17,305 vulnerabilities published in 2019
An issue was discovered in rds_tcp_kill_sock in net/rds/tcp.c in the Linux kernel before 5.0.8. There is a race conditio
An exploitable use after free vulnerability exists in the window function functionality of Sqlite3 3.26.0. A specially c
Format string vulnerability in appGet.cgi on ASUS RT-AC3200 version 3.0.0.4.382.50010 allows attackers to read arbitrary
A SQL injection vulnerability in the activities API in OpenProject before 8.3.2 allows a remote attacker to execute arbi
The Rust Programming Language Standard Library 1.34.x before 1.34.2 contains a stabilized method which, if overridden, c
Sony Bravia Smart TV devices allow remote attackers to retrieve the static Wi-Fi password (used when the TV is acting as
Due to the use of an insecure RFID technology (MIFARE Classic), ABUS proximity chip keys (RFID tokens) of the ABUS Secve
An improper authentication vulnerability can be exploited through a race condition that occurs in Ellucian Banner Web Ta
A vulnerability in the web-based management interface of Cisco Prime Infrastructure (PI) and Cisco Evolved Programmable
A vulnerability in the web-based management interface of Cisco Prime Infrastructure (PI) and Cisco Evolved Programmable
An elevation of privilege vulnerability exists in Microsoft Windows when a man-in-the-middle attacker is able to success
In Hazelcast before 3.11, the cluster join procedure is vulnerable to remote code execution via Java deserialization. If
The ViewUpgrades resource in Jira before version 7.13.4, from version 8.0.0 before version 8.0.4, and from version 8.1.0
stack_protect_prologue in cfgexpand.c and stack_protect_epilogue in function.c in GNU Compiler Collection (GCC) 4.1 thro
In Zoho ManageEngine Application Manager prior to 14.6 Build 14660, the 'haid' parameter of the '/auditLogAction.do' mod
Computrols CBAS 18.0.0 allows Authentication Bypass.
Use of cryptographically weak PRNG in the password recovery token generation of Revive Adserver < v4.2.1 causes a potent
An issue was discovered in GNOME gvfs 1.29.4 through 1.41.2. daemon/gvfsbackendadmin.c has race conditions because the a
When RPC is enabled in Wind River VxWorks 6.9 prior to 6.9.1, a specially crafted RPC request can trigger an integer ove
Firejail before 0.9.60 allows truncation (resizing to length 0) of the firejail binary on the host by running exploit co
An XML external entities (XXE) vulnerability in Jenkins Pipeline Maven Integration Plugin 1.7.0 and earlier allowed atta
In some configurations an attacker can inject a new executable path into the extensions.load file for osquery and hard l
A SQL Injection vulnerability exists in Ivanti LANDESK Management Suite (LDMS, aka Endpoint Manager) 10.0.1.168 Service
Grails before 3.3.10 used cleartext HTTP to resolve the SDKMan notification service. NOTE: users' apps were not resolvin
In Yubico pam-u2f 1.0.7, when configured with debug and a custom debug log file is set using debug_file, that file descr
A remote code execution vulnerability was identified in HPE Intelligent Management Center (IMC) PLAT earlier than versio
Samsung Galaxy Apps before 4.4.01.7 allows modification of the hostname used for load balancing on installations of appl
An issue was discovered on Moxa AWK-3121 1.14 devices. The device by default allows HTTP traffic thus providing an insec
An issue was discovered on Moxa AWK-3121 1.14 devices. The device provides a Wi-Fi connection that is open and does not
In Eclipse Buildship versions prior to 3.1.1, the build files indicate that this project is resolving dependencies over
The Photo Sharing Plus component on Sony Bravia TV through 8.587 devices allows Directory Traversal.
A shell escape vulnerability in /webconsole/APIController in the API Configuration component of Sophos XG firewall 17.0.
KeyIdentity LinOTP before 2.10.5.3 has Incorrect Access Control (issue 1 of 2).
Insufficient policy enforcement in Extensions API in Google Chrome prior to 67.0.3396.62 allowed an attacker who convinc
Grouptime Teamwire Desktop Client 1.5.1 prior to 1.9.0 on Windows allows code injection via a template, leading to remot
LemonLDAP::NG before 1.9.20 has an XML External Entity (XXE) issue when submitting a notification to the notification se
Irssi before 1.0.8, 1.1.x before 1.1.3, and 1.2.x before 1.2.1, when SASL is enabled, has a use after free when sending
A path traversal flaw was found in spacewalk-proxy, all versions through 2.9, in the way the proxy processes cached clie
modules/luksbootkeyfile/main.py in Calamares versions 3.1 through 3.2.10 has a race condition between the time when the
Incorrect access control in the RPC framework in Odoo Community 8.0 through 11.0 and Odoo Enterprise 9.0 through 11.0 al
In several versions of JetBrains IntelliJ IDEA Ultimate, creating run configurations for cloud application servers leads
Incorrect access control in the password reset component in Odoo Community 11.0 and earlier and Odoo Enterprise 11.0 and
JetBrains Kotlin versions before 1.3.30 were resolving artifacts using an http connection during the build process, pote
JetBrains Ktor framework (created using the Kotlin IDE template) versions before 1.1.0 were resolving artifacts using an
JetBrains IntelliJ IDEA projects created using the Kotlin (JS Client/JVM Server) IDE Template were resolving Gradle arti
posix/JackSocket.cpp in libjack in JACK2 1.9.1 through 1.9.12 (as distributed with alsa-plugins 1.1.7 and later) has a "
MailEnable Enterprise Premium 10.23 was vulnerable to multiple directory traversal issues, with which authenticated user
An authorization bypass vulnerability in pinboard updates in ThoughtSpot 4.4.1 through 5.1.1 (before 5.1.2) allows a low
GitLab CE/EE, versions 8.6 up to 11.x before 11.3.11, 11.4 before 11.4.8, and 11.5 before 11.5.1, are vulnerable to an a
Cloudera Manager through 5.15 has Incorrect Access Control.
Scan for 2019 Vulnerabilities
CyberStrike detects these CVEs across your infrastructure automatically.
Get Started