17,305 vulnerabilities published in 2019
The simple-login-log plugin before 1.1.2 for WordPress has SQL injection.
The contact-form-7 plugin before 5.0.4 for WordPress has privilege escalation because of capability_type mishandling in
The yikes-inc-easy-mailchimp-extender plugin before 6.5.3 for WordPress has code injection via the admin input field.
The memphis-documents-library plugin before 3.0 for WordPress has Remote File Inclusion.
The memphis-documents-library plugin before 3.0 for WordPress has Local File Inclusion.
The woocommerce-store-toolkit plugin before 1.5.7 for WordPress has privilege escalation.
The woocommerce-store-toolkit plugin before 1.5.8 for WordPress has privilege escalation.
The shortcodes-ultimate plugin before 5.0.1 for WordPress has remote code execution via a filter in a meta, post, or use
The post-pay-counter plugin before 2.731 for WordPress has PHP Object Injection.
The patreon-connect plugin before 1.2.2 for WordPress has Object Injection.
The wp-payeezy-pay plugin before 2.98 for WordPress has local file inclusion in pay.php, donate.php, donate-rec, and pay
The option-tree plugin before 2.7.0 for WordPress has Object Injection by leveraging a valid nonce.
The option-tree plugin before 2.7.3 for WordPress has Object Injection because the + character is mishandled.
The option-tree plugin before 2.7.3 for WordPress has Object Injection because serialized classes are mishandled.
The shortcode-factory plugin before 2.8 for WordPress has Local File Inclusion.
Mirasys VMS before V7.6.1 and 8.x before V8.3.2 mishandles the Mirasys.Common.Utils.Security.DataCrypt method in Common.
Mirasys VMS before V7.6.1 and 8.x before V8.3.2 mishandles the auto-update feature of IDVRUpdateService2 in DVRServer.ex
The wp-support-plus-responsive-ticket-system plugin before 4.2 for WordPress has SQL injection.
The wp-support-plus-responsive-ticket-system plugin before 4.2 for WordPress has incorrect authentication.
The wp-support-plus-responsive-ticket-system plugin before 7.1.0 for WordPress has insecure direct object reference via
The slidedeck2 plugin before 2.3.5 for WordPress has file inclusion.
The email-newsletter plugin through 20.15 for WordPress has SQL injection.
The newsletters-lite plugin before 4.6.8.6 for WordPress has PHP object injection.
drivers/net/wireless/rsi/rsi_91x_usb.c in the Linux kernel through 5.2.9 has a Double Free via crafted USB device traffi
drivers/media/usb/dvb-usb/technisat-usb2.c in the Linux kernel through 5.2.9 has an out-of-bounds read via crafted USB d
openITCOCKPIT before 3.7.1 allows code injection, aka RVID 1-445b21.
openITCOCKPIT before 3.7.1 allows SSRF, aka RVID 5-445b21.
Power-Response before 2019-02-02 allows directory traversal (up to the application's main directory) via a plugin.
mixin-deep is vulnerable to Prototype Pollution in versions before 1.3.2 and version 2.0.0. The function mixin-deep coul
set-value is vulnerable to Prototype Pollution in versions lower than 3.0.1. The function mixin-deep could be tricked in
deeply is vulnerable to Prototype Pollution in versions before 3.1.0. The function assign-deep could be tricked into add
Tasking Manager before 3.4.0 allows SQL Injection via custom SQL.
The Acclaim block plugin before 2019-06-26 for Moodle allows SQL Injection via delete_records.
The proxystatistics module before 3.1.0 for SimpleSAMLphp allows SQL Injection in lib/Auth/Process/DatabaseCommand.php.
Memory corruption in PAN-OS 7.1.24 and earlier, PAN-OS 8.0.19 and earlier, PAN-OS 8.1.9 and earlier, and PAN-OS 9.0.3 an
A remote code execution vulnerability in the PAN-OS SSH device management interface that can lead to unauthenticated rem
Use of Hard-coded Credentials vulnerability in FortiRecorder all versions below 2.7.4 may allow an unauthenticated attac
Lack of root file system integrity checking in Fortinet FortiManager VM application images of 6.2.0, 6.0.6 and below may
Raml-Module-Builder 26.4.0 allows SQL Injection in PostgresClient.update.
Spoon Library through 2014-02-06, as used in Fork CMS before 1.4.1 and other products, allows PHP object injection via a
CSZ CMS 1.2.3 allows arbitrary file upload, as demonstrated by a .php file to admin/filemanager in the File Management M
Pvanloon1983 social_network before 2019-07-03 allows SQL injection in includes/form_handlers/register_handler.php.
FlashLingo before 2019-06-12 allows SQL injection, related to flashlingo.js and db.js.
GORM before 1.9.10 allows SQL injection via incomplete parentheses. NOTE: Misusing Gorm by passing untrusted user input
Several Ricoh printers have multiple buffer overflows parsing LPD packets, which allow an attacker to cause a denial of
An issue was discovered in the smallvec crate before 0.6.3 for Rust. The Iterator implementation mishandles destructors,
An issue was discovered in the safe-transmute crate before 0.10.1 for Rust. A constructor's arguments are in the wrong o
Several Ricoh printers have multiple buffer overflows parsing HTTP cookie headers, which allow an attacker to cause a de
An issue was discovered in the smallvec crate before 0.6.10 for Rust. There is a double free for certain grow attempts w
An issue was discovered in the libflate crate before 0.1.25 for Rust. MultiDecoder::read has a use-after-free, leading t
Scan for 2019 Vulnerabilities
CyberStrike detects these CVEs across your infrastructure automatically.
Get Started