17,305 vulnerabilities published in 2019
The facebook-for-woocommerce plugin before 1.9.14 for WordPress has CSRF.
The facebook-for-woocommerce plugin before 1.9.15 for WordPress has CSRF via ajax_woo_infobanner_post_click, ajax_woo_in
FreeType before 2.6.1 has a heap-based buffer over-read in T1_Get_Private_Dict in type1/t1parse.c.
admin/includes/class.import.snippet.php in the "Woody ad snippets" plugin before 2.2.5 for WordPress allows unauthentica
The breadcrumbs-by-menu plugin before 1.0.3 for WordPress has CSRF.
The crelly-slider plugin before 1.3.5 for WordPress has arbitrary file upload via a PHP file inside a ZIP archive to wp_
The slick-popup plugin before 1.7.2 for WordPress has a hardcoded OmakPass13# password for the slickpopupteam account, a
The affiliates-manager plugin before 2.6.6 for WordPress has CSRF.
The profilegrid-user-profiles-groups-and-communities plugin before 2.8.6 for WordPress has remote code execution via an
The Nexus Yum Repository Plugin in v2 is vulnerable to Remote Code Execution when instances using CommandLineExecutor.ja
Multiple file upload restriction bypass vulnerabilities in Sentrifugo 3.2 could allow authenticated users to execute arb
On BIG-IP 11.5.2-11.6.4 and Enterprise Manager 3.1.1, REST users with guest privileges may be able to escalate their pri
A vulnerability in the Cisco Webex Teams client for Windows could allow an unauthenticated, remote attacker to execute a
Poppler before 0.66.0 has an integer overflow in Parser::makeStream in Parser.cc.
OpenJPEG before 2.3.1 has a heap buffer overflow in color_apply_icc_profile in bin/common/color.c.
FFmpeg through 4.2 has a "Conditional jump or move depends on uninitialised value" issue in h2645_parse because alloc_rb
Nagios XI before 5.6.6 allows remote command execution as root. The exploit requires access to the server as the nagios
A code execution vulnerability exists in Epignosis eFront LMS v5.2.12. A specially crafted web request can cause unsafe
An issue was discovered in Total.js CMS 12.0.0. An authenticated user with the Pages privilege can conduct a path traver
An issue was discovered in Total.js CMS 12.0.0. An authenticated user with limited privileges can get access to a resour
FusionPBX 4.4.8 allows an attacker to execute arbitrary system commands by submitting a malicious command to the service
In isPreferred of HidProfile.java in Android 7.1.1, 7.1.2, 8.0, 8.1 and 9, there is a possible device type confusion due
In Pyxis ES Versions 1.3.4 through to 1.6.1 and Pyxis Enterprise Server, with Windows Server Versions 4.4 through 4.12,
An exploitable authentication bypass vulnerability exists in the Bluetooth Low Energy (BLE) authentication module of YI
Sentrifugo 3.2 lacks CSRF protection. This could lead to an attacker tricking the administrator into executing arbitrary
Silver Peak EdgeConnect SD-WAN before 8.1.7.x allows CSRF via JSON data to a .swf file.
Bludit 3.9.2 allows remote code execution via bl-kernel/ajax/upload-images.php because PHP code can be entered with a .j
CSV injection in the event-tickets (Event Tickets) plugin before 4.10.7.2 for WordPress exists via the "All Post> Ticket
framework/admin/modulec_control.php in OKLite v1.2.25 has an Arbitrary File Upload Vulnerability because a .php file fro
An issue was discovered in LibreNMS through 1.47. It does not parameterize all user supplied input within database queri
An issue was discovered in LibreNMS 1.50.1. The scripts that handle graphing options (includes/html/graphs/common.inc.ph
An issue was discovered in GitLab Community and Enterprise Edition before 11.5.8, 11.6.x before 11.6.6, and 11.7.x befor
An XML injection vulnerability was found in Limesurvey before 3.17.14 that allows remote attackers to import specially c
The elementor plugin before 1.8.0 for WordPress has incorrect access control for internal functions.
The jtrt-responsive-tables plugin before 4.1.2 for WordPress has SQL Injection via the admin/class-jtrt-responsive-table
The examapp plugin 1.0 for WordPress has SQL injection via the wp-admin/admin.php?page=examapp_UserResult id parameter.
The avada theme before 5.1.5 for WordPress has CSRF.
The RSA Identity Governance and Lifecycle software and RSA Via Lifecycle and Governance products prior to 7.1.0 P08 cont
A remote code execution vulnerability exists in the Windows Remote Desktop Client when a user connects to a malicious se
A remote code execution vulnerability exists in the Windows Remote Desktop Client when a user connects to a malicious se
A remote code execution vulnerability exists in Microsoft SharePoint when the software fails to check the source markup
A spoofing vulnerability exists in Microsoft SharePoint when it improperly handles requests to authorize applications, r
A spoofing vulnerability exists in Microsoft SharePoint when it improperly handles requests to authorize applications, r
A remote code execution vulnerability exists in the Windows Remote Desktop Client when a user connects to a malicious se
A remote code execution vulnerability exists in the Windows Remote Desktop Client when a user connects to a malicious se
A remote code execution vulnerability exists in Microsoft SharePoint where APIs aren't properly protected from unsafe da
A remote code execution vulnerability exists in Microsoft SharePoint where APIs aren't properly protected from unsafe da
A remote code execution vulnerability exists in Microsoft Excel software when the software fails to properly handle obje
An elevation of privilege vulnerability exists when a ASP.NET Core web application, created using vulnerable project tem
Jenkins Git Client Plugin 2.8.4 and earlier and 3.0.0-rc did not properly restrict values passed as URL argument to an i
Scan for 2019 Vulnerabilities
CyberStrike detects these CVEs across your infrastructure automatically.
Get Started