17,305 vulnerabilities published in 2019
The pie-register plugin before 3.1.2 for WordPress has SQL injection, a different issue than CVE-2018-10969.
The feed-them-social plugin before 1.7.0 for WordPress has possible shortcode execution in the Facebook Feeds load more
The wp-polls plugin before 2.72 for WordPress has SQL injection.
A SQL injection vulnerability exists in the Imagely NextGEN Gallery plugin before 3.2.11 for WordPress. Successful explo
In Xymon through 4.3.28, a buffer overflow vulnerability exists in the csvinfo CGI script. The overflow may be exploited
In Xymon through 4.3.28, a buffer overflow vulnerability exists in history.c.
In Xymon through 4.3.28, a buffer overflow vulnerability exists in reportlog.c.
In Xymon through 4.3.28, a stack-based buffer overflow vulnerability exists in the alert acknowledgment CGI tool because
In Xymon through 4.3.28, a buffer overflow exists in the status-log viewer CGI because of expansion in appfeed.c.
In Xymon through 4.3.28, a stack-based buffer overflow vulnerability exists in the history viewer component via a long h
In Xymon through 4.3.28, a stack-based buffer overflow exists in the status-log viewer component because of expan
The sharebar plugin before 1.2.2 for WordPress has SQL injection.
An issue was discovered in Gallagher Command Centre 8.10 before 8.10.1092(MR2). Upon an upgrade, if a custom service acc
Various Lexmark products have an Integer Overflow.
Various Lexmark products have a Buffer Overflow (issue 2 of 3).
Various Lexmark products have a Buffer Overflow (issue 3 of 3).
A vulnerability of remote credential disclosure was discovered in Advan VD-1 firmware versions up to 230. An attacker ca
A broken access control vulnerability found in Advan VD-1 firmware version 230 leads to insecure ADB service. An attacke
The woo-confirmation-email plugin before 3.2.0 for WordPress has no blocking of direct access to supportive xl folders i
An issue was discovered in GitLab Community and Enterprise Edition 12.0 through 12.1.4. It uses Hard-coded Credentials.
The formidable plugin before 4.02.01 for WordPress has unsafe deserialization.
Lute-Tab before 2019-08-23 has a buffer overflow in pdf_print.cc.
Secure Reliable Transport (SRT) through 1.3.4 has a CSndUList array overflow if there are many SRT connections.
FontForge 20190813 through 20190820 has a buffer overflow in PrefsUI_LoadPrefs in prefs.c.
ROBOTIS Dynamixel SDK through 3.7.11 has a buffer overflow via a large rxpacket.
Clara Genomics Analysis before 0.2.0 has an integer overflow for cudapoa memory management in allocate_block.cpp.
In Dovecot before 2.2.36.4 and 2.3.x before 2.3.7.2 (and Pigeonhole before 0.5.7.2), protocol processing can fail for qu
Irssi 1.2.x before 1.2.2 has a use-after-free if the IRC server sends a double CAP.
CommScope ARRIS TR4400 devices with firmware through A1.00.004-180301 are vulnerable to an authentication bypass to the
CommScope ARRIS TR4400 devices with firmware through A1.00.004-180301 are vulnerable to an authentication bypass to the
In FreeBSD 12.0-STABLE before r350648, 12.0-RELEASE before 12.0-RELEASE-p9, 11.3-STABLE before r350650, 11.3-RELEASE bef
The nd-restaurant-reservations plugin before 1.5 for WordPress has no requirement for nd_rst_import_settings_php_functio
The wps-child-theme-generator plugin before 1.2 for WordPress has classes/helpers.php directory traversal.
The wps-hide-login plugin before 1.5.3 for WordPress has an action=confirmaction protection bypass.
The wps-hide-login plugin before 1.5.3 for WordPress has an adminhash protection bypass.
The wps-hide-login plugin before 1.5.3 for WordPress has an action=rp&key&login protection bypass.
The wps-hide-login plugin before 1.5.3 for WordPress has a protection bypass via wp-login.php in the Referer field.
The LoginPress plugin before 1.1.4 for WordPress has SQL injection via an import of settings.
AsusPTPFilter.sys on Asus Precision TouchPad 11.0.0.25 hardware has a Pool Overflow associated with the \\.\AsusTP devic
eGain Chat 15.0.3 allows unrestricted file upload.
A vulnerability in the “plug-and-play” services component of Cisco Industrial Network Director (IND) could a
Pengutronix barebox through 2019.08.1 has a remote buffer overflow in nfs_readlink_reply in net/nfs.c because a length f
Pengutronix barebox through 2019.08.1 has a remote buffer overflow in nfs_readlink_req in fs/nfs.c because a length fiel
Controller/ListController.php in Eventum 3.5.0 is vulnerable to Deserialization of Untrusted Data. Fixed in version 3.5.
The Rich Text Formatter (Redactor) extension through v1.1.1 for Symphony CMS has an Unauthenticated arbitrary file uploa
In Knowage through 6.1.1, an unauthenticated user can bypass access controls and access the entire application.
An issue was discovered in Alfresco Community Edition versions 6.0 and lower. An unauthenticated, remote attacker could
Exim before 4.92.2 allows remote attackers to execute arbitrary code as root via a trailing backslash.
A flaw was found in ghostscript, versions 9.x before 9.50, in the setsystemparams procedure where it did not properly se
An access vulnerability in CA Common Services DIA of CA Technologies Client Automation 14 and Workload Automation AE 11.
Scan for 2019 Vulnerabilities
CyberStrike detects these CVEs across your infrastructure automatically.
Get Started