17,305 vulnerabilities published in 2019
Lobby Track Desktop could allow a local attacker to obtain sensitive information, caused by an error in Reports while in
Lobby Track Desktop could allow a local attacker to bypass security restrictions, caused by an error in the find visitor
EasyLobby Solo could allow a local attacker to obtain sensitive information, caused by the storing of the social securit
Envoy Passport for Android and Envoy Passport for iPhone could allow a local attacker to obtain sensitive information, c
Envoy Passport for Android and Envoy Passport for iPhone could allow a local attacker to obtain sensitive information, c
Supportutils, before version 3.1-5.7.1, wrote data to static file /tmp/supp_log, allowing local attackers to overwrite f
Vulnerability in the Oracle VM VirtualBox component of Oracle Virtualization (subcomponent: Core). Supported versions th
cPanel before 71.9980.37 allows arbitrary file-unlink operations via the cPAddons moderation system (SEC-395).
In Vanilla before 2.6.4, a flaw exists within the getSingleIndex function of the AddonManager class. The issue results i
IBM API Connect 5.0.0.0, and 5.0.8.6 could could return sensitive information that could provide critical information as
Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: Security: Privileges). Supported vers
Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: Security: Privileges). Supported vers
cPanel before 78.0.2 reveals internal data to OpenID providers (SEC-415).
It was found that the Apache ActiveMQ client before 5.14.5 exposed a remote shutdown command in the ActiveMQConnection c
cPanel before 70.0.23 exposes Apache HTTP Server logs after creation of certain domains (SEC-406).
cPanel before 68.0.27 does not enforce ownership during addpkgext and delpkgext WHM API calls (SEC-324).
cPanel before 68.0.15 allows use of an unreserved e-mail address in DNS zone SOA records (SEC-306).
cPanel before 68.0.15 does not block a username of postmaster, which might allow reception of private e-mail (SEC-326).
cPanel before 68.0.15 does not have a sufficient list of reserved usernames (SEC-327).
cPanel before 68.0.15 does not block a username of ssl (SEC-328).
cPanel before 68.0.15 allows user accounts to be partially created with invalid username formats (SEC-334).
cPanel before 66.0.2 allows resellers to read other accounts' domain log files (SEC-288).
In cPanel before 62.0.17, addon domain conversion did not require a package for resellers (SEC-208).
cPanel before 62.0.17 does not properly recognize domain ownership during addition of parked domains to a mail configura
In Limesurvey before 3.17.14, admin users can mark other users' notifications as read.
In Limesurvey before 3.17.14, admin users can run an integrity check without proper permissions.
A vulnerability has been identified in SINEMA Remote Connect Server (All versions < V2.0 SP1). An attacker with administ
In SilverStripe through 4.3.3, there is access escalation for CMS users with limited access through permission cache pol
Vulnerability in the Oracle Retail Xstore Point of Service product of Oracle Retail Applications (component: Point of Sa
Vulnerability in the MySQL Server product of Oracle MySQL (component: Information Schema). Supported versions that are a
Moodle before 2.2.2 has a permission issue in Forum Subscriptions where unenrolled users can subscribe/unsubscribe via m
A cleartext password storage issue was discovered in Katello, versions 3.x.x.x before katello 3.12.0.9. Registry credent
An issue was discovered in GitLab Community and Enterprise Edition through 12.4. It has Insecure Permissions (issue 2 of
An issue was discovered in TitanHQ WebTitan before 5.18. It exposes a database configuration file under /include/dbconfi
Improper validation of URL redirection in the Kubernetes API server in versions prior to v1.14.0 allows an attacker-cont
In TensorFlow before 1.15, a heap buffer overflow in UnsortedSegmentSum can be produced when the Index template argument
Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Shell). Supported versions that are affected
GlobalProtect Agent 4.1.0 for Windows and GlobalProtect Agent 4.1.10 and earlier for macOS may allow a local authenticat
The Linux kernel through 5.0.7, when CONFIG_IA32_AOUT is enabled and ia32_aout is loaded, allows local users to bypass A
cPanel before 68.0.27 allows attackers to read root's crontab file during a short time interval upon configuring crontab
cPanel before 68.0.27 allows attackers to read root's crontab file during a short time interval upon a post-update task
cPanel before 68.0.15 allows attackers to read backup files because they are world-readable during a short time interval
cPanel before 67.9999.103 allows Apache HTTP Server log files to become world-readable because of mishandling on an acco
In cPanel before 66.0.2, the cpdavd_error_log file can be created with weak permissions (SEC-280).
In cPanel before 66.0.2, Apache HTTP Server domlogs become temporarily world-readable during log processing (SEC-290).
A password generation weakness exists in xquest through 2016-06-13.
A race condition existed when reading and writing user preferences. This was addressed with improved state handling. Thi
A logic issue was addressed with improved restrictions. This issue affected versions prior to iOS 12.
A lock screen issue allowed access to photos via Reply With Message on a locked device. This issue was addressed with im
A lock screen issue allowed access to contacts on a locked device. This issue was addressed with improved state manageme
Scan for 2019 Vulnerabilities
CyberStrike detects these CVEs across your infrastructure automatically.
Get Started