17,305 vulnerabilities published in 2019
A use-after-free flaw was found in pacemaker up to and including version 2.0.1 which could result in certain sensitive i
Vulnerability in the Oracle Solaris component of Oracle Sun Systems Products Suite (subcomponent: File Locking Services)
Vulnerability in the Data Store component of Oracle Berkeley DB. Supported versions that are affected are Prior to 6.138
IBM TRIRIGA Application Platform 3.5.3 and 3.6.0 may disclose sensitive information only available to a local user that
The do_hidp_sock_ioctl function in net/bluetooth/hidp/sock.c in the Linux kernel before 5.0.15 allows a local user to ob
IBM BigFix Platform 9.2 and 9.5 stores potentially sensitive information in process memory that could be read by a local
A deserialization vulnerability exists in the way parso through 0.4.0 handles grammar parsing from the cache. Cache load
IBM Security Information Queue (ISIQ) 1.0.0, 1.0.1, and 1.0.2 discloses sensitive information to unauthorized users. The
IBM Security Information Queue (ISIQ) 1.0.0, 1.0.1, and 1.0.2 allows web pages to be stored locally which can be read by
Logic condition in specific microprocessors may allow an authenticated user to potentially enable partial physical addre
Insufficient password protection in the attestation database for Open CIT may allow an authenticated user to potentially
Insufficient password protection in the attestation database for Open CIT may allow an authenticated user to potentially
IBM Cognos Controller 10.2.0, 10.2.1, 10.3.0, 10.3.1, and 10.4.0 allows web pages to be stored locally which can be read
IBM Cognos Controller 10.2.0, 10.2.1, 10.3.0, 10.3.1, and 10.4.0 allows web pages to be stored locally which can be read
IBM Robotic Process Automation with Automation Anywhere 11 information disclosure could allow a local user to obtain e-m
Content Injection vulnerability in Tenable Nessus prior to 8.5.0 may allow an authenticated, local attacker to exploit t
Info-ZIP UnZip 6.0 mishandles the overlapping of files inside a ZIP container, leading to denial of service (resource co
IBM QRadar SIEM 7.2 and 7.3 could allow a local user to obtain sensitive information when exporting content that could a
tcpdump.org tcpdump 4.9.2 is affected by: CWE-126: Buffer Over-read. The impact is: May expose Saved Frame Pointer, Retu
IDRIX, Truecrypt Veracrypt, Truecrypt Prior to 1.23-Hotfix-1 (Veracrypt), all versions (Truecrypt) is affected by: Buffe
Vulnerability in the Oracle VM VirtualBox component of Oracle Virtualization (subcomponent: Core). Supported versions th
Vulnerability in the Oracle VM VirtualBox component of Oracle Virtualization (subcomponent: Core). Supported versions th
Vulnerability in the Oracle VM VirtualBox component of Oracle Virtualization (subcomponent: Core). Supported versions th
Vulnerability in the Oracle VM VirtualBox component of Oracle Virtualization (subcomponent: Core). Supported versions th
An issue was discovered in the Linux kernel before 4.18.7. In create_qp_common in drivers/infiniband/hw/mlx5/qp.c, mlx5_
cPanel before 82.0.2 does not properly enforce Reseller package creation ACLs (SEC-514).
cPanel before 80.0.5 uses world-readable permissions for the Queueprocd log (SEC-494).
API Analytics adminbin in cPanel before 80.0.5 allows spoofed insertions of log data (SEC-495).
cPanel before 78.0.18 unsafely determines terminal capabilities by using infocmp (SEC-481).
Maketext in cPanel before 78.0.2 allows format-string injection in the Email store_filter UAPI (SEC-472).
Maketext in cPanel before 78.0.2 allows format-string injection in the DCV check_domains_via_dns UAPI (SEC-474).
In cPanel before 78.0.2, a Userdata cache temporary file can conflict with domains (SEC-478).
OpenSSL has internal defaults for a directory tree where it can find a configuration file as well as certificates used f
Jenkins Configuration as Code Plugin 1.24 and earlier did not properly apply masking to values expected to be hidden whe
cPanel before 74.0.8 allows local users to disable the ClamAV daemon (SEC-409).
cPanel before 74.0.8 mishandles account suspension because of an invalid email_accounts.json file (SEC-445).
cPanel before 74.0.0 makes web-site contents accessible to other local users via Git repositories (SEC-443).
cPanel before 68.0.27 allows attackers to read the SRS secret via exim.conf (SEC-308).
cPanel before 68.0.27 allows a user to discover contents of directories (that are not owned by that user) by leveraging
cPanel before 68.0.27 allows attackers to read root's crontab file during a short time interval upon the enabling of bac
cPanel before 68.0.27 allows attackers to read a copy of httpd.conf that is created during a syntax test (SEC-353).
cPanel before 68.0.27 allows attackers to read zone information because a world-readable archive is created by the archi
cPanel before 68.0.15 does not preserve permissions for local backup transport (SEC-330).
cPanel before 66.0.2 allows demo accounts to create databases and users (SEC-271).
In cPanel before 66.0.2, EasyApache 4 conversion sets weak domlog ownership and permissions (SEC-272).
In cPanel before 66.0.2, domain log files become readable after log processing (SEC-273).
In cPanel before 66.0.2, the Apache HTTP Server configuration file is changed to world-readable when rebuilt (SEC-274).
In cPanel before 66.0.2, weak log-file permissions can occur after account modification (SEC-289).
In cPanel before 66.0.2, Apache HTTP Server SSL domain logs can persist on disk after an account termination (SEC-291).
cPanel before 62.0.17 allows file overwrite when renaming an account (SEC-219).
Scan for 2019 Vulnerabilities
CyberStrike detects these CVEs across your infrastructure automatically.
Get Started