier is vulnerable to OS command injection, which allows the remote
The QMP guest_exec command in QEMU 4.0.0 and earlier is prone to OS command injection, which allows the attacker to achi
Citrix AppDNA before 7 1906.1.0.472 has Incorrect Access Control.
LiveZilla Server before 8.0.1.1 is vulnerable to SQL Injection in server.php via the p_ext_rse parameter.
An issue was discovered in Mongoose before 6.15. The parse_mqtt() function in mg_mqtt.c has a critical heap-based buffer
LiveZilla Server before 8.0.1.1 is vulnerable to SQL Injection in functions.internal.build.inc.php via the parameter p_d
FeHelper through 2019-06-19 allows arbitrary code execution during a JSON format operation, as demonstrated by the {"a":
A vulnerability reported in Lenovo Service Bridge before version 4.1.0.1 could allow remote code execution.
A vulnerability reported in Lenovo Service Bridge before version 4.1.0.1 could allow remote code execution.
In Couchbase Sync Gateway 2.1.2, an attacker with access to the Sync Gateway’s public REST API was able to issue additio
A vulnerability in the web-based management interface of Cisco Data Center Network Manager (DCNM) could allow an unauthe
A vulnerability in the web-based management interface of Cisco Data Center Network Manager (DCNM) could allow an unauthe
The Quantenna WiFi Controller on Telus Actiontec WEB6000Q v1.1.02.22 allows login with root level access with the user "
On Telus Actiontec WEB6000Q v1.1.02.22 devices, an attacker can login with root level access with the user "root" and pa
Various Lexmark devices have a Buffer Overflow (issue 2 of 2).
Various Lexmark devices have a Buffer Overflow (issue 1 of 2).
Incorrect access control in the database manager component in Odoo Community 10.0 and 11.0 and Odoo Enterprise 10.0 and
Session data between cluster nodes during cluster synchronization is not properly encrypted in Pulse Secure Pulse Connec
An input validation issue has been found with login_meeting.cgi in Pulse Secure Pulse Connect Secure 8.3RX before 8.3R2.
In WebAccess/SCADA Versions 8.3.5 and prior, multiple heap-based buffer overflow vulnerabilities are caused by a lack of
In WebAccess/SCADA, Versions 8.3.5 and prior, multiple stack-based buffer overflow vulnerabilities are caused by a lack
In WebAccess/SCADA Versions 8.3.5 and prior, multiple untrusted pointer dereference vulnerabilities may allow a remote a
njs through 0.3.3, used in NGINX, has a buffer over-read in nxt_utf8_decode in nxt/nxt_utf8.c. This issue occurs after t
Chamilo LMS 1.11.8 and 2.x allows remote code execution through an lp_upload.php unauthenticated file upload feature. It
core/MY_Security.php in CSZ CMS 1.2.2 before 2019-06-20 has member/login/check SQL injection by sending a crafted HTTP U
Multiple integer overflows exist in MATIO before 1.5.16, related to mat.c, mat4.c, mat5.c, mat73.c, and matvar_struct.c
IBM Robotic Process Automation with Automation Anywhere 11 uses an inadequate account lockout setting that could allow a
Super Micro SuperDoctor 5, when restrictions are not implemented in agent.cfg, allows remote attackers to execute arbitr
Prima Systems FlexAir, Versions 2.3.38 and prior. The application generates database backup files with a predictable nam
Prima Systems FlexAir devices have Default Credentials.
Optergy Proton/Enterprise devices allow Remote Root Code Execution via a Backdoor Console.
SICK MSC800 all versions prior to Version 4.0, the affected firmware versions contain a hard-coded customer account pass
NetApp AFF A700s Baseboard Management Controller (BMC) firmware versions 1.22 and higher were shipped with a default acc
Nortek Linear eMerge 50P/5000P devices have Default Credentials.
Optergy Proton/Enterprise devices allow Authenticated File Upload with Code Execution as root.
IBM Spectrum Protect Servers 7.1 and 8.1 and Storage Agents are vulnerable to a stack-based buffer overflow, caused by i
An issue was discovered on D-Link DCS-1130 devices. The device provides a user with the capability of setting a SMB fold
DOSBox 0.74-2 has Incorrect Access Control.
Linear eMerge E3-Series devices have a Version Control Failure.
Linear eMerge E3-Series devices allow a Stack-based Buffer Overflow on the ARM platform.
Linear eMerge E3-Series devices allow Remote Code Execution (root access over SSH).
Linear eMerge 50P/5000P devices allow Authentication Bypass.
Scan for 2019 Vulnerabilities
CyberStrike detects these CVEs across your infrastructure automatically.
Get Started