17,305 vulnerabilities published in 2019
An issue was discovered in PrinterOn Central Print Services (CPS) through 4.1.4. A user without valid credentials can by
An issue was discovered in Veritas Resiliency Platform (VRP) before 3.4 HF1. When uploading an application bundle, a dir
cPanel before 80.0.22 allows remote code execution by a demo account because of incorrect URI dispatching (SEC-501).
cPanel before 80.0.5 allows demo accounts to execute arbitrary code via ajax_maketext_syntax_util.pl (SEC-498).
cPanel before 78.0.18 allows code execution via an addforward API1 call (SEC-480).
cPanel before 78.0.18 allows demo accounts to execute code via securitypolicy.cg (SEC-487).
A flaw was discovered in the python-novajoin plugin, all versions up to, excluding 1.1.1, for Red Hat OpenStack Platform
A sandbox bypass vulnerability in Jenkins Script Security Plugin 1.61 and earlier related to the handling of type casts
A sandbox bypass vulnerability in Jenkins Script Security Plugin 1.61 and earlier related to the handling of method poin
CImg through 2.6.7 has a heap-based buffer overflow in _load_bmp in CImg.h because of erroneous memory allocation for a
An exploitable code execution vulnerability exists in the PCX image-rendering functionality of SDL2_image 2.0.4. A speci
An exploitable code execution vulnerability exists in the XCF image rendering functionality of SDL2_image 2.0.4. A speci
An exploitable code execution vulnerability exists in the XPM image rendering functionality of SDL2_image 2.0.4. A speci
An exploitable code execution vulnerability exists in the XPM image rendering function of SDL2_image 2.0.4. A specially
SAS Drug Development (SDD) before 32DRG02 mishandles logout actions, which allows a user (who was previously logged in)
A vulnerability in the Link Layer Discovery Protocol (LLDP) subsystem of Cisco Nexus 9000 Series Application Centric Inf
Cross-site request forgery in WallacePOS 1.4.3 allows a remote attacker to perform sensitive application actions by tric
A flaw was found in moodle before versions 3.7.1, 3.6.5, 3.5.7. A sesskey (CSRF) token was not being utilised by the XML
Windu CMS 2.2 allows CSRF via admin/users/?mn=admin.message.error to add an admin account.
cPanel before 11.54.0.4 allows arbitrary code execution via scripts/synccpaddonswithsqlhost (SEC-83).
cPanel before 11.54.0.4 allows arbitrary code execution during locale duplication (SEC-72).
cPanel before 55.9999.141 allows arbitrary code execution in the context of the root account because of MakeText interpo
cPanel before 55.9999.141 allows arbitrary code execution because of an unsafe @INC path (SEC-97).
cPanel before 55.9999.141 allows account-suspension bypass via ftp (SEC-105).
cPanel before 57.9999.54 allows demo-mode escape via show_template.stor (SEC-119).
cPanel before 57.9999.54 allows Webmail accounts to execute arbitrary code through forwarders (SEC-121).
cPanel before 55.9999.141 allows daemons to access their controlling TTYs (SEC-31).
cPanel before 55.9999.141 allows attackers to bypass Two Factor Authentication via DNS clustering requests (SEC-93).
cPanel before 64.0.21 allows code execution by webmail and demo accounts via a store_filter API call (SEC-236).
In Advantech WebAccess HMI Designer Version 2.1.9.23 and prior, processing specially crafted MCR files lacking proper va
A carefully crafted or corrupt zip file can cause an OOM in Apache Tika's RecursiveParserWrapper in versions 1.7-1.21. U
A cross-site request forgery (CSRF) vulnerability exists in the checkout cart item of Magento 2.1 prior to 2.1.18, Magen
A security bypass exists in Magento 2.1 prior to 2.1.18, Magento 2.2 prior to 2.2.9, Magento 2.3 prior to 2.3.2 that cou
A remote code execution vulnerability exists in Magento 2.1 prior to 2.1.18, Magento 2.2 prior to 2.2.9, Magento 2.3 pri
Insufficient input validation in the config builder of the Elastic search module could lead to remote code execution in
In Joomla! 3.9.7 and 3.9.8, inadequate filtering allows users authorised to create custom fields to manipulate the filte
cPanel before 60.0.25 allows format-string injection in exception-message handling (SEC-171).
cPanel before 62.0.4 has a fixed password for the Munin MySQL test account (SEC-196).
In cPanel before 62.0.4, Exim piped filters ran in the context of an incorrect user account when delivering to a system
cPanel before 60.0.25 allows arbitrary code execution via Maketext in PostgreSQL adminbin (SEC-188).
cPanel before 60.0.25 allows code execution via the cpsrvd 403 error response handler (SEC-191).
AdPlug 2.3.1 has a heap-based buffer overflow in CxadbmfPlayer::__bmf_convert_stream() in bmf.cpp.
AdPlug 2.3.1 has a heap-based buffer overflow in CdtmLoader::load() in dtm.cpp.
AdPlug 2.3.1 has a heap-based buffer overflow in CmkjPlayer::load() in mkj.cpp.
cPanel before 59.9999.145 allows code execution in the context of other accounts via mailman list archives (SEC-141).
cPanel before 59.9999.145 allows arbitrary code execution due to an incorrect #! in Mail::SPF scripts (SEC-152).
Internal/Views/config.php in Schben Adive 2.0.7 allows admin/config CSRF to change a user password.
Internal/Views/addUsers.php in Schben Adive 2.0.7 allows remote unprivileged users (editor or developer) to create an ad
eQ-3 Homematic CCU2 and CCU3 use session IDs for authentication but lack authorization checks. Consequently, a valid gue
Buffer overflow in PTP (Picture Transfer Protocol) of EOS series digital cameras (EOS-1D X firmware version 2.1.0 and ea
Scan for 2019 Vulnerabilities
CyberStrike detects these CVEs across your infrastructure automatically.
Get Started