17,305 vulnerabilities published in 2019
A remote code execution vulnerability exists when Windows Hyper-V Network Switch on a host server fails to properly vali
A remote code execution vulnerability exists when Windows Hyper-V Network Switch on a host server fails to properly vali
Insufficient session validation in Intel(R) Baseboard Management Controller firmware may allow an unauthenticated user t
An issue was discovered on Zyxel GS1900 devices with firmware before 2.50(AAHH.0)C0. Through an undocumented sequence of
Footy Tipping Software AFL Web Edition 2019 allows arbitrary file upload and resultant remote code execution because a w
VMware Workstation (15.x before 15.5.1) and Fusion (11.x before 11.5.1) contain an out-of-bounds write vulnerability in
An issue was discovered in Squid before 4.9. When handling a URN request, a corresponding HTTP request is made. This HTT
In LuaJIT through 2.0.5, as used in Moonjit before 2.1.2 and other products, debug.getinfo has a type confusion issue th
RoxyFileman, as shipped with nopCommerce v4.2.0, is vulnerable to ../ path traversal via d or f to Admin/RoxyFileman/Pro
IBM SmartCloud Analytics 1.3.1 through 1.3.5 could allow a remote attacker to gain unauthorized information and unrestri
An issue was discovered in core/assets/form/form_question_types/form_question_type_file_upload/form_question_type_file_u
A vulnerability has been identified in XHQ (All versions < V6.0.0.2). The web application requests could be manipulated,
A vulnerability has been identified in SPPA-T3000 MS3000 Migration Server (All versions). An attacker with network acces
A vulnerability has been identified in SPPA-T3000 MS3000 Migration Server (All versions). An attacker with network acces
A buffer overflow was addressed with improved size validation. This issue is fixed in iOS 12.2, macOS Mojave 10.14.4, tv
An exploitable denial-of-service vulnerability exists in the iocheckd service ‘’I/O-Chec’’ functionality of WAGO PFC 200
An exploitable denial of service vulnerability exists in the iocheckd service "I/O-Check" functionality of WAGO PFC200 F
An exploitable denial-of-service vulnerability exists in the iocheckd service "I/O-Check" functionality of WAGO PFC 200
In ImageMagick 7.0.8-43 Q16, there is a heap-based buffer over-read in the function WritePNGImage of coders/png.c, relat
In GraphicsMagick 1.4 snapshot-20191208 Q8, there is a heap-based buffer over-read in the function EncodeImage of coders
class.userpeer.php in MFScripts YetiShare 3.5.2 through 4.5.3 uses an insecure method of creating password reset hashes
An issue was discovered in Zoho ManageEngine ADSelfService Plus 5.6 Build 5607. An exposed service allows an unauthentic
An exploitable buffer overflow vulnerability exists in the HTTP header-parsing function of the Webroot BrightCloud SDK.
IBM Security Identity Manager 6.0.0 allows the attacker to upload or transfer files of dangerous types that can be autom
Kibana versions before 6.6.1 contain an arbitrary code execution flaw in the security audit logger. If a Kibana instance
Flatpak before 1.0.8, 1.1.x and 1.2.x before 1.2.4, and 1.3.x before 1.3.1 allows a sandbox bypass. Flatpak versions sin
IBM BigFix Platform 9.5 could allow any authenticated user to upload any file to any location on the server with root pr
Cantemo Portal before 3.2.13, 3.3.x before 3.3.8, and 3.4.x before 3.4.9 has XSS. Leveraging this vulnerability would en
An issue was discovered in GNOME gnome-desktop 3.26, 3.28, and 3.30 prior to 3.30.2.2, and 3.32 prior to 3.32.1.1. A com
Vulnerability in the Java SE component of Oracle Java SE (subcomponent: Windows DLL). The supported version that is affe
In uBlock before 0.9.5.15, the $rewrite filter option allows filter-list maintainers to run arbitrary code in a client-s
An elevation of privilege vulnerability exists in Microsoft Edge that could allow an attacker to escape from the AppCont
Improper access control and open directories in Ivanti LANDESK Management Suite (LDMS, aka Endpoint Manager) 10.0.1.168
lib/Controller/ExtractionController.php in the Extract add-on before 1.2.0 for Nextcloud allows Remote Code Execution vi
Prima Systems FlexAir, Versions 2.3.38 and prior. Parameters sent to scripts are not properly sanitized before being ret
All versions up to UKBB_WF820+_1.0.0B06 of ZTE WF820+ LTE Outdoor CPE product are impacted by command injection vulnerab
A command injection (missing input validation) issue in the remote phonebook configuration URI in the web interface of t
An exploitable information disclosure vulnerability exists in the Weave PASE pairing functionality of the Nest Cam IQ In
There is a stored XSS in Rambox 0.6.9 that can lead to code execution. The XSS is in the name field while adding/editing
Vulnerability in the Oracle Hospitality RES 3700 component of Oracle Food and Beverage Applications. The supported versi
FUDForum 3.0.9 is vulnerable to Stored XSS via the User-Agent HTTP header. This may result in remote code execution. An
FUDForum 3.0.9 is vulnerable to Stored XSS via the nlogin parameter. This may result in remote code execution. An attack
The "301 Redirects - Easy Redirect Manager" plugin before 2.45 for WordPress allows users (with subscriber or greater ac
Scan for 2019 Vulnerabilities
CyberStrike detects these CVEs across your infrastructure automatically.
Get Started