17,305 vulnerabilities published in 2019
A path disclosure vulnerability exists in Magento 2.1 prior to 2.1.18, Magento 2.2 prior to 2.2.9, Magento 2.3 prior to
A cryptograhic flaw in Magento 2.1 prior to 2.1.18, Magento 2.2 prior to 2.2.9, Magento 2.3 prior to 2.3.2 could be abus
An insecure direct object reference (IDOR) vulnerability exists in the RSS feeds of Magento 2.1 prior to 2.1.18, Magento
Samples of disabled downloadable products are accessible in Magento Open Source prior to 1.9.4.2, and Magento Commerce p
Names of disabled downloadable products could be disclosed due to inadequate validation of user input in Magento Open So
cPanel before 60.0.15 does not ensure that system accounts lack a valid password, so that logins are impossible (CPANEL-
Jenkins TestLink Plugin 3.16 and earlier stores credentials unencrypted in its global configuration file on the Jenkins
Wind River VxWorks 6.5, 6.6, 6.7, 6.8, 6.9.3 and 6.9.4 has a Memory Leak in the IGMPv3 client component. There is an IPN
Search Guard versions before 24.0 had an issue that field caps and mapping API leak field names (but not values) for fie
The login.jsp resource in Jira before version 7.13.4, and from version 8.0.0 before version 8.2.2 allows remote attacker
In Joomla! before 3.9.11, inadequate checks in com_contact could allow mail submission in disabled forms.
Under certain conditions, SAP BusinessObjects Business Intelligence Platform (BI Workspace), versions 4.1, 4.2, 4.3, all
During an OData V2/V4 request in SAP Gateway, versions 750, 751, 752, 753, the HTTP Header attributes cache-control and
The FV Flowplayer Video Player plugin before 7.3.15.727 for WordPress allows guests to obtain the email subscription lis
In ClickHouse before 18.12.13, functions for loading CatBoost models allowed path traversal and reading arbitrary files
Zabbix through 4.4.0alpha1 allows User Enumeration. With login requests, it is possible to enumerate application usernam
The Recruitment module in Humanica Humatrix 7 1.0.0.203 and 1.0.0.681 allows an unauthenticated attacker to access all c
An information leakage vulnerability in Iomega and LenovoEMC NAS products could allow disclosure of some device details
plugin/Audit/Objects/AuditTable.php in YouPHPTube through 7.2 allows SQL Injection.
IBM API Connect 2018.1 through 2018.4.1.6 may inadvertently leak sensitive details about internal servers and network vi
Adobe Acrobat and Reader versions 2019.012.20035 and earlier, 2019.012.20035 and earlier, 2017.011.30142 and earlier, 20
An exploitable information disclosure vulnerability exists in the Weave Legacy Pairing functionality of Nest Cam IQ Indo
The total-security plugin before 3.4.1 for WordPress has a settings-change vulnerability.
In CentOS-WebPanel.com (aka CWP) CentOS Web Panel 0.9.8.848, the Login process allows attackers to check whether a usern
AjaxDomainServlet in Zoho ManageEngine ServiceDesk Plus 10 allows User Enumeration. NOTE: the vendor's position is that
Leakage of stack traces in remote access to backup & restore in earlier versions than ProSyst mBS SDK 8.2.6 and Bosch Io
The wp-support-plus-responsive-ticket-system plugin before 4.2 for WordPress has full path disclosure.
The advanced-ajax-page-loader plugin before 2.7.7 for WordPress has no protection against the reading of uploaded files
The Privacy > Phone Number feature in the Telegram app 5.10 for Android and iOS provides an incorrect indication that th
Several worklog rest resources in Jira before version 7.13.7, and from version 8.0.0 before version 8.3.2 allow remote a
The /rest/issueNav/1/issueTable resource in Jira before version 8.3.2 allows remote attackers to enumerate usernames via
Swoole before 4.2.13 allows directory traversal in swPort_http_static_handler.
comelz Quark before 2019-03-26 allows directory traversal to locations outside of the project directory.
An information exposure vulnerability in FortiOS 6.2.3, 6.2.0 and below may allow an unauthenticated attacker to gain pl
An issue was discovered in the hyper crate before 0.9.18 for Rust. It mishandles newlines in headers.
An issue was discovered in the security-framework crate before 0.1.12 for Rust. Hostname verification for certificates d
cli/lib/main.js in Entropic before 2019-06-13 does not reject / and \ in command names, which might allow a directory tr
Various Lexmark products have Incorrect Access Control (issue 1 of 2).
Various Lexmark products have Incorrect Access Control (issue 2 of 2).
The legacy finger service (TCP port 79) is enabled by default on various older Lexmark devices.
/payu/icpcheckout/ in the WooCommerce PayU India Payment Gateway plugin 2.1.1 for WordPress allows Parameter Tampering i
cgi-bin/webscr?cmd=_cart in the WooCommerce PayPal Checkout Payment Gateway plugin 1.6.17 for WordPress allows Parameter
Log viewer in totemomail 6.0.0 build 570 allows access to sessionIDs of high privileged users by leveraging access to a
A vulnerability in the implementation of the Simple Network Management Protocol (SNMP) Access Control List (ACL) feature
Incorrect scoping of kill operations in MongoDB Server's packaged SysV init scripts allow users with write access to the
A path traversal vulnerability in <= v0.9.7 of statichttpserver npm module allows attackers to list files in arbitrary f
On BIG-IP 14.1.0-14.1.0.5, 14.0.0-14.0.0.4, 13.0.0-13.1.2, 12.1.0-12.1.4.1, 11.5.2-11.6.4, when processing authenticatio
In Knowage through 6.1.1, the sign up page does not invalidate a valid CAPTCHA token. This allows for CAPTCHA bypass in
An exploitable information disclosure vulnerability exists in the packet-parsing functionality of Blynk-Library v0.6.1.
In Knowage through 6.1.1, an unauthenticated user can enumerated valid usernames via the ChangePwdServlet page.
Scan for 2019 Vulnerabilities
CyberStrike detects these CVEs across your infrastructure automatically.
Get Started