17,305 vulnerabilities published in 2019
In RubyGem excon before 0.71.0, there was a race condition around persistent connections, where a connection which is in
WordPress users with lower privileges (like contributors) can inject JavaScript code in the block editor using a specifi
In WordPress before 5.3.1, authenticated users with lower privileges (like contributors) can inject JavaScript code in t
It was found Ceph versions before 13.2.4 that authenticated ceph users with read only permissions could steal dm-crypt e
MyWebSQL 3.7 has a Cross-site request forgery (CSRF) vulnerability for deleting a database via the /?q=wrkfrm&type=datab
An issue was discovered in idreamsoft iCMS through 7.0.14. A CSRF vulnerability can delete users' articles via the publi
Ekiga versions before 3.3.0 attempted to load a module from /tmp/ekiga_test.so.
python-dbusmock before version 0.15.1 AddTemplate() D-Bus method call or DBusTestCase.spawn_server_template() method cou
A spoofing vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted web requ
A spoofing vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted web requ
An issue was discovered in GNOME gvfs 1.29.4 through 1.41.2. daemon/gvfsbackendadmin.c mishandles a file's user and grou
A potential improper access control vulnerability exists in the backup mechanism of the Bosch Smart Home Controller (SHC
Gemalto DS3 Authentication Server 2.6.1-SP01 allows Local File Disclosure.
Gemalto DS3 Authentication Server 2.6.1-SP01 has Broken Access Control.
The ABB IDAL FTP server is vulnerable to a buffer overflow when a long string is sent by an authenticated attacker. This
Use after free in Bluetooth in Google Chrome prior to 68.0.3440.75 allowed an attacker who convinced a user to install a
ZTE MW NR8000V2.4.4.03 and NR8000V2.4.4.04 are impacted by path traversal vulnerability. Due to path traversal,users can
Vulnerability in the Oracle FLEXCUBE Universal Banking component of Oracle Financial Services Applications (subcomponent
Vulnerability in the Oracle FLEXCUBE Investor Servicing component of Oracle Financial Services Applications (subcomponen
bin/csvprocess in cPanel before 68.0.27 allows insecure file operations (SEC-354).
The admin-renamer-extended (aka Admin renamer extended) plugin 3.2.1 for WordPress allows wp-admin/plugins.php?page=admi
The codection "Import users from CSV with meta" plugin before 1.14.2.2 for WordPress allows wp-admin/admin-ajax.php?acti
IBM Business Automation Workflow 18.0.0.0, 18.0.0.1, and 18.0.0.2 could allow a user to obtain highly sensitive informat
Libra Core before 2019-09-03 has an erroneous regular expression for inline comments, which makes it easier for attacker
Vulnerability in the Core RDBMS (jackson-databind) component of Oracle Database Server. Supported versions that are affe
Vulnerability in the Oracle FLEXCUBE Direct Banking product of Oracle Financial Services Applications (component: Paymen
A missing check on incoming client requests can be exploited to cause a situation where the Kea server's lease storage c
A security vulnerability exists in a management port in the version of ZTE's ZXMP M721V3.10P01B10_M2NCP. An attacker cou
A specially crafted Bitcoin script can cause a discrepancy between the specified SLP consensus rules and the validation
A specially crafted Bitcoin script can cause a discrepancy between the specified SLP consensus rules and the validation
The Huawei Share function of P20 phones with versions earlier than Emily-L29C 9.1.0.311 has an improper file management
This issue was addressed with improved transparency. This issue is fixed in iOS 12.2. A user may authorize an enterprise
An inconsistency in Wi-Fi network configuration settings was addressed. This issue is fixed in iOS 13.2 and iPadOS 13.2.
Vulnerability in the Oracle VM VirtualBox component of Oracle Virtualization (subcomponent: Core). Supported versions th
A prototype pollution vulnerability was found in lodash <4.17.11 where the functions merge, mergeWith, and defaultsDeep
kernel/bpf/verifier.c in the Linux kernel before 4.20.6 performs undesirable out-of-bounds speculation on pointer arithm
Data Leakage Attacks vulnerability in Microsoft Windows client in McAfee True Key (TK) 3.1.9211.0 and earlier allows loc
IBM SDK, Java Technology Edition Version 8 on the AIX platform uses absolute RPATHs which may facilitate code injection
A flaw was found in the way KVM hypervisor handled x2APIC Machine Specific Rregister (MSR) access with nested(=1) virtua
GE Communicator, all versions prior to 4.0.517, has a service running with system privileges that may allow an unprivile
Microarchitectural Store Buffer Data Sampling (MSBDS): Store buffers on some microprocessors utilizing speculative execu
Microarchitectural Load Port Data Sampling (MLPDS): Load ports on some microprocessors utilizing speculative execution m
Microarchitectural Data Sampling Uncacheable Memory (MDSUM): Uncacheable memory on some microprocessors utilizing specul
A vulnerability was found in the app 2.0 of the Shenzhen Jisiwei i3 robot vacuum cleaner. Actions performed on the app s
Vulnerability in the Oracle Clusterware component of Oracle Support Tools (subcomponent: Trace File Analyzer (TFA) Colle
In the Linux kernel before 2.6.37, an out of bounds array access happened in drivers/net/mlx4/port.c. When searching for
cPanel before 68.0.27 allows arbitrary file-read operations via restore adminbin (SEC-349).
An information disclosure vulnerability exists in SymCrypt during the OAEP decryption stage. An attacker who successfull
An information disclosure vulnerability exists when certain central processing units (CPU) speculatively access memory.
A backporting error was discovered in the Linux stable/longterm kernel 4.4.x through 4.4.190, 4.9.x through 4.9.190, 4.1
Scan for 2019 Vulnerabilities
CyberStrike detects these CVEs across your infrastructure automatically.
Get Started