17,305 vulnerabilities published in 2019
A man-in-the-middle vulnerability related to vCenter access was found in Cohesity DataPlatform version 5.x and 6.x prior
An elevation of privilege vulnerability exists in Microsoft Exchange Server, aka 'Microsoft Exchange Server Elevation of
SDL (Simple DirectMedia Layer) through 1.2.15 and 2.x through 2.0.9 has a heap-based buffer over-read in BlitNtoN in vid
In libssh2 before 1.9.0, kex_method_diffie_hellman_group_exchange_sha256_key_exchange in kex.c has an integer overflow t
Improper handling of LDAP authentication in MongoDB Server versions 3.0.0 to 3.0.6 allows an unauthenticated client to g
Remote Code Execution in PAN-OS 7.1.18 and earlier, PAN-OS 8.0.11-h1 and earlier, and PAN-OS 8.1.2 and earlier with Glob
IBM QRadar SIEM 7.2 and 7.3 specifies permissions for a security-critical resource in a way that allows that resource to
WCMS v0.3.2 has a CSRF vulnerability, with resultant directory traversal, to modify index.html via the /wex/html.php?fin
If hyperthreading is not disabled, a timing attack vulnerability exists, similar to previous Spectre attacks. Apple has
A use-after-free vulnerability can occur in AssertWorkerThread due to a race condition with shared workers. This results
Vulnerability in the Oracle FLEXCUBE Universal Banking component of Oracle Financial Services Applications (subcomponent
Vulnerability in the Oracle FLEXCUBE Investor Servicing component of Oracle Financial Services Applications (subcomponen
A race condition in the one-pass compression functions of Zstandard prior to version 1.3.8 could allow an attacker to wr
Yarn before 1.17.3 is vulnerable to Missing Encryption of Sensitive Data due to HTTP URLs in lockfile causing unencrypte
SMTP MITM refers to a malicious actor setting up an SMTP proxy server between the UniFi Controller version <= 5.10.21 an
It was found that in icedtea-web up to and including 1.7.2 and 1.8.2 executable code could be injected in a JAR file wit
A flaw was found in Jolokia versions from 1.2 to before 1.6.1. Affected versions are vulnerable to a system-wide CSRF. T
It was discovered evolution-ews before 3.31.3 does not check the validity of SSL certificates. An attacker could abuse t
cPanel before 11.54.0.0 allows unauthorized password changes via Webmail API commands (SEC-65).
cPanel before 11.54.0.0 allows unauthorized zone modification via the WHM API (SEC-66).
cPanel before 11.54.0.4 allows SQL injection in bin/horde_update_usernames (SEC-71).
cPanel before 11.54.0.4 allows code execution in the context of shared users via JSON-API (SEC-76).
cPanel before 11.54.0.4 allows arbitrary file-overwrite operations in scripts/check_system_storable (SEC-78).
cPanel before 11.54.0.4 allows arbitrary file-chown and file-chmod operations during Roundcube database conversions (SEC
cPanel before 11.54.0.4 allows arbitrary file-read and file-write operations via scripts/fixmailboxpath (SEC-80).
cPanel before 55.9999.141 allows attackers to bypass a Security Policy by faking static documents (SEC-92).
cPanel before 55.9999.141 allows ACL bypass for AppConfig applications via magic_revision (SEC-100).
When processing Deeplink scheme, Happypoint mobile app 6.3.19 and earlier versions doesn't check Deeplink URL correctly.
cPanel before 60.0.25 allows file-create and file-chmod operations during ModSecurity Audit logfile processing (SEC-165)
The Host Access Control feature in cPanel before 60.0.25 mishandles actionless host.deny entries (SEC-187).
The SQLite journal feature in cPanel before 57.9999.54 allows arbitrary file-overwrite operations during Horde Restore (
Jura E8 devices lack Bluetooth connection security.
Nespresso Prodigio devices lack Bluetooth connection security.
Wind River VxWorks 6.9.4 and vx7 has a Buffer Overflow in the TCP component (issue 4 of 4). There is an IPNET security v
eQ-3 Homematic CCU2 and CCU3 with the XML-API through 1.2.0 AddOn installed allow Remote Code Execution by unauthenticat
eQ-3 Homematic CCU2 and CCU3 with the CUxD AddOn before 2.3.0 installed allow administrative operations by unauthenticat
It was found that Keycloak's SAML broker, versions up to 6.0.1, did not verify missing message signatures. If an attacke
The Bluetooth BR/EDR specification up to and including version 5.1 permits sufficiently low encryption key length and do
An issue was discovered on NETGEAR Nighthawk M1 (MR1100) devices before 12.06.03. The web-interface Cross-Site Request F
Nessus 8.5.2 and earlier on Windows platforms were found to contain an issue where certain system files could be overwri
OX App Suite 7.10.1 allows Content Spoofing.
A vulnerability in the web-based management interface of Cisco Integrated Management Controller (IMC) Software could all
The posts-in-page plugin before 1.3.0 for WordPress has ic_add_posts template='../ directory traversal.
There is Missing SSL Certificate Validation in the pw3270 terminal emulator before version 5.1.
An issue was discovered in the openssl crate before 0.9.0 for Rust. There is an SSL/TLS man-in-the-middle vulnerability
Numerous Tableau products are vulnerable to XXE via a malicious workbook, extension, or data source, leading to informat
The Kubernetes kube-apiserver mistakenly allows access to a cluster-scoped custom resource if the request is made as if
The EAP peer implementation in Espressif ESP-IDF 2.0.0 through 4.0.0 and ESP8266_NONOS_SDK 2.2.0 through 3.1.0 allows th
An issue was discovered in LibreNMS through 1.47. Several of the scripts perform dynamic script inclusion via the includ
An issue was discovered in LibreNMS 1.50.1. A SQL injection flaw was identified in the ajax_rulesuggest.php file where t
Scan for 2019 Vulnerabilities
CyberStrike detects these CVEs across your infrastructure automatically.
Get Started