17,305 vulnerabilities published in 2019
Multiple padding oracle vulnerabilities (Zombie POODLE, GOLDENDOODLE, OpenSSL 0-length) in the CBC padding implementatio
An issue was discovered in the portaudio crate through 0.7.0 for Rust. There is a man-in-the-middle issue because the so
An issue was discovered in OpenCV 4.1.0. There is a divide-by-zero error in cv::HOGDescriptor::getDescriptorSize in modu
In all versions prior to version 3.9.6 for eclipse-wtp, all versions prior to version 9.4.4 for eclipse-cdt, and all ver
An information disclosure vulnerability exists in the way Rome SDK handles server SSL/TLS certificate validation, aka 'R
The PGP signing plugin in Gradle before 6.0 relies on the SHA-1 algorithm, which might allow an attacker to replace an a
A CWE-248: Uncaught Exception vulnerability exists IN Modicon M580 all versions prior to V2.80, which could cause a poss
The Print Service is susceptible to man in the middle attacks due to improperly used crypto. This could lead to remote i
In wpa_supplicant, there is a possible man in the middle vulnerability due to improper input validation of the basicCons
Description: Western Digital SSD Dashboard before 2.5.1.0 and SanDisk SSD Dashboard before 2.5.1.0 applications are pote
JetBrains IntelliJ IDEA before 2019.2 was resolving the markdown plantuml artifact download link via a cleartext http co
JetBrains Toolbox before 1.15.5605 was resolving an internal URL via a cleartext http connection.
MatrixSSL 4.2.1 and earlier contains a timing side channel in ECDSA signature generation. This allows a local or a remot
A race condition which may occur when discarding malformed packets can result in BIND exiting due to a REQUIRE assertion
Clustered Data ONTAP versions 9.0 and higher do not enforce hostname verification under certain circumstances making the
On EX4600, QFX5100 Series, NFX Series, QFX10K Series, QFX5110, QFX5200 Series, QFX5110, QFX5200, QFX10K Series, vSRX, SR
A tampering vulnerability exists in Microsoft Windows when a man-in-the-middle attacker is able to successfully bypass t
A spoofing vulnerability exists when Transport Layer Security (TLS) accesses non- Extended Master Secret (EMS) sessions,
A security feature bypass vulnerability exists in Microsoft Windows when a man-in-the-middle attacker is able to success
A vulnerability has been found in the implementation of the Label Distribution Protocol (LDP) protocol in EOS. Under rac
Vulnerability in the Oracle Retail Customer Management and Segmentation Foundation product of Oracle Retail Applications
Vulnerability in the MICROS Relate CRM Software product of Oracle Retail Applications (component: Internal Operations).
Vulnerability in the Java SE, Java SE Embedded product of Oracle Java SE (component: Libraries). Supported versions that
Mirror zones are a BIND feature allowing recursive servers to pre-cache zone data provided by other servers. A mirror zo
A defect in code added to support QNAME minimization can cause named to exit with an assertion failure if a forwarder re
Man-in-the-middle vulnerability in Micro Focus Self Service Password Reset, affecting all versions prior to 4.4.0.4. The
Sensitive information disclosure vulnerability resulting from a lack of certificate validation during the File-Based Bac
Sensitive information disclosure vulnerability resulting from a lack of certificate validation during the File-Based Bac
Mercurial before 1.6.4 fails to verify the Common Name field of SSL certificates which allows remote attackers who acqui
OpenAFS before 1.6.24 and 1.8.x before 1.8.5 is prone to information leakage upon certain error conditions because unini
The malware scan function in Total Defense Anti-virus 11.5.2.28 is vulnerable to a TOCTOU bug; consequently, symbolic li
An exploitable vulnerability exists in the grsecurity PaX patch for the function read_kmem, in PaX from version pax-linu
HTTPSConnections in OpenStack Keystone 2013, OpenStack Compute 2013.1, and possibly other OpenStack components, fail to
Cache Poisoning issue exists in DNS Response Rate Limiting.
The mirroring support (-M, --use-mirrors) in Python Pip before 1.5 uses insecure DNS querying and authenticity checks wh
Technicolor C2000T and C2100T uses hard-coded cryptographic keys.
vdsm and vdsclient does not validate certficate hostname from another vdsm which could facilitate a man-in-the-middle at
offlineimap before 6.3.2 does not check for SSL server certificate validation when "ssl = yes" option is specified which
In Mitsubishi Electric MELSEC-Q Series Q03/04/06/13/26UDVCPU: serial number 21081 and prior, Q04/06/13/26UDPVCPU: serial
STMicroelectronics ST33TPHF2ESPI TPM devices before 2019-09-12 allow attackers to extract the ECDSA private key via a si
An issue was discovered on Zyxel GS1900 devices with firmware before 2.50(AAHH.0)C0. The firmware hashes and encrypts pa
Perdition before 2.2 may have weak security when handling outbound connections, caused by an error in the STARTTLS IMAP
A memory leak in the nfp_abm_u32_knode_replace() function in drivers/net/ethernet/netronome/nfp/abm/cls.c in the Linux k
Four memory leaks in the nfp_flower_spawn_phy_reprs() function in drivers/net/ethernet/netronome/nfp/flower/main.c in th
A memory leak in the nfp_flower_spawn_vnic_reprs() function in drivers/net/ethernet/netronome/nfp/flower/main.c in the L
Use of a hardcoded cryptographic key in the FortiGuard services communication protocol may allow a Man in the middle wit
Jenkins Google Compute Engine Plugin 4.1.1 and earlier does not verify SSH host keys when connecting agents created by t
The containers/image library used by the container tools Podman, Buildah, and Skopeo in Red Hat Enterprise Linux version
OpenStack Nova before 2012.1 allows someone with access to an EC2_ACCESS_KEY (equivalent to a username) to obtain the EC
SQLite 3.30.1 mishandles pExpr->y.pTab, as demonstrated by the TK_COLUMN case in sqlite3ExprCodeTarget in expr.c.
Scan for 2019 Vulnerabilities
CyberStrike detects these CVEs across your infrastructure automatically.
Get Started