17,305 vulnerabilities published in 2019
GlobalProtect Agent 4.1.0 for Windows and GlobalProtect Agent 4.1.10 and earlier for macOS may allow a local authenticat
The Linux kernel through 5.0.7, when CONFIG_IA32_AOUT is enabled and ia32_aout is loaded, allows local users to bypass A
cPanel before 68.0.27 allows attackers to read root's crontab file during a short time interval upon configuring crontab
cPanel before 68.0.27 allows attackers to read root's crontab file during a short time interval upon a post-update task
cPanel before 68.0.15 allows attackers to read backup files because they are world-readable during a short time interval
cPanel before 67.9999.103 allows Apache HTTP Server log files to become world-readable because of mishandling on an acco
In cPanel before 66.0.2, the cpdavd_error_log file can be created with weak permissions (SEC-280).
In cPanel before 66.0.2, Apache HTTP Server domlogs become temporarily world-readable during log processing (SEC-290).
A password generation weakness exists in xquest through 2016-06-13.
A race condition existed when reading and writing user preferences. This was addressed with improved state handling. Thi
A logic issue was addressed with improved restrictions. This issue affected versions prior to iOS 12.
A lock screen issue allowed access to photos via Reply With Message on a locked device. This issue was addressed with im
A lock screen issue allowed access to contacts on a locked device. This issue was addressed with improved state manageme
Diagnostics Agent in Solution Manager, version 7.2, stores several credentials such as SLD user connection as well as So
Vulnerability in the Oracle Hyperion Workspace component of Oracle Hyperion (subcomponent: UI and Visualization). The su
Bypass lock protection in the Nextcloud Android app prior to version 3.6.2 causes leaking of thumbnails when requesting
On Ledger Nano S and Nano X devices, a side channel for the row-based OLED display was found. The power consumption of e
On ShapeShift KeepKey devices, a side channel for the row-based OLED display was found. The power consumption of each ro
On Mooltipass Mini devices, a side channel for the row-based OLED display was found. The power consumption of each row-b
On BC Vault devices, a side channel for the row-based SSD1309 OLED display was found. The power consumption of each row-
RSA BSAFE Micro Edition Suite versions prior to 4.4 (in 4.0.x, 4.1.x, 4.2.x and 4.3.x) are vulnerable to a Heap-based Bu
IBM Maximo Anywhere 7.6.0, 7.6.1, 7.6.2, and 7.6.3 does not have device root detection which could result in an attacker
Vulnerability in the Oracle JDeveloper and ADF product of Oracle Fusion Middleware (component: OAM). Supported versions
Information Leakage in PPPoE Packet Padding in AVM Fritz!Box 7490 with Firmware versions Fritz!OS 6.80 and 6.83 allows p
gdm3 3.14.2 and possibly later has an information leak before screen lock
Honor play smartphones with versions earlier than Cornell-AL00A 9.1.0.321(C00E320R1P1T8) have an insufficient authentica
Mate 20 RS smartphones with versions earlier than 9.1.0.135(C786E133R3P1) have an improper authorization vulnerability.
In the Linux kernel before 5.3.4, there is an info-leak bug that can be caused by a malicious USB device in the drivers/
In the Linux kernel before 5.3.11, there is an info-leak bug that can be caused by a malicious USB device in the drivers
An issue existed where partially entered passcodes may not clear when the device went to sleep. This issue was addressed
A logic issue was addressed with improved restrictions. This issue is fixed in iOS 12.3. A person with physical access t
The issue was addressed with improved UI handling. This issue is fixed in iOS 12.4, watchOS 5.3. A user may inadvertentl
The issue was addressed by restricting options offered on a locked device. This issue is fixed in iOS 13. A person with
The issue was addressed by restricting options offered on a locked device. This issue is fixed in iOS 13.1 and iPadOS 13
Insufficient access control in Kernel Mode Driver in Intel(R) Graphics Driver for Windows* before versions 10.18.x.5059
OpenShift Container Platform before version 4.1.3 writes OAuth tokens in plaintext to the audit logs for the Kubernetes
cPanel before 74.0.0 allows file-rename operations during account renames (SEC-442).
In the Android kernel in the video driver there is a kernel pointer leak due to a WARN_ON statement. This could lead to
Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). Supported versions that ar
Vulnerability in the Core RDBMS component of Oracle Database Server. Supported versions that are affected are 12.1.0.2,
IBM Cloud Orchestrator 2.4 through 2.4.0.5 and 2.5 through 2.5.0.9 contain APIs that could be used by a local user to se
Symantec Endpoint Protection (SEP), prior to 14.2 RU2 may be susceptible to a password protection bypass vulnerability w
In supportutils, before version 3.1-5.7.1 and if pacemaker is installed on the system, an unprivileged user could have o
In yast2-multipath before version 4.1.1 a static temporary filename allows local attackers to overwrite files on systems
Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: InnoDB). Supported versions that are affected
Postgresql, versions 11.x before 11.5, is vulnerable to a memory disclosure in cross-type comparison for hashed subplan.
A potential security vulnerability caused by incomplete obfuscation of application configuration information was discove
IBM Maximo Asset Management 7.6 could allow a physical user of the system to obtain sensitive information from a previou
A vulnerability in generate_filestorage_key of Ubuntu MAAS allows an attacker to brute-force filenames. This issue affec
All versions of unity-scope-gdrive logs search terms to syslog.
Scan for 2019 Vulnerabilities
CyberStrike detects these CVEs across your infrastructure automatically.
Get Started