17,305 vulnerabilities published in 2019
Double free issue can happen when sensor power settings is freed by some thread while another thread try to access. in S
Kernel can do a memory read from arbitrary address passed by user during execution of a syscall in Snapdragon Auto, Snap
Improper validation of array index causes OOB write and then leads to memory corruption in MMCP in Snapdragon Auto, Snap
Improper validation of read and write index of tx and rx fifo`s before calculating pointer can lead to out-of-bound acce
Out of bound write issue is observed while giving information about properties that have been set so far for playing vid
While processing vendor command which contains corrupted channel count, an integer overflow occurs and finally will lead
Lack of check to ensure crypto engine data passed by user is initialized can result in bus error in Snapdragon Auto, Sna
When ADSP is compromised, the audio port index that`s returned from ADSP might be out of the valid range and leads to ou
Out of boundary access due to token received from ADSP and is used without validation as an index into the array in Snap
Possible Integer overflow because of subtracting two integers without checking if the result would overflow or not in Sn
Memory corruption while accessing the memory as payload size is not validated before access in Snapdragon Auto, Snapdrag
Apache CXF before 3.3.4 and 3.2.11 provides all of the components that are required to build a fully fledged OpenId Conn
An issue was discovered in net/ipv4/sysctl_net_ipv4.c in the Linux kernel before 5.0.11. There is a net/ipv4/tcp_input.c
An issue was discovered in the Linux kernel through 5.3.9. There is a use-after-free when aa_label_parse() fails in aa_a
A wrong type is used for a return value from strlen in WebKit in Google Chrome before Blink M12 on 64-bit platforms.
Potential security vulnerabilities have been identified with HPE Nimble Storage systems in multi array group configurati
gitolite before 1.4.1 does not filter src/ or hooks/ from path names.
syscp 1.4.2.1 allows attackers to add arbitrary paths via the documentroot of a domain by appending a colon to it and se
TWiki before 5.1.4 allows remote attackers to execute arbitrary shell commands by sending a crafted '%MAKETEXT{}%' param
strapi before 3.0.0-beta.17.5 mishandles password resets within packages/strapi-admin/controllers/Auth.js and packages/s
clamav 0.91.2 suffers from a floating point exception when using ScanOLE2.
gri before 2.12.18 generates temporary files in an insecure way.
Matrix Synapse before 1.5.0 mishandles signature checking on some federation APIs. Events sent over /send_join, /send_le
Escalation of privileges in EnergyCAP 7 through 7.5.6 allows an attacker to access data. If an unauthenticated user clic
Certain D-Link devices have a hardcoded Alphanetworks user account with TELNET access because of /etc/config/image_sign
gdk-pixbuf through 2.31.1 has GIF loader buffer overflow when initializing decompression tables due to an input validati
Elgg through 1.7.10 has a SQL injection vulnerability
In Helm 2.x before 2.15.2, commands that deal with loading a chart as a directory or packaging a chart provide an opport
File Sharing Wizard version 1.5.0 build 2008 is affected by a Structured Exception Handler based buffer overflow vulnera
Systematic IRIS WebForms 5.4 and its functionalities can be accessed and used without any form of authentication.
An issue was discovered in Picture_Manage_mvc.aspx in AUO SunVeillance Monitoring System before v1.1.9e. There is an inc
A remote code execution vulnerability exists in Microsoft Exchange through the deserialization of metadata via PowerShel
A security feature bypass vulnerability exists in the way that Office Click-to-Run (C2R) components handle a specially c
libpoe-component-irc-perl before v6.32 does not remove carriage returns and line feeds. This can be used to execute arbi
The BIOS tamper detection mechanism was not triggered in Lenovo ThinkPad T460p, BIOS versions up to R07ET90W, and T470p,
Symlink Traversal vulnerability in ASUS RT-AC66U and RT-N56U due to misconfiguration in the SMB service.
Symlink Traversal vulnerability in TP-LINK TL-WDR4300 and TL-1043ND..
An SSRF issue was discovered in Enghouse Web Chat 6.1.300.31. In any POST request, one can replace the port number at We
Symlink Traversal vulnerability in NETGEAR WNR3500U and WNR3500L due to misconfiguration in the SMB service.
In okToConnect of HidHostService.java, there is a possible permission bypass due to an incorrect state check. This could
In FindSharedFunctionInfo of objects.cc, there is a possible out of bounds read due to a mistake in AST traversal. This
In ProxyResolverV8::SetPacScript of proxy_resolver_v8.cc, there is a possible memory corruption due to a use after free.
offlineimap before 6.3.4 added support for SSL server certificate validation but it is still possible to use SSL v2 prot
Undocumented TELNET service in TRENDnet TEW-691GR and TEW-692GR when a web page named backdoor contains an HTML paramete
In Fuji Electric V-Server 4.0.6 and prior, several heap-based buffer overflows have been identified, which may allow an
SibSoft Xfilesharing through 2.5.1 allows cgi-bin/up.cgi arbitrary file upload. This can be combined with CVE-2019-18951
An exploitable command injection vulnerability exists in the Config editor of the Exhibitor Web UI versions 1.0.9 to 1.7
Unprotected Storage of Credentials vulnerability in McAfee Advanced Threat Defense (ATD) prior to 4.8 allows local attac
In klibc 1.5.20 and 1.5.21, the DHCP options written by ipconfig to /tmp/net-$DEVICE.conf are not properly escaped. This
Adobe Media Encoder versions 13.1 and earlier have an out-of-bounds write vulnerability. Successful exploitation could l
Scan for 2019 Vulnerabilities
CyberStrike detects these CVEs across your infrastructure automatically.
Get Started