17,305 vulnerabilities published in 2019
TTLock devices do not properly restrict password-reset attempts, leading to incorrect access control and disclosure of s
Reflected Cross Site Scripting vulnerability in Administrators web console in McAfee Web Gateway (MWG) 7.8.x prior to 7.
The kama-clic-counter plugin 3.4.9 for WordPress has SQL injection via the admin.php order parameter.
The Post Indexer plugin before 3.0.6.2 for WordPress has incorrect handling of data passed to the unserialize function.
Cloud Foundry NFS Volume Service, 1.7.x versions prior to 1.7.11 and 2.x versions prior to 2.3.0, is vulnerable to LDAP
Multiple classes used within Apereo CAS before release 6.1.0-RC5 makes use of apache commons-lang3 RandomStringUtils for
The buddypress-activity-plus plugin before 1.6.2 for WordPress has CSRF with resultant directory traversal via the wp-ad
Certain NETGEAR devices allow remote attackers to disable all authentication requirements by visiting genieDisableLanCha
Dell EMC Avamar Server versions 7.4.1, 7.5.0, 7.5.1, 18.2 and 19.1 and Dell EMC Integrated Data Protection Appliance (ID
LZ4 before 1.9.2 has a heap-based buffer overflow in LZ4_write32 (related to LZ4_compress_destSize), affecting applicati
OX App Suite through 7.10.2 has Insecure Permissions.
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Console). Supported versions
Vulnerability in the Oracle Hospitality Reporting and Analytics component of Oracle Food and Beverage Applications. The
Vulnerability in the Oracle Hospitality Reporting and Analytics component of Oracle Food and Beverage Applications. The
Adobe Acrobat and Reader versions , 2019.012.20040 and earlier, 2017.011.30148 and earlier, 2017.011.30148 and earlier,
In libssh2 v1.9.0 and earlier versions, the SSH_MSG_DISCONNECT logic in packet.c has an integer overflow in a bounds che
A cross-site request forgery vulnerability in Jenkins Dynatrace Application Monitoring Plugin 2.1.3 and earlier allowed
An XML external entities (XXE) vulnerability in Jenkins 360 FireLine Plugin allows attackers with Overall/Read access to
php-symfony2-Validator has loss of information during serialization
I race condition in Temp files was found in gs-gpl before 8.56 addons scripts.
One Identity Cloud Access Manager before 8.1.4 Hotfix 1 allows OTP bypass via vectors involving a man in the middle, the
archivemail 0.6.2 uses temporary files insecurely leading to a possible race condition.
Possible use after free issue due to race condition while attempting to mark the entry pages as dirty using function set
dtc-xen 0.5.x before 0.5.4 suffers from a race condition where an attacker could potentially get a bash access as xenXX
A security feature bypass vulnerability exists when Windows Netlogon improperly handles a secure communications channel,
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') in McAfee Advanced Threat Defense (
Stack overflow in Intel(R) Baseboard Management Controller firmware may allow an authenticated user to potentially enabl
The Tecno Camon iClick Android device with a build fingerprint of TECNO/H633/TECNO-IN6:8.1.0/O11019/A-180409V96:user/rel
The Coolpad 1851 Android device with a build fingerprint of Coolpad/android/android:8.1.0/O11019/1534834761:userdebug/re
The Haier A6 Android device with a build fingerprint of Haier/A6/A6:8.1.0/O11019/1534219877:userdebug/release-keys conta
The network protocol of Blade Shadow though 2.13.3 allows remote attackers to take control of a Shadow instance and exec
An issue was discovered in Symfony 2.8.0 through 2.8.50, 3.4.0 through 3.4.34, 4.2.0 through 4.2.11, and 4.3.0 through 4
Out of bounds read in Skia in Google Chrome prior to 75.0.3770.80 allowed a remote attacker to obtain potentially sensit
Out of bounds read in SwiftShader in Google Chrome prior to 77.0.3865.75 allowed a remote attacker to obtain potentially
Ruby through 2.4.7, 2.5.x through 2.5.6, and 2.6.x through 2.6.4 allows code injection if the first argument (aka the "c
PEGA Platform 8.3.0 is vulnerable to a direct prweb/sso/random_token/!STANDARD?pyActivity=Data-Admin-DB-Name.DBSchema_Li
An issue was discovered in dhclient 4.3.1-6 due to an embedded path variable.
Some Huawei home routers have an input validation vulnerability. Due to input parameter is not correctly verified, an at
An issue was discovered in TitanHQ WebTitan before 5.18. The appliance has a hard-coded root password set during install
OpenShift cartridge allows remote URL retrieval
SaltStack RSA Key Generation allows remote users to decrypt communications
Race condition between the camera functions due to lack of resource lock which will lead to memory corruption and UAF is
Cacti through 1.2.7 is affected by multiple instances of lib/functions.php unsafe deserialization of user-controlled dat
A vulnerability has been identified in XHQ (All versions < V6.0.0.2). The web interface could allow a Cross-Site Request
An exploitable heap underflow vulnerability exists in the derive_taps_and_gains function in kdu_v7ar.dll of Kakadu Softw
Unencrypted HTTP communications for firmware upgrades in Petalk AI and PF-103 allow man-in-the-middle attackers to run a
eDeploy has tmp file race condition flaws
In Omron PLC CJ series, all versions, and Omron PLC CS series, all versions, an attacker could monitor traffic between t
Barco ClickShare Button R9861500D01 devices before 1.9.0 have incorrect Credentials Management. The ClickShare Button im
Jenkins Maven Release Plugin 0.16.1 and earlier does not configure the XML parser to prevent XML external entity (XXE) a
Scan for 2019 Vulnerabilities
CyberStrike detects these CVEs across your infrastructure automatically.
Get Started