17,305 vulnerabilities published in 2019
Insufficient access control in Intel(R) Baseboard Management Controller firmware may allow an unauthenticated user to po
An issue was discovered in the rack-cors (aka Rack CORS Middleware) gem before 1.0.4 for Ruby. It allows ../ directory t
An issue was discovered in the AbuseFilter extension through 1.34 for MediaWiki. Once a specific abuse filter has (accid
permission and access control vulnerability, which exists in V2.1.14 and below versions of C520V21 smart camera devices.
When updating a Process Group via the API in NiFi versions 1.3.0 to 1.9.2, the response to the request includes all of i
9base 1:6-6 and 1:6-7 insecurely creates temporary files which results in predictable filenames.
An issue was discovered in Symfony 4.2.0 to 4.2.11 and 4.3.0 to 4.3.7. The ability to enumerate users was possible due t
When a Beckhoff TwinCAT Runtime receives a malformed UDP packet, the ADS Discovery Service shuts down. Note that the Twi
IBM Tivoli Netcool Impact 7.1.0 through 7.1.0.16 generates an error message that includes sensitive information about it
The Mijosoft MijoSearch component 2.0.1 and earlier for Joomla! allows remote attackers to obtain sensitive information
Embedthis GoAhead before 5.0.1 mishandles redirected HTTP requests with a large Host header. The GoAhead WebsRedirect us
Authentication Bypass vulnerability in the Microsoft Windows client in McAfee Client Proxy (MCP) prior to 3.0.0 allows l
UI spoofing in Chromium in Google Chrome prior to 77.0.3865.75 allowed a remote attacker to spoof notifications via a cr
Inappropriate implementation in TLS in Google Chrome prior to 77.0.3865.75 allowed a remote attacker to spoof client IP
Inappropriate implementation in JavaScript in Google Chrome prior to 72.0.3626.81 allowed a remote attacker to leak cros
Insufficient policy enforcement in JavaScript in Google Chrome prior to 78.0.3904.70 allowed a remote attacker to leak c
Nokia IMPACT < 18A has path traversal that may lead to RCE if chained with CVE-2019-1743
Various methods in WEBrick::HTTPRequest in Ruby 1.9.2 and 1.8.7 and earlier do not validate the X-Forwarded-For, X-Forwa
A vulnerability in web interface of the Cisco Webex Event Center, Cisco Webex Meeting Center, Cisco Webex Support Center
A vulnerability in the antispam protection mechanisms of Cisco AsyncOS Software for Cisco Email Security Appliance (ESA)
A vulnerability in the web-based management interface of certain Cisco Small Business RV Series Routers could allow an u
A vulnerability in the access-control logic of the NETCONF over Secure Shell (SSH) of Cisco IOS XR Software may allow co
A vulnerability in the loading mechanism of specific dynamic link libraries in Cisco Webex Teams for Windows could allow
An issue was discovered in GitLab Community and Enterprise Edition 11.3 to 12.3 in the protected environments feature. I
An issue was discovered in GitLab Community and Enterprise Edition 11.3 through 12.4 when moving an issue to a public pr
An issue was discovered in GitLab Community and Enterprise Edition 8.17 through 12.4 in the Search feature provided by E
An issue was discovered in Squid 3.x and 4.x through 4.8. It allows attackers to smuggle HTTP requests through frontend
Ruby through 2.4.7, 2.5.x through 2.5.6, and 2.6.x through 2.6.4 allows HTTP Response Splitting. If a program using WEBr
dirmngr before 2.1.0 improperly handles certain system calls, which allows remote attackers to cause a denial of service
PackageKit 0.6.17 allows installation of unsigned RPM packages as though they were signed which may allow installation o
In Octopus Deploy before 2019.10.7, in a configuration where SSL offloading is enabled, the CSRF cookie was sometimes se
In app/Controller/TagsController.php in MISP 2.4.118, users can bypass intended restrictions on tagging data.
cabextract before 1.6 does not properly check for leading slashes when extracting files, which allows remote attackers t
The Anhui Huami Mi Fit application before 4.0.11 for Android has an Unencrypted Update Check.
The CBC Gem application before 9.24.1 for Android and before 9.26.0 for iOS has Unencrypted Analytics.
Anviz access control devices expose private Information (pin code and name) by allowing remote attackers to query this i
In jpv (aka Json Pattern Validator) before 2.1.1, compareCommon() can be bypassed because certain internal attributes ca
A vulnerability exists in libgwenhywfar through 4.12.0 due to the usage of outdated bundled CA certificates.
Improper Check for filenames with overly long extensions in PostMaster (sending in email) or uploading files (e.g. attac
A Security Bypass vulnerability exists in the phpCAS 1.2.2 library from the jasig project due to the way proxying of ser
In Puma before versions 3.12.2 and 4.3.1, a poorly-behaved client could use keepalive requests to monopolize Puma's reac
SROS 2 0.8.1 (which provides the tools that generate and distribute keys for Robot Operating System 2 and uses the under
SROS 2 0.8.1 (after CVE-2019-19625 is mitigated) leaks ROS 2 node-related information regardless of the rtps_protection_
There is an overflow bug in the x64_64 Montgomery squaring procedure used in exponentiation with 512-bit moduli. No EC a
The Last.fm desktop app (Last.fm Scrobbler) through 2.1.39 on macOS makes HTTP requests that include an API key without
All Samba versions 4.x.x before 4.9.17, 4.10.x before 4.10.11 and 4.11.x before 4.11.3 have an issue, where the (poorly
Foreman has improper input validation which could lead to partial Denial of Service
wolfSSL and wolfCrypt 4.1.0 and earlier (formerly known as CyaSSL) generate biased DSA nonces. This allows a remote atta
A vulnerability has been identified in Desigo PX automation controllers PXC00-E.D, PXC50-E.D, PXC100-E.D, PXC200-E.D wit
A vulnerability has been identified in EN100 Ethernet module DNP3 variant (All versions), EN100 Ethernet module IEC 6185
Scan for 2019 Vulnerabilities
CyberStrike detects these CVEs across your infrastructure automatically.
Get Started