17,305 vulnerabilities published in 2019
In Progress MOVEit Transfer 10.2 before 10.2.6 (2018.3), 11.0 before 11.0.4 (2019.0.4), and 11.1 before 11.1.3 (2019.1.3
In Progress MOVEit Transfer 11.1 before 11.1.3, a vulnerability has been found that could allow an attacker to sign in w
yum does not properly handle bad metadata, which allows an attacker to cause a denial of service and possibly have other
Chicken before 4.8.0 is susceptible to algorithmic complexity attacks related to hash table collisions.
FreeTDS through 1.1.11 has a Buffer Overflow.
Advantech WISE-PaaS/RMM, Versions 3.3.29 and prior. There is an unsecured function that allows anyone who can access the
Advantech WISE-PaaS/RMM, Versions 3.3.29 and prior. Path traversal vulnerabilities are caused by a lack of proper valida
Honeywell equIP series and Performance series IP cameras and recorders, A vulnerability exists in the affected products
minidlna has SQL Injection that may allow retrieval of arbitrary files
TWiki allows arbitrary shell command execution via the Include function
MiniDLNA has heap-based buffer overflow
Apache Struts before 2.3.1.2 allows remote attackers to bypass security protections in the ParameterInterceptor class an
Foswiki before 1.1.8 contains a code injection vulnerability in the MAKETEXT macro.
An issue was discovered in YouPHPTube through 7.7. User input passed through the live_stream_code POST parameter to /plu
Cryptocat before 2.0.22 has Remote Script Injection due to improperly sanitizing user input
Cryptocat before 2.0.22 has Arbitrary Code Execution on Firefox Conversation Overview
Cryptocat before 2.0.22: Cryptocat.random() Function Array Key has Entropy Weakness
A SQL injection vulnerability in a /login/forgot1 POST request in ARP-GUARD 4.0.0-5 allows unauthenticated remote attack
An eval() vulnerability exists in Python Software Foundation Djblets 0.7.21 and Beanbag Review Board before 1.7.15 when
The plural form formula in ngettext family of calls in php-gettext before 1.0.12 allows remote attackers to execute arbi
Buffer overflows were discovered in the CoAP library in Arm Mbed OS 5.14.0. The CoAP parser is responsible for parsing r
An integer overflow was discovered in the CoAP library in Arm Mbed OS 5.14.0. The function sn_coap_builder_calc_needed_p
Nvu 0.99+1.0pre uses an old copy of Mozilla XPCOM which can result in multiple security issues.
An arbitrary command injection vulnerability in the Cluster Server component of Veritas InfoScale allows an unauthentica
Cross-Site Scripting (XSS) in Xinha, as included in the Serendipity package before 1.5.5, allows remote attackers to exe
WebKit in Google Chrome before Blink M11 contains a bad cast to RenderBlock when anonymous blocks are renderblocks.
An insecure component vulnerability exists in Magento 2.1 prior to 2.1.19, Magento 2.2 prior to 2.2.10, Magento 2.3 prio
A remote code execution vulnerability exists in Magento 2.2 prior to 2.2.10, Magento 2.3 prior to 2.3.3 or 2.3.2-p1. Dep
An insecure component vulnerability exists in Magento 2.2 prior to 2.2.10, Magento 2.3 prior to 2.3.3 or 2.3.2-p1. Magen
A remote code execution vulnerability exists in Magento 2.3 prior to 2.3.3 or 2.3.2-p1. An unauthenticated user can inse
Insecure authentication and session management vulnerability exists in Magento 2.2 prior to 2.2.10, Magento 2.3 prior to
An XPath entity injection vulnerability exists in Magento 2.2 prior to 2.2.10, Magento 2.3 prior to 2.3.3 or 2.3.2-p1. A
xlockmore 5.13 and 5.22 segfaults when using libpam-opensc and returns the underlying xsession. This allows unauthorized
xlockmore 5.13 allows potential xlock bypass when FVWM switches to the same virtual desktop as a new Gaim window.
termpkg 3.3 suffers from buffer overflow.
linux vserver 2.6 before 2.6.17 suffers from privilege escalation in remount code.
SuiteCRM 7.10.x versions prior to 7.10.21 and 7.11.x versions prior to 7.11.9 allow SQL Injection.
There is a possible heap overflow in libclamav/fsg.c before 0.100.0.
Aruba ClearPass Policy Manager before 6.5.7 and 6.6.x before 6.6.2 allows attackers to obtain database credentials.
Quest KACE Systems Management Appliance Server Center version 9.1.317 is vulnerable to SQL injection. The affected file
Rbot Reaction plugin allows command execution
TYPO3 before 4.3.12, 4.4.x before 4.4.9, and 4.5.x before 4.5.4 allows remote attackers to bypass authentication mechani
Out of bound access while processing a non-standard IE measurement request with length crossing past the size of frame i
While playing the clip which is nonstandard buffer overflow can occur while parsing in Snapdragon Auto, Snapdragon Compu
Use after free issue in kernel while accessing freed mdlog session info and its attributes after closing the session in
Incorrect reading of system image resulting in buffer overflow when size of system image is increased in Snapdragon Auto
Out of bound access due to improper validation of array index cause the index table entry to get corrupt in Snapdragon A
Null-pointer dereference can occur while accessing the super index entry when it is not been allocated in Snapdragon Aut
Dereference on uninitialized buffer can happen when parsing FLV clip with corrupted codec specific data in Snapdragon Au
Buffer over-read may occur when downloading a corrupted firmware file that has chunk length in header which doesn`t matc
Scan for 2019 Vulnerabilities
CyberStrike detects these CVEs across your infrastructure automatically.
Get Started