17,305 vulnerabilities published in 2019
The Libreswan Project has found a vulnerability in the processing of IKEv1 informational exchange packets which are encr
An issue was discovered in versions earlier than 1.3.2 for Polycom RealPresence Debut where the admin cookie is reset on
A flaw was found in Moodle before 3.7, 3.6.4, 3.5.6, 3.4.9 and 3.1.18. The form to upload cohorts contained a redirect f
Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server : Compiling). Supported versions that
Vulnerability in the Java SE, Java SE Embedded component of Oracle Java SE (subcomponent: Networking). Supported version
Vulnerability in the Java SE component of Oracle Java SE (subcomponent: Security). Supported versions that are affected
cPanel before 68.0.15 allows domain data to be deleted for domains with the .lock TLD (SEC-341).
Jenkins Aqua Security Serverless Scanner Plugin 1.0.4 and earlier transmitted configured passwords in plain text as part
Vulnerability in the Java SE, Java SE Embedded product of Oracle Java SE (component: Libraries). Supported versions that
Vulnerability in the Java SE, Java SE Embedded product of Oracle Java SE (component: Networking). Supported versions tha
A Username Enumeration via Error Message issue was discovered in NiceHash Miner before 2.0.3.0 because an "EMAIL DOES NO
In RHEV-M VDC 2.2.0, it was found that the SSL certificate was not verified when using the client-side Red Hat Enterpris
The serialize-to-js NPM package before version 3.0.1 is vulnerable to Cross-site Scripting (XSS). It does not properly m
Lobby Track Desktop could allow a local attacker to obtain sensitive information, caused by an error in Reports while in
Lobby Track Desktop could allow a local attacker to bypass security restrictions, caused by an error in the find visitor
EasyLobby Solo could allow a local attacker to obtain sensitive information, caused by the storing of the social securit
Envoy Passport for Android and Envoy Passport for iPhone could allow a local attacker to obtain sensitive information, c
Envoy Passport for Android and Envoy Passport for iPhone could allow a local attacker to obtain sensitive information, c
Supportutils, before version 3.1-5.7.1, wrote data to static file /tmp/supp_log, allowing local attackers to overwrite f
Vulnerability in the Oracle VM VirtualBox component of Oracle Virtualization (subcomponent: Core). Supported versions th
cPanel before 71.9980.37 allows arbitrary file-unlink operations via the cPAddons moderation system (SEC-395).
In Vanilla before 2.6.4, a flaw exists within the getSingleIndex function of the AddonManager class. The issue results i
IBM API Connect 5.0.0.0, and 5.0.8.6 could could return sensitive information that could provide critical information as
Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: Security: Privileges). Supported vers
Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: Security: Privileges). Supported vers
cPanel before 78.0.2 reveals internal data to OpenID providers (SEC-415).
It was found that the Apache ActiveMQ client before 5.14.5 exposed a remote shutdown command in the ActiveMQConnection c
cPanel before 70.0.23 exposes Apache HTTP Server logs after creation of certain domains (SEC-406).
cPanel before 68.0.27 does not enforce ownership during addpkgext and delpkgext WHM API calls (SEC-324).
cPanel before 68.0.15 allows use of an unreserved e-mail address in DNS zone SOA records (SEC-306).
cPanel before 68.0.15 does not block a username of postmaster, which might allow reception of private e-mail (SEC-326).
cPanel before 68.0.15 does not have a sufficient list of reserved usernames (SEC-327).
cPanel before 68.0.15 does not block a username of ssl (SEC-328).
cPanel before 68.0.15 allows user accounts to be partially created with invalid username formats (SEC-334).
cPanel before 66.0.2 allows resellers to read other accounts' domain log files (SEC-288).
In cPanel before 62.0.17, addon domain conversion did not require a package for resellers (SEC-208).
cPanel before 62.0.17 does not properly recognize domain ownership during addition of parked domains to a mail configura
In Limesurvey before 3.17.14, admin users can mark other users' notifications as read.
In Limesurvey before 3.17.14, admin users can run an integrity check without proper permissions.
A vulnerability has been identified in SINEMA Remote Connect Server (All versions < V2.0 SP1). An attacker with administ
In SilverStripe through 4.3.3, there is access escalation for CMS users with limited access through permission cache pol
Vulnerability in the Oracle Retail Xstore Point of Service product of Oracle Retail Applications (component: Point of Sa
Vulnerability in the MySQL Server product of Oracle MySQL (component: Information Schema). Supported versions that are a
Moodle before 2.2.2 has a permission issue in Forum Subscriptions where unenrolled users can subscribe/unsubscribe via m
A cleartext password storage issue was discovered in Katello, versions 3.x.x.x before katello 3.12.0.9. Registry credent
An issue was discovered in GitLab Community and Enterprise Edition through 12.4. It has Insecure Permissions (issue 2 of
An issue was discovered in TitanHQ WebTitan before 5.18. It exposes a database configuration file under /include/dbconfi
Improper validation of URL redirection in the Kubernetes API server in versions prior to v1.14.0 allows an attacker-cont
In TensorFlow before 1.15, a heap buffer overflow in UnsortedSegmentSum can be produced when the Index template argument
Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Shell). Supported versions that are affected
Scan for 2019 Vulnerabilities
CyberStrike detects these CVEs across your infrastructure automatically.
Get Started