17,305 vulnerabilities published in 2019
Buffer overflow in MiniShare 1.4.1 and earlier allows remote attackers to execute arbitrary code via a long HTTP HEAD re
Buffer overflow in MiniShare 1.4.1 and earlier allows remote attackers to execute arbitrary code via a long HTTP POST re
EPON CPE-WiFi devices 2.0.4-X000 are vulnerable to escalation of privileges by sending cooLogin=1, cooUser=admin, and ti
Zoho ManageEngine ADSelfService Plus 5.x before build 5701 has XXE via an uploaded product license.
Pluto Safety PLC Gateway Ethernet devices ABB GATE-E1 and GATE-E2 all versions do not allow authentication to be configu
An issue was discovered in weixin-java-tools v3.3.0. There is an XXE vulnerability in the getXmlDoc method of the BaseWx
Apache Karaf provides a features deployer, which allows users to "hot deploy" a features XML by dropping the file direct
includes/db/class.reflines_db.inc in FrontAccounting 2.4.6 contains a SQL Injection vulnerability in the reference field
SAP Cloud Connector, before version 2.11.3, does not perform any authentication checks for functionalities that require
SAP Cloud Connector, before version 2.11.3, allows an attacker to inject code that can be executed by the application. A
A memory corruption vulnerability exists in the Windows DHCP client when an attacker sends specially crafted DHCP respon
A remote code execution vulnerability exists in Microsoft Exchange software when the software fails to properly handle o
D-Link DIR-822 C1 before v3.11B01Beta, DIR-822-US C1 before v3.11B01Beta, DIR-850L A* before v1.21B08Beta, DIR-850L B* b
In Traccar Server version 4.2, protocol/SpotProtocolDecoder.java might allow XXE attacks.
Buffer overflow in the license management function of YOKOGAWA products (iDefine for ProSafe-RS R1.16.3 and earlier, STA
Buffer overflow in INplc-RT 3.08 and earlier allows remote attackers to cause denial-of-service (DoS) condition that may
INplc-RT 3.08 and earlier allows remote attackers to bypass authentication to execute an arbitrary command through the p
INplc-RT 3.08 and earlier allows remote attackers to bypass authentication to execute an arbitrary command through the p
LogonTracer 1.2.0 and earlier allows remote attackers to execute arbitrary OS commands via unspecified vectors.
LogonTracer 1.2.0 and earlier allows remote attackers to conduct Python code injection attacks via unspecified vectors.
RICOH Interactive Whiteboard D2200 V1.6 to V2.2, D5500 V1.6 to V2.2, D5510 V1.6 to V2.2, and the display versions with R
SQL injection vulnerability in the RICOH Interactive Whiteboard D2200 V1.3 to V2.2, D5500 V1.3 to V2.2, D5510 V1.3 to V2
PgpoolAdmin 4.0 and earlier allows remote attackers to bypass the login authentication and obtain the administrative pri
Irssi 1.1.x before 1.1.2 has a use after free when hidden lines are expired from the scroll buffer.
An issue was discovered in ShopXO 1.2.0. In the application\install\controller\Index.php file, there is no validation lo
Nelson Open Source ERP v6.3.1 allows SQL Injection via the db/utils/query/data.xml query parameter.
In CIMTechniques CIMScan 6.x through 6.2, the SOAP WSDL parser allows attackers to execute SQL code.
modulemd 1.3.1 and earlier uses an unsafe function for processing externally provided data, leading to remote code execu
In macOS High Sierra before 10.13.3, Security Update 2018-001 Sierra, and Security Update 2018-001 El Capitan, a logic e
In iCloud for Windows before 7.3, Safari before 11.0.3, iTunes before 12.7.3 for Windows, and iOS before 11.2.5, multipl
In macOS High Sierra before 10.13.3, Security Update 2018-001 Sierra, and Security Update 2018-001 El Capitan, an out-of
In iOS before 11.2.5, macOS High Sierra before 10.13.3, Security Update 2018-001 Sierra, and Security Update 2018-001 El
In macOS High Sierra before 10.13.5, an input validation issue existed in the kernel. This issue was addressed with impr
In macOS High Sierra before 10.13.5, a buffer overflow was addressed with improved size validation.
In macOS High Sierra before 10.13.5, a buffer overflow was addressed with improved bounds checking.
In SwiftNIO before 1.8.0, a buffer overflow was addressed with improved size validation.
In macOS High Sierra before 10.13.3, Security Update 2018-001 Sierra, and Security Update 2018-001 El Capitan, a permiss
An issue was discovered in SVG++ (aka svgpp) 1.2.3. After calling the gil::get_color function in Generic Image Library i
A Denial of Service issue was discovered in the LIVE555 Streaming Media libraries as used in Live555 Media Server 0.93.
An issue was discovered in idreamsoft iCMS V7.0.13. There is SQL Injection via the app/article/article.admincp.php _data
Cleanto 5.0 has SQL Injection via the assets/lib/service_method_ajax.php service_id parameter.
Cleanto 5.0 has SQL Injection via the assets/lib/export_ajax.php id parameter.
The DB abstraction layer of OXID eSales 4.10.6 is vulnerable to SQL injection via the oxid or synchoxid parameter to the
CubeCart before 6.1.13 has SQL Injection via the validate[] parameter of the "I forgot my Password!" feature.
In Pydio before 8.2.2, an attack is possible via PHP Object Injection because a user is allowed to use the $phpserial$a:
In versions of Drupal 8 core prior to 8.3.7; There is a vulnerability in the entity access system that could allow unwan
On EX2300 and EX3400 series, stateless firewall filter configuration that uses the action 'policer' in combination with
A certain crafted HTTP packet can trigger an uninitialized function pointer deference vulnerability in the Packet Forwar
The function number_format is vulnerable to a heap overflow issue when its second argument ($dec_points) is excessively
The implementations of streams for bz2 and php://output improperly implemented their readImpl functions, returning -1 co
Scan for 2019 Vulnerabilities
CyberStrike detects these CVEs across your infrastructure automatically.
Get Started