17,305 vulnerabilities published in 2019
A vulnerability has been identified in SPPA-T3000 Application Server (All versions < Service Pack R8.2 SP2). The Applica
A vulnerability has been identified in SPPA-T3000 Application Server (All versions < Service Pack R8.2 SP2). The Applica
A vulnerability has been identified in SPPA-T3000 MS3000 Migration Server (All versions). An attacker with network acces
A vulnerability has been identified in SPPA-T3000 Application Server (All versions < Service Pack R8.2 SP2). An attacker
A vulnerability has been identified in SPPA-T3000 Application Server (All versions < Service Pack R8.2 SP2). An attacker
A vulnerability has been identified in SPPA-T3000 Application Server (All versions < Service Pack R8.2 SP2). An attacker
A vulnerability has been identified in SPPA-T3000 Application Server (All versions < Service Pack R8.2 SP2). An attacker
A vulnerability has been identified in SPPA-T3000 Application Server (All versions < Service Pack R8.2 SP2). An attacker
A vulnerability has been identified in Control Center Server (CCS) (All versions < V1.5.0). The SFTP service (default po
In Dovecot before 2.3.9.2, an attacker can crash a push-notification driver with a crafted email when push notifications
Some Huawei smart phones have a null pointer dereference vulnerability. An attacker crafts specific packets and sends to
Barco ClickShare Button R9861500D01 devices before 1.9.0 allow Information Exposure. The encrypted ClickShare Button fir
Improper conditions check in multiple Intel® Processors may allow an authenticated user to potentially enable partial es
In Apache Incubator Superset before 0.31 user could query database metadata information from a database he has no access
In Apache Incubator Superset before 0.32, a user can view database names that he has no access to on a dropdown list in
Contao 4.0 through 4.8.5 has Insecure Permissions. Back end users can manipulate the details view URL to show pages and
Jenkins SCTMExecutor Plugin 2.2 and earlier transmits previously configured service credentials in plain text as part of
Contao 4.8.4 and 4.8.5 has Improper Encoding or Escaping of Output. It is possible to inject insert tags into the login
In Joomla! before 3.9.14, a missing access check in framework files could lead to a path disclosure.
This issue was addressed with improved checks. This issue is fixed in iOS 12.4, macOS Mojave 10.14.6. A remote attacker
An inconsistent user interface issue was addressed with improved state management. This issue is fixed in macOS Mojave 1
A logic issue existed with the display of notification previews. This issue was addressed with improved validation. This
The issue was addressed with improved handling of service worker lifetime. This issue is fixed in Safari 13.0.1. Service
"Clear History and Website Data" did not clear the history. The issue was addressed with improved data deletion. This is
An exploitable information exposure vulnerability exists in the iocheckd service "I/O-Check" functionality of WAGO PFC20
An improper access control vulnerability exists in Gitlab EE <v12.3.3, <v12.2.7, & <v12.1.13 that allowed the group sear
A flaw was found in Ansible Tower, versions 3.6.x before 3.6.2 and 3.5.x before 3.5.4, when /websocket is requested and
On BIG-IP versions 15.0.0-15.0.1, 14.1.0-14.1.2.2, 14.0.0-14.0.1, and 13.1.0-13.1.3.1, the TMM process may restart when
On BIG-IP versions 15.0.0-15.0.1.1, 14.1.0-14.1.2, 14.0.0-14.0.1, 13.1.0-13.1.3.1, the Traffic Management Microkernel (T
All versions up to V4.01.01.02 of ZTE ZXCLOUD GoldenData VAP product have a file reading vulnerability. Attackers could
SQLite 3.30.1 mishandles certain parser-tree rewriting, related to expr.c, vdbeaux.c, and window.c. This is caused by in
In wolfSSL before 4.3.0, wc_ecc_mulmod_ex does not properly resist side-channel attacks.
An issue was discovered in wolfSSL before 4.3.0 in a non-default configuration where DSA is enabled. DSA signing uses th
The WordPress plugin, Email Subscribers & Newsletters, before 4.2.3 had a flaw that allowed for unauthenticated option c
The WordPress plugin, Email Subscribers & Newsletters, before 4.2.3 had a flaw that allowed unauthenticated file downloa
REMISE Payment Module (2.11, 2.12 and 2.13) version 3.0.12 and earlier allow remote attackers to [Disclosed_Information_
An issue was discovered in GitLab Community and Enterprise Edition before 11.4.13, 11.5.x before 11.5.6, and 11.6.x befo
Karotz API 12.07.19.00: Session Token Information Disclosure
IBM Watson Studio Local 1.2.3 could disclose sensitive information over the network that an attacked could use in furthe
_account_forgot_password.ajax.php in MFScripts YetiShare 3.5.2 through 4.5.3 takes a different amount of time to return
_account_forgot_password.ajax.php in MFScripts YetiShare 3.5.2 through 4.5.3 displays a message indicating whether an em
An issue was discovered in GitLab Community and Enterprise Edition before 11.4.13, 11.5.x before 11.5.6, and 11.6.x befo
An issue was discovered in GitLab Community and Enterprise Edition 11.3.x and 11.4.x before 11.4.13, 11.5.x before 11.5.
An issue was discovered in GitLab Enterprise Edition 11.2.x through 11.4.x before 11.4.13, 11.5.x before 11.5.6, and 11.
A vulnerability was found in sssd. If a user was configured with no home directory set, sssd would return '/' (the root
The Ubuntu SELinux initscript before version 1:0.10 used touch to create a lockfile in a world-writable directory. If th
NETGEAR EX7000 V1.0.0.42_1.0.94 devices allow XSS via the SSID.
IBM Cloud Automation Manager 3.1.2 could allow a malicious user on the client side (with access to client computer) to r
A vulnerability in the web-based management interface of Cisco SPA122 ATA with Router Devices could allow an unauthentic
For the printers listed a maliciously crafted print file might cause certain HP Inkjet printers to assert. Under certain
Scan for 2019 Vulnerabilities
CyberStrike detects these CVEs across your infrastructure automatically.
Get Started