17,305 vulnerabilities published in 2019
The simple-login-log plugin before 1.1.2 for WordPress has SQL injection.
The ninja-forms plugin before 3.3.21.2 for WordPress has SQL injection in the search filter on the submissions page.
The all-in-one-wp-security-and-firewall plugin before 3.9.1 for WordPress has multiple SQL injection issues.
The wp-editor plugin before 1.2.6 for WordPress has incorrect permissions.
The all-in-one-wp-security-and-firewall plugin before 4.0.9 for WordPress has multiple SQL injection issues.
The all-in-one-wp-security-and-firewall plugin before 4.0.7 for WordPress has multiple SQL injection issues.
A potential authorization bypass issue was found in Micro Focus Self Service Password Reset (SSPR) versions prior to: 4.
Wind River VxWorks 6.6, 6.7, 6.8, 6.9 and 7 has Incorrect Access Control in the RARP client component. IPNET security vu
The HTTP client in Gradle before 5.6 sends authentication credentials originally destined for the configured host. If th
A memory corruption vulnerability exists in the Windows DHCP client when an attacker sends specially crafted DHCP respon
The web-based configuration interface of the TP-Link M7350 V3 with firmware before 190531 is affected by a pre-authentic
An issue was discovered on NETGEAR Nighthawk M1 (MR1100) devices before 12.06.03. System commands can be executed, via t
A remote code execution vulnerability exists in Remote Desktop Services – formerly known as Terminal Services – when an
A remote code execution vulnerability exists in Remote Desktop Services – formerly known as Terminal Services – when an
A remote code execution vulnerability exists in Microsoft Word software when it fails to properly handle objects in memo
A memory corruption vulnerability exists in the Windows Server DHCP service when processing specially crafted packets. A
A memory corruption vulnerability exists in the Windows Server DHCP service when an attacker sends specially crafted pac
A remote code execution vulnerability exists in Remote Desktop Services – formerly known as Terminal Services – when an
A remote code execution vulnerability exists in Remote Desktop Services – formerly known as Terminal Services – when an
eQ-3 Homematic AddOn 'CloudMatic' on CCU2 and CCU3 allows uncontrolled admin access, resulting in the ability to obtain
eQ-3 Homematic CCU2 prior to 2.47.10 and CCU3 prior to 3.47.10 JSON API has Improper Access Control for Interface.***Met
A SQL injection vulnerability exists in the Impress GiveWP Give plugin through 2.5.0 for WordPress. Successful exploitat
Incorrect Access Control in the LDAP class of GONICUS GOsa through 2019-04-11 allows an attacker to log into any account
Incorrect configuration in deb package in ClickHouse before 1.1.54131 could lead to unauthorized use of the database.
In ClickHouse before 18.10.3, unixODBC allowed loading arbitrary shared objects from the file system which led to a Remo
An issue was discovered in 3S-Smart CODESYS V3 products. The CODESYS Gateway does not correctly verify the ownership of
LibreOffice is typically bundled with LibreLogo, a programmable turtle vector graphics script, which can execute arbitra
LibreOffice is typically bundled with LibreLogo, a programmable turtle vector graphics script, which can execute arbitra
An issue was discovered in Zoho ManageEngine OpManager in builds before 14310. One can bypass the user password requirem
An issue was discovered in Webmin <=1.920. The parameter old in password_change.cgi contains a command injection vulnera
filemgr.php in Artica Integria IMS 5.0.86 allows index.php?sec=wiki&sec2=operation/wiki/wiki&action=upload arbitrary fil
The visitors-online plugin before 0.4 for WordPress has SQL injection.
The wp-business-intelligence-lite plugin before 1.6.3 for WordPress has SQL injection.
The olimometer plugin before 2.57 for WordPress has SQL injection.
The note-press plugin before 0.1.2 for WordPress has SQL injection.
A command injection vulnerability in Nokogiri v1.10.3 and earlier allows commands to be executed in a subprocess via Rub
Creative Cloud Desktop Application versions 4.6.1 and earlier have an insecure inherited permissions vulnerability. Succ
Creative Cloud Desktop Application versions 4.6.1 and earlier have a using components with known vulnerabilities vulnera
Adobe Experience Manager versions 6.5, and 6.4 have an authentication bypass vulnerability. Successful exploitation coul
The i-recommend-this plugin before 3.7.3 for WordPress has SQL injection.
The 404-to-301 plugin before 2.0.3 for WordPress has SQL injection.
The easy-digital-downloads plugin before 2.3.3 for WordPress has SQL injection.
The invite-anyone plugin before 1.3.16 for WordPress has incorrect access control for email-based invitations.
The companion-auto-update plugin before 3.2.1 for WordPress has local file inclusion.
The Recruitment module in Humanica Humatrix 7 1.0.0.203 and 1.0.0.681 allows an unauthenticated attacker to upload any f
core.py in Mitogen before 0.2.8 has a typo that drops the unidirectional-routing protection mechanism in the case of a c
AdPlug 2.3.1 has a double free in the Cu6mPlayer class in u6m.h.
The rest-client gem 1.6.10 through 1.6.13 for Ruby, as distributed on RubyGems.org, included a code-execution backdoor i
Live555 before 2019.08.16 has a Use-After-Free because GenericMediaServer::createNewClientSessionWithId can generate the
The wp-all-import plugin before 3.2.5 for WordPress has blind SQL injection.
Scan for 2019 Vulnerabilities
CyberStrike detects these CVEs across your infrastructure automatically.
Get Started