17,305 vulnerabilities published in 2019
Zend Framework before 2.2.10 and 2.3.x before 2.3.5 has Potential SQL injection in PostgreSQL Zend\Db adapter.
Milesight IP security cameras through 2016-11-14 have a buffer overflow in a web application via a long username or pass
Milesight IP security cameras through 2016-11-14 have a hardcoded SSL private key under the /etc/config directory.
Milesight IP security cameras through 2016-11-14 have a default set of 10 privileged accounts with hardcoded credentials
Milesight IP security cameras through 2016-11-14 allow remote attackers to bypass authentication and access a protected
Milesight IP security cameras through 2016-11-14 have a default root password in /etc/shadow that is the same across dif
D-Link DIR-865L has PHP File Inclusion in the router xml file.
Adobe Experience Manager versions 6.5, 6.4, 6.3 and 6.2 have a command injection vulnerability. Successful exploitation
Linksys EA6500 has SMB Symlink Traversal allowing symbolic links to be created to locations outside of the Samba share.
RepetierServer.exe in Repetier-Server 0.8 through 0.91 does not properly validate the XML data structure provided when u
CODESYS V2.3 ENI server up to V3.2.2.24 has a Buffer Overflow.
Rittal Chiller SK 3232-Series web interface as built upon Carel pCOWeb firmware A1.5.3 – B1.2.4. The authentication mech
A command injection have been found in YouPHPTube Encoder. A successful attack could allow an attacker to compromise the
A command injection have been found in YouPHPTube Encoder. A successful attack could allow an attacker to compromise the
A command injection have been found in YouPHPTube Encoder. A successful attack could allow an attacker to compromise the
Buffer overflow in LabF nfsAxe FTP client 3.7 allows an attacker to execute code remotely.
An issue was discovered in rConfig 3.9.2. An attacker can directly execute system commands by sending a GET request to a
An issue was discovered on Mitsubishi Electric Europe B.V. ME-RTU devices through 2.02 and INEA ME-RTU devices through 3
An issue was discovered on Mitsubishi Electric Europe B.V. ME-RTU devices through 2.02 and INEA ME-RTU devices through 3
An issue was discovered on Mitsubishi Electric Europe B.V. ME-RTU devices through 2.02 and INEA ME-RTU devices through 3
An issue was discovered on Mitsubishi Electric Europe B.V. ME-RTU devices through 2.02 and INEA ME-RTU devices through 3
Snoopy before 2.0.0 has a security hole in exec cURL
pixelpost 1.7.1 has SQL injection
Tiki Wiki CMS Groupware 5.2 has Local File Inclusion
In K7 Antivirus Premium 16.0.xxx through 16.0.0120; K7 Total Security 16.0.xxx through 16.0.0120; and K7 Ultimate Securi
A directory traversal vulnerability was discovered in RepetierServer.exe in Repetier-Server 0.8 through 0.91 that allows
A remote SEH buffer overflow has been discovered in IntraSrv 1.0 (2007-06-03). An attacker may send a crafted HTTP GET o
A directory traversal vulnerability in Trend Micro Apex One, OfficeScan (11.0, XG) and Worry-Free Business Security (9.5
ytnef has directory traversal
qtparted has insecure library loading which may allow arbitrary code execution
Bitlbee does not drop extra group privileges correctly in unix.c
Postgresql Windows installer before versions 11.5, 10.10, 9.6.15, 9.5.19, 9.4.24 is vulnerable via bundled OpenSSL execu
Sequelize all versions prior to 3.35.1, 4.44.3, and 5.8.11 are vulnerable to SQL Injection due to JSON path keys not bei
sequelize before version 3.35.1 allows attackers to perform a SQL Injection due to the JSON path keys not being properly
TightVNC code version 1.3.10 contains heap buffer overflow in rfbServerCutText handler, which can potentially result cod
TightVNC code version 1.3.10 contains heap buffer overflow in InitialiseRFBConnection function, which can potentially re
TurboVNC server code contains stack buffer overflow vulnerability in commit prior to cea98166008301e614e0d36776bf9435a53
In axohelp.c before 1.3 in axohelp in axodraw2 before 2.1.1b, as distributed in TeXLive and other collections, sprintf i
Opera Mini for Android allows attackers to bypass intended restrictions on .apk file download/installation via an RTLO (
TightVNC code version 1.3.10 contains global buffer overflow in HandleCoRREBBP macro function, which can potentially res
SugarCRM CE <= 6.3.1 contains scripts that use "unserialize()" with user controlled input which allows remote attackers
systemd 239 through 245 accepts any certificate signed by a trusted certificate authority for DNS Over TLS. Server Name
columnQuote in medoo before 1.7.5 allows remote attackers to perform a SQL Injection due to improper escaping.
European Commission eIDAS-Node Integration Package before 2.3.1 allows Certificate Faking because an attacker can sign a
European Commission eIDAS-Node Integration Package before 2.3.1 has Missing Certificate Validation because a certain Exp
Transmission before 1.92 allows an attacker to cause a denial of service (crash) or possibly have other unspecified impa
An issue was discovered in Xen through 4.12.x allowing 32-bit PV guest OS users to gain guest OS privileges by installin
In JetBrains TeamCity before 2019.1.4, insecure Java Deserialization could potentially allow remote code execution.
overkill has buffer overflow via long player names that can corrupt data on the server machine
burn allows file names to escape via mishandled quotation marks
Scan for 2019 Vulnerabilities
CyberStrike detects these CVEs across your infrastructure automatically.
Get Started