17,305 vulnerabilities published in 2019
A CSRF issue was found in OpenShift Enterprise 1.2. The web console is using 'Basic authentication' and the REST API has
OutSystems Platform 10 through 11 allows ImageResourceDetail.aspx CSRF for content modifications and file uploads. NOTE:
The GOsa_Filter_Settings cookie in GONICUS GOsa 2.7.5.2 is vulnerable to PHP objection injection, which allows a remote
Cross-site request forgery (CSRF) vulnerability in admin.php in Zenphoto before 1.4.9 allows remote attackers to hijack
An issue was discovered in ezXML 0.8.3 through 0.8.6. The function ezxml_ent_ok() mishandles recursion, leading to stack
An issue was discovered in ezXML 0.8.3 through 0.8.6. The function ezxml_decode, while parsing a crafted XML file, perfo
An issue was discovered in ezXML 0.8.3 through 0.8.6. The function ezxml_decode, while parsing crafted a XML file, perfo
An issue was discovered in ezXML 0.8.3 through 0.8.6. The ezxml_parse_* functions mishandle XML entities, leading to an
An issue was discovered in ezXML 0.8.3 through 0.8.6. The function ezxml_char_content() tries to use realloc on a block
Vulnerability in the Sun ZFS Storage Appliance Kit (AK) component of Oracle Sun Systems Products Suite (subcomponent: Ob
Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: Connection Handling). Supported versi
The IBM Power 9 OP910, OP920, and FW910 boot firmware's bootloader is responsible for loading and validating the initial
The kubectl cp command allows copying files between containers and the user machine. To copy files from a container, Kub
IBM Cognos Analytics 11 could allow a remote attacker to traverse directories on the system. An attacker could send a sp
Juju Core's Joyent provider before version 1.25.5 uploads the user's private ssh key.
IBM API Connect 2018.1 and 2018.4.1.4 could allow a remote attacker to hijack the clicking action of the victim. By pers
An issue was discovered in Espressif ESP-IDF 2.x and 3.x before 3.0.6 and 3.1.x before 3.1.1. Insufficient validation of
Dell EMC RecoverPoint versions prior to 5.1.3 and RecoverPoint for VMs versions prior to 5.2.0.2 contain an OS command i
A vulnerability in the Remote Package Manager (RPM) subsystem of Cisco NX-OS Software could allow an authenticated, loca
Huawei Honor V10 smartphones versions earlier than Berkeley-AL20 9.0.0.125(C00E125R2P14T8) have an authorization bypass
A remote code execution vulnerability exists in the way that comctl32.dll handles objects in memory. The vulnerability c
It was found that Picketlink as shipped with Jboss Enterprise Application Platform 7.2 would accept an xinclude paramete
An issue was discovered on Securifi Almond, Almond+, and Almond 2015 devices with firmware AL-R096. The device provides
A vulnerability in the CLI of Cisco Integrated Management Controller (IMC) could allow an authenticated, local attacker
Intersystems Cache 2017.2.2.865.0 allows XXE.
Vulnerability in the PeopleSoft Enterprise FIN Project Costing component of Oracle PeopleSoft Products (subcomponent: Pr
A remote code execution vulnerability exists in the way that Microsoft browsers access objects in memory. The vulnerabil
An issue was discovered in the Linux kernel before 5.0.10. There is a use-after-free in the sound subsystem because card
Dell EMC Enterprise Copy Data Management (eCDM) versions 1.0, 1.1, 2.0, 2.1, and 3.0 contain a certificate validation vu
OpenSC before 0.20.0-rc1 has an out-of-bounds access of an ASN.1 Bitstring in decode_bit_string in libopensc/asn1.c.
OpenSC before 0.20.0-rc1 has an out-of-bounds access of an ASN.1 Octet string in asn1_decode_entry in libopensc/asn1.c.
In the Android kernel in the mnh driver there is a race condition due to insufficient locking. This could lead to a use-
In the Android kernel in the FingerTipS touchscreen driver there is a possible memory corruption due to a race condition
The RSA Identity Governance and Lifecycle software and RSA Via Lifecycle and Governance products prior to 7.1.0 P08 cont
The RSA Identity Governance and Lifecycle software and RSA Via Lifecycle and Governance products prior to 7.1.0 P08 cont
In the Easel driver, there is possible memory corruption due to race conditions. This could lead to local escalation of
In the Easel driver, there is possible memory corruption due to race conditions. This could lead to local escalation of
In hostapd, there is a possible out of bounds write due to a race condition. This could lead to local escalation of priv
A remote code execution vulnerability exists in the way that the VBScript engine handles objects in memory, aka 'VBScrip
Vulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Fusion Middleware (component: Ana
Vulnerability in the Hyperion Data Relationship Management product of Oracle Hyperion (component: Access and Security).
A potential vulnerability in the SMI callback function used in the Legacy USB driver using boot services structure in ru
A potential vulnerability in the SMI callback function used in Legacy USB driver using passed parameter without sufficie
Vulnerability in the Oracle Application Testing Suite component of Oracle Enterprise Manager Products Suite (subcomponen
A vulnerability was discovered in gdm before 3.31.4. When timed login is enabled in configuration, an attacker could byp
Insufficient access control in User Mode Driver in Intel(R) Graphics Driver for Windows* before versions 10.18.x.5059 (a
A flaw was found in the /oauth/token/request custom endpoint of the OpenShift OAuth server allowing for XSS generation o
IBM InfoSphere Information Server 11.5 and 11.7 is vulnerable to SQL injection. A remote attacker could send specially-c
Vulnerability in the Oracle Application Testing Suite component of Oracle Enterprise Manager Products Suite (subcomponen
Vulnerability in the MySQL Connectors component of Oracle MySQL (subcomponent: Connector/J). Supported versions that are
Scan for 2019 Vulnerabilities
CyberStrike detects these CVEs across your infrastructure automatically.
Get Started