17,305 vulnerabilities published in 2019
SITOS six Build v6.2.1 allows a user to change their password and recovery email address without requiring them to confi
The orbisius-child-theme-creator plugin before 1.2.8 for WordPress has incorrect access control for file modification vi
An issue was discovered in drivers/xen/balloon.c in the Linux kernel before 5.2.3, as used in Xen through 4.12.x, allowi
An issue was discovered in Xen through 4.11.x allowing x86 PV guest OS users to cause a denial of service by leveraging
An issue was discovered in Xen 4.8.x through 4.11.x allowing x86 PV guest OS users to cause a denial of service because
An issue was discovered in Xen through 4.11.x allowing x86 PV guest OS users to cause a denial of service because of an
In Centreon Web through 2.8.29, disclosure of external components' passwords allows authenticated attackers to move late
Due to missing input validation, SAP Financial Consolidation, before versions 10.0 and 10.1, enables an attacker to use
OTCMS v3.85 has CSRF in the admin/member_deal.php Admin Panel page, leading to creation of a new management group accoun
gif2png 2.5.13 has a memory leak in the writefile function.
Exiv2 0.27.2 allows attackers to trigger a crash in Exiv2::getULong in types.cpp when called from Exiv2::Internal::CiffD
SSL-Proxy feature on SRX devices fails to handle a hardware resource limitation which can be exploited by remote SSL/TLS
When an MX Series Broadband Remote Access Server (BRAS) is configured as a Broadband Network Gateway (BNG) with DHCPv6 e
Receipt of a specific link-local IPv6 packet destined to the RE may cause the system to crash and restart (vmcore). By c
The SRX flowd process, responsible for packet forwarding, may crash and restart when processing specific multicast packe
Koji through 1.18.0 allows remote Directory Traversal, with resultant Privilege Escalation.
An issue was discovered in fastadmin 1.0.0.20190705_beta. There is a public/admin/general.config/edit CSRF vulnerability
A vulnerability has been identified in SIMATIC IT UADM (All versions < V1.3). An authenticated remote attacker with netw
An information disclosure vulnerability exists in Microsoft SQL Server Management Studio (SSMS) when it improperly enfor
An elevation of privilege vulnerability exists in Microsoft SharePoint, aka 'Microsoft SharePoint Elevation of Privilege
A denial of service vulnerability exists when Windows improperly handles objects in memory, aka 'Windows Denial of Servi
A denial of service vulnerability exists when Windows improperly handles objects in memory, aka 'Windows Denial of Servi
A denial of service vulnerability exists when Windows improperly handles objects in memory, aka 'Windows Denial of Servi
An information disclosure vulnerability exists when Microsoft Edge based on Edge HTML improperly handles objects in memo
An information disclosure vulnerability exists in Microsoft SQL Server Management Studio (SSMS) when it improperly enfor
find_abstract_instance in dwarf2.c in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binut
An issue was discovered in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.32. I
Bento4 1.5.1.0 has a NULL pointer dereference in AP4_DescriptorListInspector::Action in Core/Ap4Descriptor.h, related to
Bento4 1.5.1.0 has a NULL pointer dereference in AP4_DescriptorListWriter::Action in Core/Ap4Descriptor.h, related to AP
Bento4 1.5.1.0 has a NULL pointer dereference in AP4_Descriptor::GetTag in Core/Ap4Descriptor.h, related to AP4_StsdAtom
Tracker PDF-XChange Editor before 8.0.330.0 has an NTLM SSO hash theft vulnerability using crafted FDF or XFDF files (a
An issue was discovered in Landing-CMS 0.0.6. There is a CSRF vulnerability that can change the admin's password via the
The Infinite Design application 3.4.12 for Android sends a username and password via TCP without any encryption during l
NETGEAR JNR1010 devices before 1.0.0.32 allow cgi-bin/webproc CSRF via the :InternetGatewayDevice.X_TWSZ-COM_URL_Filter.
The Yale Bluetooth Key application for mobile devices allows unauthorized unlock actions by sniffing Bluetooth Low Energ
An arbitrary file read vulnerability in Jenkins Google OAuth Credentials Plugin 0.9 and earlier allowed attackers able t
A missing permission check in Jenkins CRX Content Package Deployer Plugin 1.8.1 and earlier allowed attackers with Overa
Jenkins Bumblebee HP ALM Plugin 4.1.3 and earlier unconditionally disabled SSL/TLS and hostname verification for connect
Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Security: Encryption). Supported versions
Vulnerability in the Oracle Data Integrator product of Oracle Fusion Middleware (component: Studio). The supported versi
Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: PS). Supported versions that are affected
Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported versions that are af
Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported versions that are af
Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported versions that are af
Vulnerability in the Oracle FLEXCUBE Direct Banking product of Oracle Financial Services Applications (component: eMail)
Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Parser). Supported versions that are affec
Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: C API). Supported versions that are affect
Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). Supported versions that ar
Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). Supported versions that ar
A packet containing a malformed DUID can cause the Kea DHCPv6 server process (kea-dhcp6) to exit due to an assertion fai
Scan for 2019 Vulnerabilities
CyberStrike detects these CVEs across your infrastructure automatically.
Get Started