17,305 vulnerabilities published in 2019
The wp-editor plugin before 1.2.6 for WordPress has CSRF.
The custom-sidebars plugin before 3.1.0 for WordPress has CSRF related to set location, import actions, and export actio
The custom-sidebars plugin before 3.0.8.1 for WordPress has CSRF.
The newsletter-by-supsystic plugin before 1.1.8 for WordPress has CSRF.
The responsive-menu plugin before 3.1.4 for WordPress has no CSRF protection mechanism for the admin interface.
The wp-ultimate-csv-importer plugin before 5.6.1 for WordPress has CSRF.
The wp-ultimate-exporter plugin before 1.4.2 for WordPress has CSRF.
An issue was discovered in Bento4 1.5.1.0. There is a heap-based buffer over-read in the function AP4_BitReader::SkipBit
An issue was discovered in Bento4 1.5.1.0. There is a heap-based buffer overflow in the AP4_RtpAtom class at Core/Ap4Rtp
An issue was discovered in Bento4 1.5.1.0. There is a heap-based buffer over-read in the AP4_Dec3Atom class at Core/Ap4D
An issue was discovered in Bento4 1.5.1.0. There is a heap-based buffer over-read in the AP4_AvccAtom class at Core/Ap4A
It was found that Keycloak's account console, up to 6.0.1, did not perform adequate header checks in some requests. An a
The web-based configuration interface of the TP-Link M7350 V3 with firmware before 190531 is affected by several post-au
An issue was discovered in the svg-vector-icon-plugin (aka WP SVG Icons) plugin through 3.2.1 for WordPress. wp-admin/ad
A remote code execution vulnerability exists in the way that the Chakra scripting engine handles objects in memory in Mi
A remote code execution vulnerability exists when the Windows font library improperly handles specially crafted embedded
A remote code execution vulnerability exists when the Windows font library improperly handles specially crafted embedded
A remote code execution vulnerability exists when the Windows font library improperly handles specially crafted embedded
A remote code execution vulnerability exists when the Windows font library improperly handles specially crafted embedded
A remote code execution vulnerability exists when the Windows font library improperly handles specially crafted embedded
A remote code execution vulnerability exists when the Windows font library improperly handles specially crafted embedded
This information is being revised to indicate that this CVE (CVE-2019-1183) is fully mitigated by the security updates f
An elevation of privilege vulnerability exists in Dynamics On-Premise v9. An attacker who successfully exploited the vul
An elevation of privilege vulnerability exists in Azure Active Directory Authentication Library On-Behalf-Of flow, in th
The profile photo upload feature in Leaf Admin 61.9.0212.10 f allows Unrestricted Upload of a File with a Dangerous Type
All versions up to V1.1.10P3T18 of ZTE ZXHN F670 product are impacted by command injection vulnerability. Due to insuffi
wp-admin/admin-ajax.php?action=newsletters_exportmultiple in the Tribulant Newsletters plugin before 4.6.19 for WordPres
An issue was discovered in in TortoiseSVN 1.12.1. The Tsvncmd: URI handler allows a customised diff operation on Excel w
An issue was discovered in 3S-Smart CODESYS V3 products. The application may utilize non-TLS based encryption, which res
In ClickHouse before 1.1.54388, "remote" table function allowed arbitrary symbols in "user", "password" and "default_dat
Yes24ViewerX ActiveX Control 1.0.327.50126 and earlier versions contains a vulnerability that could allow remote attacke
In OSIsoft PI Web API and prior, the affected product is vulnerable to a direct attack due to a cross-site request forge
A directory traversal vulnerability in the v-list-user script in Vesta Control Panel 0.9.8-24 allows remote attackers to
A command injection vulnerability in UploadHandler.php in Vesta Control Panel 0.9.8-24 allows remote attackers to escala
An issue was discovered in Zoho ManageEngine OpManager through 12.4x. There is a SQL Injection vulnerability in jsp/NewT
An issue was discovered in Zoho ManageEngine Application Manager through 14.2. There is a SQL Injection vulnerability in
EyesOfNetwork 5.1 allows Remote Command Execution via shell metacharacters in the module/tool_all/ host field.
The erident-custom-login-and-dashboard plugin before 3.5 for WordPress has CSRF.
The invite-anyone plugin before 1.3.16 for WordPress has admin-panel CSRF.
The jayj-quicktag plugin before 1.3.2 for WordPress has CSRF.
The nelio-ab-testing plugin before 4.6.4 for WordPress has CSRF in experiment forms.
The church-admin plugin before 1.2550 for WordPress has CSRF affecting the upload of a bible reading plan.
The companion-auto-update plugin before 3.2.1 for WordPress has CSRF.
The js-jobs plugin before 1.0.7 for WordPress has CSRF.
The companion-sitemap-generator plugin before 3.7.0 for WordPress has CSRF.
The formcraft-form-builder plugin before 1.2.2 for WordPress has CSRF.
The peters-login-redirect plugin before 2.9.2 for WordPress has CSRF.
coders/mat.c in ImageMagick 7.0.8-43 Q16 allows remote attackers to cause a denial of service (use-after-free and applic
In the OAuth2 Client extension before 0.4 for MediaWiki, a CSRF vulnerability exists due to the OAuth2 state parameter n
FUEL CMS 1.4.4 has CSRF in the blocks/create/ Create Blocks section of the Admin console. This could lead to an attacker
Scan for 2019 Vulnerabilities
CyberStrike detects these CVEs across your infrastructure automatically.
Get Started