17,305 vulnerabilities published in 2019
An information disclosure vulnerability exists when the Windows kernel improperly handles objects in memory, aka 'Window
An information disclosure vulnerability exists in the way that Microsoft Graphics Components handle objects in memory, a
An information disclosure vulnerability exists in the way that the Windows Graphics Device Interface (GDI) handles objec
An information disclosure vulnerability exists when affected Open Enclave SDK versions improperly handle objects in memo
The web application portal of the Cobham EXPLORER 710, firmware version 1.07, has no authentication by default. This cou
The web root directory of the Cobham EXPLORER 710, firmware version 1.07, has no access restrictions on downloading and
In ScreenRotationAnimation of ScreenRotationAnimation.java, there is a possible capture of a secure screen due to a miss
In generateServicesMap of RegisteredServicesCache.java, there is a possible account protection bypass due to a caching o
In nfc_ncif_decode_rf_params of nfc_ncif.cc, there is a possible out of bounds read due to an integer underflow. This co
A vulnerability was found in Ansible engine 2.x up to 2.8 and Ansible tower 3.x up to 3.5. When a module has an argument
Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported versions that are af
A Local Privilege Escalation vulnerability exists in the GlobalProtect Agent for Windows 5.0.3 and earlier, and GlobalPr
In Apache POI up to 4.1.0, when using the tool XSSFExportToXml to convert user-provided Microsoft Excel documents, a spe
A buffer over-read was discovered in ReadMP3APETag in apetag.c in MP3Gain 1.6.2. The vulnerability causes an application
An issue was discovered in Podman in libpod before 1.6.0. It resolves a symlink in the host context during a copy operat
mailscanner can allow local users to prevent virus signatures from being updated
IBM Security Guardium Big Data Intelligence (SonarG) 4.0 stores user credentials in plain in clear text which can be rea
IBM Security Guardium Big Data Intelligence (SonarG) 4.0 uses hard coded credentials which could allow a local user to o
paxtest handles temporary files insecurely
A stack based buffer overflow vulnerability exists in the method receiving data from SysTreeView32 control of the GMER 2
All versions of archiver allow attacker to perform a Zip Slip attack via the "unarchive" functions. It is exploited usin
xpdf allows remote attackers to cause a denial of service (NULL pointer dereference and crash) in the way it processes J
In xpdf, the xref table contains an infinite loop which allows remote attackers to cause a denial of service (applicatio
The quarantine restoration function in Total Defense Anti-virus 11.5.2.28 is vulnerable to symbolic link attacks, allowi
evince is missing a check on number of pages which can lead to a segmentation fault
Mutt before 1.5.20 patch 7 allows an attacker to cause a denial of service via a series of requests to mutt temporary fi
Insecure temporary file vulnerability in Redis before 2.6 related to /tmp/redis-%p.vm.
Insecure temporary file vulnerability in Redis 2.6 related to /tmp/redis.ds.
CloudForms stores user passwords in recoverable format
RHUI (Red Hat Update Infrastructure) 2.1.3 has world readable PKI entitlement certificates
Insecure temporary file vulnerability in RedHat vsdm 4.9.6.
A vulnerability in the implementation of a CLI diagnostic command in Cisco FXOS Software and Cisco NX-OS Software could
In the Linux kernel through 5.3.8, f->fmt.sdr.reserved is uninitialized in rcar_drif_g_fmt_sdr_cap in drivers/media/plat
The kernel in Red Hat Enterprise Linux 7 and MRG-2 does not clear garbage data for SG_IO buffer, which may leaking sensi
DCI client which might be preemptively freed up might be accessed for transferring packets leading to kernel error in Sn
While deserializing any key blob during key operations, buffer overflow could occur exposing partial key information if
MySQL-GUI-tools (mysql-administrator) leaks passwords into process list after with launch of mysql text console
A memory leak in the ql_alloc_large_buffers() function in drivers/net/ethernet/qlogic/qla3xxx.c in the Linux kernel befo
A memory leak in the ccp_run_sha_cmd() function in drivers/crypto/ccp/ccp-ops.c in the Linux kernel through 5.3.9 allows
A memory leak in the sof_set_get_large_ctrl_data() function in sound/soc/sof/ipc.c in the Linux kernel through 5.3.9 all
ldap-git-backup before 1.0.4 exposes password hashes due to incorrect directory permissions.
Eximious Logo Designer 3.82 has a User Mode Write AV starting at ExiVectorRender!StrokeText_Blend+0x00000000000003a7.
Eximious Logo Designer 3.82 has Heap Corruption starting at ntdll!RtlpNtMakeTemporaryKey+0x0000000000001a78.
Eximious Logo Designer 3.82 has a User Mode Write AV starting at ExiCustomPathLib!ExiCustomPathLib::CGradientColorsProfi
In Linux 2.6 before 2.6.23, the TRACE_IRQS_ON function in iret_exc calls a C function without ensuring that the segments
tuned before 2.x allows local users to kill running processes due to insecure permissions with tuned's ktune service.
An information-exposure vulnerability was discovered where openstack-mistral's undercloud log files containing clear-tex
The authentication mechanism, in Brocade SANnav versions before v2.0, logs plaintext account credentials at the ‘trace’
Brocade SANnav versions before v2.0, logs plain text database connection password while triggering support save.
NVIDIA Windows GPU Display Driver, all versions, contains a vulnerability in the kernel mode layer (nvlddmkm.sys) in whi
Scan for 2019 Vulnerabilities
CyberStrike detects these CVEs across your infrastructure automatically.
Get Started