17,305 vulnerabilities published in 2019
Integard Pro 2.2.0.9026 allows remote attackers to execute arbitrary code via a buffer overflow involving a long NoJs pa
ZZZCMS zzzphp v1.7.2 has an insufficient protection mechanism against PHP Code Execution, because passthru bypasses an s
All versions up to V81511329.1008 of ZTE ZXV10 B860A products are impacted by input validation vulnerability. Due to inp
The makandra consul gem through 1.0.2 for Ruby has Incorrect Access Control.
An issue was discovered in net/wireless/nl80211.c in the Linux kernel through 5.2.17. It does not check the length of va
In wolfSSL through 4.1.0, there is a missing sanity check of memory accesses in parsing ASN.1 certificate data while han
An issue was discovered in Suricata 4.1.4. By sending multiple IPv4 packets that have invalid IPv4Options, the function
ONTAP Select Deploy administration utility versions 2.12 & 2.12.1 ship with an HTTP service bound to the network allowin
ONTAP Select Deploy administration utility versions 2.2 through 2.12.1 transmit credentials in plaintext.
File Sharing Wizard 1.5.0 allows a remote attacker to obtain arbitrary code execution by exploiting a Structured Excepti
vBulletin 5.x through 5.5.4 allows remote command execution via the widgetConfig[code] parameter in an ajax/render/widge
emlog through 6.0.0beta has an arbitrary file deletion vulnerability via an admin/data.php?action=dell_all_bak request w
SQL injection vulnerabilities in Centreon through 19.04 allow attacks via the svc_id parameter in include/monitoring/sta
An issue was discovered in the linea crate through 0.9.4 for Rust. There is double free in the Matrix::zip_elements meth
An issue was discovered in the portaudio-rs crate through 0.3.1 for Rust. There is a use-after-free with resultant arbit
In SilverStripe through 4.3.3, a missing warning about leaving install.php in a public webroot can lead to unauthenticat
An authentication bypass vulnerability discovered in Smart Battery A2-25DE, a multifunctional portable charger, firmware
A broken access control vulnerability in Smart Battery A4, a multifunctional portable charger, firmware version ?<= r1.7
An unsafe authentication interface was discovered in Smart Battery A4, a multifunctional portable charger, firmware vers
OpenID Connect Issuer in LemonLDAP::NG 2.x through 2.0.5 may allow an attacker to bypass access control rules via a craf
The oauth2-provider plugin before 3.1.5 for WordPress has incorrect generation of random numbers.
BMC Remedy ITSM Suite is prone to unspecified vulnerabilities in both DWP and SmartIT components, which can permit remot
download.php in inoERP 4.15 allows SQL injection through insecure deserialization.
An issue was discovered in pfSense through 2.4.4-p3. widgets/widgets/picture.widget.php uses the widgetkey parameter dir
Unauthenticated remote code execution occurs in D-Link products such as DIR-655C, DIR-866L, DIR-652, and DHP-1565. The i
ColdFusion 2018- update 4 and earlier and ColdFusion 2016- update 11 and earlier have a Command Injection via Vulnerable
ColdFusion 2018- update 4 and earlier and ColdFusion 2016- update 11 and earlier have a Path Traversal vulnerability. Su
When a master password is set, it is required to be entered again before stored passwords can be accessed in the 'Saved
Mozilla developers and community members reported memory safety bugs present in Firefox 68. Some of these bugs showed ev
In libAACdec, there is a possible out of bounds write due to an integer overflow. This could lead to remote code executi
In Bluetooth, there is a possible deserialization error due to missing string validation. This could lead to remote code
In libttspico, there is a possible OOB write due to a heap buffer overflow. This could lead to remote escalation of priv
Exim 4.92 through 4.92.2 allows remote code execution, a different vulnerability than CVE-2019-15846. There is a heap-ba
Dell EMC ECS versions prior to 3.4.0.0 contain an improper restriction of excessive authentication attempts vulnerabilit
NSA Ghidra through 9.0.4, when experimental mode is enabled, allows arbitrary code execution if the Read XML Files featu
Plataformatec Simple Form has Incorrect Access Control in file_method? in lib/simple_form/form_builder.rb, because a use
CloudBoot through 2019-03-08 allows SQL Injection via a crafted Status field in JSON data to the api/osinstall/v1/device
contrib/pmdb2diag/pmdb2diag.c in Rsyslog v8.1908.0 allows out-of-bounds access because the level length is mishandled.
Device record of the pairing device used after free during ACL disconnection in Snapdragon Auto, Snapdragon Compute, Sna
Lack of check of address range received from firmware response allows modem to respond arbitrary pages into its address
Possible buffer overflow issue due to lack of length check when parsing the extended cap IE header length in Snapdragon
Buffer overflow in WLAN NAN function due to lack of check of count value received in NAN availability attribute in Snapd
Classic buffer overflow vulnerability while playing the specific video whose Decode picture buffer size is more than 16
Usage of hard-coded magic number for calculating heap guard bytes can allow users to corrupt heap blocks without heap al
Victure PC530 devices allow unauthenticated TELNET access as root.
An issue was discovered in JetBrains TeamCity 2018.2.4. It had a possible remote code execution issue. This was fixed in
A series of deserialization vulnerabilities have been discovered in Codehaus 1.9.x implemented in EAP 7. This CVE fixes
A Polymorphic Typing issue was discovered in FasterXML jackson-databind 2.0.0 through 2.9.10. When Default Typing is ena
A Polymorphic Typing issue was discovered in FasterXML jackson-databind 2.0.0 through 2.9.10. When Default Typing is ena
PuTTY before 0.73 on Windows improperly opens port-forwarding listening sockets, which allows attackers to listen on the
Scan for 2019 Vulnerabilities
CyberStrike detects these CVEs across your infrastructure automatically.
Get Started