17,305 vulnerabilities published in 2019
A cross-site request forgery vulnerability in Jenkins Artifactory Plugin 3.2.2 and earlier in ReleaseAction#doSubmit, Gr
The "action" get_sess_id in the web application of Pydio through 8.2.2 discloses the session cookie value in the respons
The Quest Kace K1000 Appliance, versions prior to 9.0.270, allows an authenticated, remote attacker with least privilege
A Directory Traversal issue was discovered in the Web GUI in Titan FTP Server 2019 Build 3505. When an authenticated use
There is a DoS vulnerability in RTSP module of Leland-AL00A Huawei smart phones versions earlier than Leland-AL00A 9.1.0
Lack of root file system integrity checking in Fortinet FortiOS VM application images all versions below 6.0.5 may allow
An issue was discovered in phpMyAdmin before 4.9.0. A vulnerability was found that allows an attacker to trigger a CSRF
A remote credential disclosure vulnerability was identified in HPE Intelligent Management Center (IMC) PLAT earlier than
IBM Maximo Asset Management 7.6 could allow a an authenticated user to replace a target page with a phishing site which
Progress Sitefinity 10.1.6536 does not invalidate session cookies upon logouts. It instead tries to overwrite the cookie
An issue was discovered in MantisBT through 1.3.14, and 2.0.0. Using a crafted request on bug_report_page.php (modifying
Gallagher Command Centre before 7.80.939, 7.90.x before 7.90.961, and 8.x before 8.00.1128 allows arbitrary event creati
Hasplm cookie in Gemalto Admin Control Center, all versions prior to 7.92, does not have 'HttpOnly' flag. This allows ma
WampServer before 3.1.9 has CSRF in add_vhost.php because the synchronizer pattern implemented as remediation of CVE-201
Jenkins ElectricFlow Plugin 1.1.5 and earlier disabled SSL/TLS and hostname verification globally for the Jenkins master
An issue was discovered in Joomla! before 3.9.7. The update server URL of com_joomlaupdate can be manipulated by non Sup
This security update corrects a denial of service in the Local Security Authority Subsystem Service (LSASS) caused when
A remote code execution vulnerability exists in the way that the Chakra scripting engine handles objects in memory in Mi
A spoofing vulnerability exists in Azure DevOps Server when it improperly handles requests to authorize applications, re
An information disclosure vulnerability exists when the scripting engine does not properly handle objects in memory in M
A denial of service vulnerability exists when Windows improperly handles objects in memory. An attacker who successfully
A vulnerability was found in keycloak before 6.0.2. The X.509 authenticator supports the verification of client certific
A Buffer Overflow in VLC Media Player < 3.0.7 causes a crash which can possibly be further developed into a remote code
IBM Cognos Controller 10.2.0, 10.2.1, 10.3.0, 10.3.1, and 10.4.0 could allow a remote attacker to obtain sensitive infor
An issue was discovered on Vera VeraEdge 1.7.19 and Veralite 1.7.481 devices. The device provides UPnP services that are
An issue was discovered on Vera VeraEdge 1.7.19 and Veralite 1.7.481 devices. The device provides a script file called "
OPNsense 18.7.x before 18.7.7 has Incorrect Access Control.
Recently it was discovered as a part of the research on IoT devices in the most recent firmware for Shekar Endoscope tha
Recently it was discovered as a part of the research on IoT devices in the most recent firmware for Shekar Endoscope tha
Recently it was discovered as a part of the research on IoT devices in the most recent firmware for Shekar Endoscope tha
An issue was discovered in Netdata 1.10.0. JSON injection exists via the api/v1/data tqx parameter because of web_client
Alpine Linux abuild through 3.4.0 allows an unprivileged member of the abuild group to add an untrusted package via a --
An issue was discovered on Securifi Almond, Almond+, and Almond 2015 devices with firmware AL-R096. The device provides
Samba 4.9.x before 4.9.9 and 4.10.x before 4.10.5 has a NULL pointer dereference, leading to Denial of Service. This is
Samba 4.10.x before 4.10.5 has a NULL pointer dereference, leading to an AD DC LDAP server Denial of Service. This is re
IBM Spectrum Protect Plus 10.1.2 may display the vSnap CIFS password in the IBM Spectrum Protect Plus Joblog. This can r
The doAirdrop function of a smart contract implementation for Primeo (PEO), an Ethereum token, does not check the numeri
NGA ResourceLink 20.0.2.1 allows local file inclusion.
An issue was discovered on Teltonika RTU950 R_31.04.89 devices. The application allows a user to login without limitatio
The Photo Sharing Plus component on Sony Bravia TV through 8.587 devices has a Buffer Overflow.
In llcp_util_parse_connect of llcp_util.cc, there is a possible out-of-bound read due to a missing bounds check. This co
In llcp_util_parse_cc of llcp_util.cc, there is a possible out-of-bound read due to a missing bounds check. This could l
In llcp_util_parse_link_params of llcp_util.cc, there is a possible out-of-bound read due to a missing bounds check. Thi
In ce_t4t_data_cback of ce_t4t.cc, there is a possible out-of-bound read due to a missing bounds check. This could lead
In llcp_dlc_proc_rr_rnr_pdu of llcp_dlc.cc, there is a possible out-of-bound read due to a missing bounds check. This co
In rw_t3t_act_handle_ndef_detect_rsp of rw_t3t.cc, there is a possible out-of-bound read due to a missing bounds check.
In rw_t3t_act_handle_fmt_rsp and rw_t3t_act_handle_sro_rsp of rw_t3t.cc, there is a possible out-of-bound read due to a
Pydio Cells before 1.5.0 does incomplete cleanup of a user's data upon deletion. This allows a new user, holding the sam
A vulnerability in the Server Utilities of Cisco Integrated Management Controller (IMC) could allow an authenticated, re
A vulnerability in Cisco Security Manager could allow an unauthenticated, remote attacker to access sensitive informatio
Scan for 2019 Vulnerabilities
CyberStrike detects these CVEs across your infrastructure automatically.
Get Started