17,305 vulnerabilities published in 2019
An issue was discovered in TitanHQ WebTitan before 5.18. It has a hidden support account (with a hard-coded password) in
Zanata 3.0.0 through 3.1.2 has RCE due to EL interpolation in logging
In OkayCMS through 2.3.4, an unauthenticated attacker can achieve remote code execution by injecting a malicious PHP obj
An issue was discovered in SALTO ProAccess SPACE 5.4.3.0. An attacker can write arbitrary content to arbitrary files, as
An exploitable code execution vulnerability exists in the processing of multi-part/form-data requests within the base Go
This command injection vulnerability in Music Station allows attackers to execute commands on the affected device. To fi
This command injection vulnerability in File Station allows attackers to execute commands on the affected device. To fix
An invalid free in mb_detect_order can cause the application to crash or potentially result in remote code execution. Th
Improper handling of close_notify alerts can result in an out-of-bounds read in AsyncSSLSocket. This issue affects folly
Insufficient boundary checks when processing a string in mb_ereg_replace allows access to out-of-bounds memory. This iss
Various APC functions accept keys containing null bytes as input, leading to premature truncation of input. This issue a
In the course of decompressing HPACK inside the HTTP2 protocol, an unexpected sequence of header table resize operations
Apache Olingo versions 4.0.0 to 4.6.0 provide the AbstractService class, which is public API, uses ObjectInputStream and
class.upload.php in verot.net class.upload before 1.0.3 and 2.x before 2.0.4, as used in the K2 extension for Joomla! an
Fronius Solar Inverter devices before 3.14.1 (HM 1.12.1) allow attackers to bypass authentication because the password f
An SQL Injection vulnerability exists in MiniDLNA prior to 1.1.0
libc in OpenBSD 6.6 allows authentication bypass via the -schallenge username, as demonstrated by smtpd, ldapd, or radiu
The Lever PDF Embedder plugin 4.4 for WordPress does not block the distribution of polyglot PDF documents that are valid
lookupName in resolve.c in SQLite 3.30.1 omits bits from the colUsed bitmask in the case of a generated column, which al
A vulnerability was found in keycloak 7.x, when keycloak is configured with LDAP user federation and StartTLS is used in
reset/modules/fotoliaFoto/multi_upload.php in the RESET.PRO Adobe Stock API Integration for PrestaShop 1.6 and 1.7 allow
reset/modules/advanced_form_maker_edit/multiupload/upload.php in the RESET.PRO Adobe Stock API integration 4.8 for Prest
This improper link resolution vulnerability allows remote attackers to access system files. To fix this vulnerability, Q
This improper access control vulnerability allows remote attackers to gain unauthorized access to the system. To fix the
This improper input validation vulnerability allows remote attackers to inject arbitrary code to the system. To fix the
This external control of file name or path vulnerability allows remote attackers to access or modify system files. To fi
This external control of file name or path vulnerability allows remote attackers to access or modify system files. To fi
phpMyAdmin before 4.9.2 does not escape certain Git information, related to libraries/classes/Display/GitRevision.php an
In all versions of libyang before 1.0-r5, a stack-based buffer overflow was discovered in the way libyang parses YANG fi
In all versions of libyang before 1.0-r5, a stack-based buffer overflow was discovered in the way libyang parses YANG fi
OpenSLP as used in ESXi and the Horizon DaaS appliances has a heap overwrite issue. VMware has evaluated the severity of
The username parameter of the TITool PrintMonitor solution during the login request is vulnerable to and/or time-based b
An issue was discovered on Weidmueller IE-SW-VL05M 3.6.6 Build 16102415, IE-SW-VL08MT 3.5.2 Build 16102415, and IE-SW-PL
An issue was discovered on Weidmueller IE-SW-VL05M 3.6.6 Build 16102415, IE-SW-VL08MT 3.5.2 Build 16102415, and IE-SW-PL
An issue was discovered on Weidmueller IE-SW-VL05M 3.6.6 Build 16102415, IE-SW-VL08MT 3.5.2 Build 16102415, and IE-SW-PL
Insufficient checks in the USB packet handling of the ShapeShift KeepKey hardware wallet before firmware 6.2.2 allow out
safer-eval is a npm package to sandbox the he evaluation of code used within the eval function. Affected versions of thi
An issue was discovered in libsixel 1.8.2. There is a heap-based buffer overflow in the function sixel_decode_raw_impl a
An issue was discovered in libsixel 1.8.2. There is an integer overflow in the function sixel_encode_body at tosixel.c.
An issue was discovered in libsixel 1.8.2. There is an integer overflow in the function sixel_decode_raw_impl at fromsix
An issue was discovered in libsixel 1.8.2. There is a heap-based buffer overflow in the function load_pnm at frompnm.c,
Trend Micro Security (Consumer) 2020 (v16.x) is affected by a vulnerability in where null pointer dereference errors res
pragma.c in SQLite through 3.30.1 mishandles NOT NULL in an integrity_check PRAGMA command in certain cases of generated
An unsafe deserialization vulnerability exists in CA Release Automation (Nolio) 6.6 with the DataManagement component th
IBM DataPower Gateway 7.6.0.0-7 throug 6.0.14 and 2018.4.1.0 through 2018.4.1.5 have a default administrator account tha
rubygem-openshift-origin-controller: API can be used to create applications via cartridge_cache.rb URI.prase() to perfor
Monkey HTTP Daemon: broken user name authentication
python-keystoneclient version 0.2.3 to 0.2.5 has middleware memcache encryption bypass
python-keystoneclient version 0.2.3 to 0.2.5 has middleware memcache signing bypass
Platform System Manager in IBM Cloud Pak System 2.3 is potentially vulnerable to CVS Injection. A remote attacker could
Scan for 2019 Vulnerabilities
CyberStrike detects these CVEs across your infrastructure automatically.
Get Started