17,305 vulnerabilities published in 2019
Adobe Photoshop CC versions 19.1.8 and earlier and 20.0.5 and earlier have an out of bound write vulnerability. Successf
Adobe Photoshop CC versions 19.1.8 and earlier and 20.0.5 and earlier have a heap overflow vulnerability. Successful exp
Adobe Photoshop CC versions 19.1.8 and earlier and 20.0.5 and earlier have an out of bound write vulnerability. Successf
Adobe Photoshop CC versions 19.1.8 and earlier and 20.0.5 and earlier have a type confusion vulnerability. Successful ex
Adobe Photoshop CC versions 19.1.8 and earlier and 20.0.5 and earlier have an out of bound write vulnerability. Successf
Adobe Photoshop CC versions 19.1.8 and earlier and 20.0.5 and earlier have an out of bound write vulnerability. Successf
Adobe Photoshop CC versions 19.1.8 and earlier and 20.0.5 and earlier have an out of bound write vulnerability. Successf
Adobe Photoshop CC versions 19.1.8 and earlier and 20.0.5 and earlier have a heap overflow vulnerability. Successful exp
Adobe Photoshop CC versions 19.1.8 and earlier and 20.0.5 and earlier have an out of bound write vulnerability. Successf
Adobe Photoshop CC versions 19.1.8 and earlier and 20.0.5 and earlier have an out of bound write vulnerability. Successf
Adobe Photoshop CC versions 19.1.8 and earlier and 20.0.5 and earlier have a command injection vulnerability. Successful
Adobe Photoshop CC versions 19.1.8 and earlier and 20.0.5 and earlier have an out of bound read vulnerability. Successfu
Adobe Photoshop CC versions 19.1.8 and earlier and 20.0.5 and earlier have an out of bound write vulnerability. Successf
Adobe Photoshop CC versions 19.1.8 and earlier and 20.0.5 and earlier have an out of bound read vulnerability. Successfu
Adobe Photoshop CC versions 19.1.8 and earlier and 20.0.5 and earlier have an out of bound read vulnerability. Successfu
The wp-rollback plugin before 1.2.3 for WordPress has CSRF.
The js-support-ticket plugin before 2.0.6 for WordPress has CSRF.
The bbp-move-topics plugin before 1.1.6 for WordPress has CSRF.
The zoho-salesiq plugin before 1.0.9 for WordPress has CSRF.
The groundhogg plugin before 1.3.5 for WordPress has wp-admin/admin-ajax.php?action=bulk_action_listener remote code exe
The insert-or-embed-articulate-content-into-wordpress plugin before 4.2999 for WordPress has insufficient restrictions o
The wp-members plugin before 3.2.8 for WordPress has CSRF.
Multiple CSRF issues exist in MicroPyramid Django CRM 0.2.1 via /change-password-by-admin/, /api/settings/add/, /cases/c
Edimax BR-6208AC V1 devices have Insufficient Compartmentalization between a host network and a guest network that are e
D-link DIR-825AC G1 devices have Insufficient Compartmentalization between a host network and a guest network that are e
D-link DIR-825AC G1 devices have Insufficient Compartmentalization between a host network and a guest network that are e
D-link DIR-825AC G1 devices have Insufficient Compartmentalization between a host network and a guest network that are e
TP-Link Archer C3200 V1 and Archer C2 V1 devices have Insufficient Compartmentalization between a host network and a gue
TP-Link Archer C3200 V1 and Archer C2 V1 devices have Insufficient Compartmentalization between a host network and a gue
TP-Link Archer C3200 V1 and Archer C2 V1 devices have Insufficient Compartmentalization between a host network and a gue
Edimax BR-6208AC V1 devices have Insufficient Compartmentalization between a host network and a guest network that are e
Edimax BR-6208AC V1 devices have Insufficient Compartmentalization between a host network and a guest network that are e
components/Modals/HelpModal.jsx in BloodHound 2.2.0 allows remote attackers to execute arbitrary OS commands (by spawnin
Jenkins 2.191 and earlier, LTS 2.176.2 and earlier allowed users to obtain CSRF tokens without an associated web session
A sandbox bypass vulnerability in Jenkins Splunk Plugin 1.7.4 and earlier allowed attackers with Overall/Read permission
In Knowage through 6.1.1, an authenticated user who accesses the datasources page will gain access to any data source cr
MyT Project Management 1.5.1 lacks CSRF protection and, for example, allows a user/create CSRF attack. This could lead t
The handl-utm-grabber plugin before 2.6.5 for WordPress has CSRF via add_option and update_option.
The woo-address-book plugin before 1.6.0 for WordPress has save calls without nonce verification checks.
The Eques elf smart plug and the mobile app use a hardcoded AES 256 bit key to encrypt the commands and responses betwee
The insta-gallery plugin before 2.4.8 for WordPress has no nonce validation for qligg_dismiss_notice or qligg_form_item_
The facebook-by-weblizar plugin before 2.8.5 for WordPress has CSRF.
There was a local file disclosure vulnerability in Confluence Server and Confluence Data Center via page exporting. An a
Datalogic AV7000 Linear barcode scanner all versions prior to 4.6.0.0 is vulnerable to authentication bypass, which may
The photo-gallery plugin before 1.2.42 for WordPress has CSRF.
The one-click-ssl plugin before 1.4.7 for WordPress has CSRF.
The visitors-traffic-real-time-statistics plugin before 1.12 for WordPress has CSRF in the settings page.
The visitors-traffic-real-time-statistics plugin before 1.13 for WordPress has CSRF.
The webp-converter-for-media plugin before 1.0.3 for WordPress has CSRF.
The wp-better-permalinks plugin before 3.0.5 for WordPress has CSRF.
Scan for 2019 Vulnerabilities
CyberStrike detects these CVEs across your infrastructure automatically.
Get Started