17,305 vulnerabilities published in 2019
IBM API Connect 2018.1 and 2018.4.1.4 could allow a remote attacker to hijack the clicking action of the victim. By pers
An issue was discovered in Espressif ESP-IDF 2.x and 3.x before 3.0.6 and 3.1.x before 3.1.1. Insufficient validation of
Dell EMC RecoverPoint versions prior to 5.1.3 and RecoverPoint for VMs versions prior to 5.2.0.2 contain an OS command i
A vulnerability in the Remote Package Manager (RPM) subsystem of Cisco NX-OS Software could allow an authenticated, loca
Huawei Honor V10 smartphones versions earlier than Berkeley-AL20 9.0.0.125(C00E125R2P14T8) have an authorization bypass
A remote code execution vulnerability exists in the way that comctl32.dll handles objects in memory. The vulnerability c
It was found that Picketlink as shipped with Jboss Enterprise Application Platform 7.2 would accept an xinclude paramete
An issue was discovered on Securifi Almond, Almond+, and Almond 2015 devices with firmware AL-R096. The device provides
A vulnerability in the CLI of Cisco Integrated Management Controller (IMC) could allow an authenticated, local attacker
Intersystems Cache 2017.2.2.865.0 allows XXE.
Vulnerability in the PeopleSoft Enterprise FIN Project Costing component of Oracle PeopleSoft Products (subcomponent: Pr
A remote code execution vulnerability exists in the way that Microsoft browsers access objects in memory. The vulnerabil
An issue was discovered in the Linux kernel before 5.0.10. There is a use-after-free in the sound subsystem because card
Dell EMC Enterprise Copy Data Management (eCDM) versions 1.0, 1.1, 2.0, 2.1, and 3.0 contain a certificate validation vu
OpenSC before 0.20.0-rc1 has an out-of-bounds access of an ASN.1 Bitstring in decode_bit_string in libopensc/asn1.c.
OpenSC before 0.20.0-rc1 has an out-of-bounds access of an ASN.1 Octet string in asn1_decode_entry in libopensc/asn1.c.
In the Android kernel in the mnh driver there is a race condition due to insufficient locking. This could lead to a use-
In the Android kernel in the FingerTipS touchscreen driver there is a possible memory corruption due to a race condition
The RSA Identity Governance and Lifecycle software and RSA Via Lifecycle and Governance products prior to 7.1.0 P08 cont
The RSA Identity Governance and Lifecycle software and RSA Via Lifecycle and Governance products prior to 7.1.0 P08 cont
In the Easel driver, there is possible memory corruption due to race conditions. This could lead to local escalation of
In the Easel driver, there is possible memory corruption due to race conditions. This could lead to local escalation of
In hostapd, there is a possible out of bounds write due to a race condition. This could lead to local escalation of priv
A remote code execution vulnerability exists in the way that the VBScript engine handles objects in memory, aka 'VBScrip
Vulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Fusion Middleware (component: Ana
Vulnerability in the Hyperion Data Relationship Management product of Oracle Hyperion (component: Access and Security).
A potential vulnerability in the SMI callback function used in the Legacy USB driver using boot services structure in ru
A potential vulnerability in the SMI callback function used in Legacy USB driver using passed parameter without sufficie
Vulnerability in the Oracle Application Testing Suite component of Oracle Enterprise Manager Products Suite (subcomponen
A vulnerability was discovered in gdm before 3.31.4. When timed login is enabled in configuration, an attacker could byp
Insufficient access control in User Mode Driver in Intel(R) Graphics Driver for Windows* before versions 10.18.x.5059 (a
A flaw was found in the /oauth/token/request custom endpoint of the OpenShift OAuth server allowing for XSS generation o
IBM InfoSphere Information Server 11.5 and 11.7 is vulnerable to SQL injection. A remote attacker could send specially-c
Vulnerability in the Oracle Application Testing Suite component of Oracle Enterprise Manager Products Suite (subcomponen
Vulnerability in the MySQL Connectors component of Oracle MySQL (subcomponent: Connector/J). Supported versions that are
SEP (Mac client) prior to and including 12.1 RU6 MP9 and prior to 14.2 RU1 may be susceptible to a CSV/DDE injection (al
The Vivo V7 Android device with a build fingerprint of vivo/1718/1718:7.1.2/N2G47H/compil11021857:user/release-keys cont
IBM Tivoli Storage Productivity Center (IBM Spectrum Control Standard Edition 5.2.1 through 5.2.17) allows users to rema
Vulnerability in the Enterprise Manager Ops Center component of Oracle Enterprise Manager Products Suite (subcomponent:
Open directories in Ivanti LANDESK Management Suite (LDMS, aka Endpoint Manager) 10.0.1.168 Service Update 5 may lead to
A remote code execution vulnerability was identified in HPE Intelligent Management Center (IMC) PLAT earlier than versio
An elevation of privilege vulnerability exists when the Windows User Profile Service (ProfSvc) improperly handles symlin
An elevation of privilege vulnerability exists when the Windows Shell fails to validate folder shortcuts. An attacker wh
Code injection vulnerability in Palo Alto Networks Traps 5.0.5 and earlier may allow an authenticated attacker to inject
A security feature bypass vulnerability exists when Active Directory Federation Services (ADFS) improperly updates its l
Vulnerability in the Solaris component of Oracle Sun Systems Products Suite (subcomponent: Open Fabrics Tools). The supp
Vulnerability in the Oracle Outside In Technology component of Oracle Fusion Middleware (subcomponent: Outside In Filter
A cross-site request forgery vulnerability in Jenkins Maven Release Plugin 0.14.0 and earlier in the M2ReleaseAction#doS
cPanel before 74.0.8 allows demo accounts to execute arbitrary code via the Fileman::viewfile API (SEC-444).
cPanel before 70.0.23 allows demo accounts to execute code via awstats (SEC-362).
Scan for 2019 Vulnerabilities
CyberStrike detects these CVEs across your infrastructure automatically.
Get Started