17,305 vulnerabilities published in 2019
LCDS Laquis SCADA prior to version 4.1.0.4150 allows out of bounds read when opening a specially crafted project file, w
A vulnerability in the Graphite interface of Cisco HyperFlex software could allow an authenticated, local attacker to wr
An issue was discovered in the Bosch Smart Camera App before 1.3.1 for Android. Due to setting of insecure permissions,
Insufficient access control in User Mode Driver in Intel(R) Graphics Driver for Windows* before versions 10.18.x.5059 (a
Unhandled exception in User Mode Driver in Intel(R) Graphics Driver for Windows* before versions 10.18.x.5059 (aka 15.33
Insufficient input validation in Kernel Mode Driver in Intel(R) Graphics Driver for Windows* before versions 10.18.x.505
Buffer leakage in igdkm64.sys in Intel(R) Graphics Driver for Windows* before versions 10.18.x.5059 (aka 15.33.x.5059),
hw/ppc/spapr.c in QEMU through 3.1.0 allows Information Exposure because the hypervisor shares the /proc/device-tree/sys
This issue was addressed with improved entitlements. This issue affected versions prior to iOS 12.
A consistency issue existed in the handling of application snapshots. The issue was addressed with improved handling of
This issue was addressed with improved entitlements. This issue affected versions prior to iOS 12.1.1.
A privacy issue in the handling of Open Directory records was addressed with improved indexing. This issue affected vers
In Lenovo systems, SMM BIOS Write Protection is used to prevent writes to SPI Flash. While this provides sufficient prot
A use-after-free flaw was found in pacemaker up to and including version 2.0.1 which could result in certain sensitive i
Vulnerability in the Oracle Solaris component of Oracle Sun Systems Products Suite (subcomponent: File Locking Services)
Vulnerability in the Data Store component of Oracle Berkeley DB. Supported versions that are affected are Prior to 6.138
IBM TRIRIGA Application Platform 3.5.3 and 3.6.0 may disclose sensitive information only available to a local user that
The do_hidp_sock_ioctl function in net/bluetooth/hidp/sock.c in the Linux kernel before 5.0.15 allows a local user to ob
IBM BigFix Platform 9.2 and 9.5 stores potentially sensitive information in process memory that could be read by a local
A deserialization vulnerability exists in the way parso through 0.4.0 handles grammar parsing from the cache. Cache load
IBM Security Information Queue (ISIQ) 1.0.0, 1.0.1, and 1.0.2 discloses sensitive information to unauthorized users. The
IBM Security Information Queue (ISIQ) 1.0.0, 1.0.1, and 1.0.2 allows web pages to be stored locally which can be read by
Logic condition in specific microprocessors may allow an authenticated user to potentially enable partial physical addre
Insufficient password protection in the attestation database for Open CIT may allow an authenticated user to potentially
Insufficient password protection in the attestation database for Open CIT may allow an authenticated user to potentially
IBM Cognos Controller 10.2.0, 10.2.1, 10.3.0, 10.3.1, and 10.4.0 allows web pages to be stored locally which can be read
IBM Cognos Controller 10.2.0, 10.2.1, 10.3.0, 10.3.1, and 10.4.0 allows web pages to be stored locally which can be read
IBM Robotic Process Automation with Automation Anywhere 11 information disclosure could allow a local user to obtain e-m
Content Injection vulnerability in Tenable Nessus prior to 8.5.0 may allow an authenticated, local attacker to exploit t
Info-ZIP UnZip 6.0 mishandles the overlapping of files inside a ZIP container, leading to denial of service (resource co
IBM QRadar SIEM 7.2 and 7.3 could allow a local user to obtain sensitive information when exporting content that could a
tcpdump.org tcpdump 4.9.2 is affected by: CWE-126: Buffer Over-read. The impact is: May expose Saved Frame Pointer, Retu
IDRIX, Truecrypt Veracrypt, Truecrypt Prior to 1.23-Hotfix-1 (Veracrypt), all versions (Truecrypt) is affected by: Buffe
Vulnerability in the Oracle VM VirtualBox component of Oracle Virtualization (subcomponent: Core). Supported versions th
Vulnerability in the Oracle VM VirtualBox component of Oracle Virtualization (subcomponent: Core). Supported versions th
Vulnerability in the Oracle VM VirtualBox component of Oracle Virtualization (subcomponent: Core). Supported versions th
Vulnerability in the Oracle VM VirtualBox component of Oracle Virtualization (subcomponent: Core). Supported versions th
An issue was discovered in the Linux kernel before 4.18.7. In create_qp_common in drivers/infiniband/hw/mlx5/qp.c, mlx5_
cPanel before 82.0.2 does not properly enforce Reseller package creation ACLs (SEC-514).
cPanel before 80.0.5 uses world-readable permissions for the Queueprocd log (SEC-494).
API Analytics adminbin in cPanel before 80.0.5 allows spoofed insertions of log data (SEC-495).
cPanel before 78.0.18 unsafely determines terminal capabilities by using infocmp (SEC-481).
Maketext in cPanel before 78.0.2 allows format-string injection in the Email store_filter UAPI (SEC-472).
Maketext in cPanel before 78.0.2 allows format-string injection in the DCV check_domains_via_dns UAPI (SEC-474).
In cPanel before 78.0.2, a Userdata cache temporary file can conflict with domains (SEC-478).
OpenSSL has internal defaults for a directory tree where it can find a configuration file as well as certificates used f
Jenkins Configuration as Code Plugin 1.24 and earlier did not properly apply masking to values expected to be hidden whe
cPanel before 74.0.8 allows local users to disable the ClamAV daemon (SEC-409).
cPanel before 74.0.8 mishandles account suspension because of an invalid email_accounts.json file (SEC-445).
cPanel before 74.0.0 makes web-site contents accessible to other local users via Git repositories (SEC-443).
Scan for 2019 Vulnerabilities
CyberStrike detects these CVEs across your infrastructure automatically.
Get Started