17,305 vulnerabilities published in 2019
Mailvelope prior to 3.3.0 allows private key operations without user interaction via its client-API. By modifying an URL
A NULL Pointer Dereference in match_at() in regexec.c in Oniguruma 6.9.2 allows attackers to potentially cause denial of
An issue was discovered in GitLab Community and Enterprise Edition before 11.3.11, 11.4.x before 11.4.8, and 11.5.x befo
An issue was discovered in GitLab Community and Enterprise Edition 10.x and 11.x before 11.3.11, 11.4.x before 11.4.8, a
GitLab EE, version 11.5 before 11.5.1, is vulnerable to an insecure object reference issue that permits a user with Repo
GitLab CE/EE, versions 8.0 up to 11.x before 11.3.11, 11.4 before 11.4.8, and 11.5 before 11.5.1, would log access token
MediaWiki through 1.32.1 has Incorrect Access Control. Suppressed username or log in Special:EditTags are exposed. Fixed
Wikimedia MediaWiki through 1.32.1 has Incorrect Access Control. Suppressed log in RevisionDelete page is exposed. Fixed
There is a path traversal vulnerability on Huawei Share. The software does not properly validate the path, an attacker c
There is an out-of-bounds read in Exiv2::MrwImage::readMetadata in mrwimage.cpp in Exiv2 through 0.27.2.
A missing permission check in Jenkins Docker Plugin 1.1.6 and earlier in DockerAPI.DescriptorImpl#doTestConnection allow
The Windows Guest Tools in Citrix XenServer 6.2 SP1 and earlier allows remote attackers to cause a denial of service (gu
A vulnerability in the pfe-chassisd Chassis Manager (CMLC) daemon of Juniper Networks Junos OS allows an attacker to cau
Buffer overflow in res_pjsip_messaging in Digium Asterisk versions 13.21-cert3, 13.27.0, 15.7.2, 16.4.0 and earlier allo
On Fitbit activity-tracker devices, certain addresses never change. According to the popets-2019-0036.pdf document, this
Deepwoods Software WebLibrarian 3.5.2 and earlier is affected by: SQL Injection. The impact is: Exposing the entire data
An information disclosure vulnerability exists when Visual Studio improperly parses XML input in certain settings files,
An information disclosure vulnerability exists when Exchange allows creation of entities with Display Names having non-p
An information disclosure vulnerability exists when the Windows GDI component improperly discloses the contents of its m
An information disclosure vulnerability exists when the Windows GDI component improperly discloses the contents of its m
An information disclosure vulnerability exists when the Windows GDI component improperly discloses the contents of its m
An information disclosure vulnerability exists when the Windows GDI component improperly discloses the contents of its m
An information disclosure vulnerability exists when the Windows GDI component improperly discloses the contents of its m
An information disclosure vulnerability exists when the Windows GDI component improperly discloses the contents of its m
An information disclosure vulnerability exists when the Windows RDP client improperly discloses the contents of its memo
An information disclosure vulnerability exists when the Windows GDI component improperly discloses the contents of its m
njs through 0.3.3, used in NGINX, has a heap-based buffer over-read in nxt_vsprintf in nxt/nxt_sprintf.c during error ha
Dancer::Plugin::SimpleCRUD 1.14 and earlier is affected by: Incorrect Access Control. The impact is: Potential for unath
Zipios before 0.1.7 does not properly handle certain malformed zip archives and can go into an infinite loop, causing a
A path traversal vulnerability in Jenkins 2.185 and earlier, LTS 2.176.1 and earlier in core/src/main/java/hudson/model/
SDL (Simple DirectMedia Layer) 2.x through 2.0.9 has a heap-based buffer over-read in Fill_IMA_ADPCM_block, caused by an
lodash prior to 4.17.11 is affected by: CWE-400: Uncontrolled Resource Consumption. The impact is: Denial of service. Th
The Sleuth Kit 4.6.0 and earlier is affected by: Integer Overflow. The impact is: Opening crafted disk image triggers cr
In Bento4 1.5.1-627, AP4_DataBuffer::SetDataSize does not handle reallocation failures, leading to a memory copy into a
Adobe Experience Manager version 6.4 and ealier have a Cross-Site Request Forgery vulnerability. Successful exploitation
Adobe Bridge CC version 9.0.2 and earlier versions have an out of bound read vulnerability. Successful exploitation coul
Jenkins Credentials Binding Plugin Jenkins 1.17 is affected by: CWE-257: Storing Passwords in a Recoverable Format. The
Embedded systems based on Arduino before Rev3 allow remote attackers to send data to LEDs (directly connected to GPIO pi
The JPXStream::init function in Poppler 0.78.0 and earlier doesn't check for negative values of stream length, leading t
Juniper juniper/libslax libslax latest version (as of commit 084ddf6ab4a55b59dfa9a53f9c5f14d192c4f8e5 Commits on Sep 1,
The user password via the registration form of TronLink Wallet 2.2.0 is stored in the log when the class CreateWalletTwo
The Momo application 2.1.9 for Android stores confidential information insecurely on the system (i.e., in cleartext), wh
The Send Anywhere application 9.4.18 for Android stores confidential information insecurely on the system (i.e., in clea
Jeesite 1.2.7 is affected by: XML External Entity (XXE). The impact is: sensitive information disclosure. The component
If the ALT and "a" keys are pressed when users receive an extension installation prompt, the extension will be installed
A malicious page can briefly cause the wrong name to be highlighted as the domain name in the addressbar during page nav
A hyperlink using the res: protocol can be used to open local files at a known location in Internet Explorer if a user a
A hyperlink using protocols associated with Internet Explorer, such as IE.HTTP:, can be used to open local files at a kn
The unicode latin 'kra' character can be used to spoof a standard 'k' character in the addressbar. This allows for domai
When a user navigates to site marked as unsafe by the Safebrowsing API, warning messages are displayed and navigation is
Scan for 2019 Vulnerabilities
CyberStrike detects these CVEs across your infrastructure automatically.
Get Started