17,305 vulnerabilities published in 2019
A vulnerability in Cisco NX-OS Software and Cisco IOS XE Software could allow an authenticated, local attacker with vali
A vulnerability in the Guest Shell of Cisco IOS XE Software could allow an authenticated, local attacker to perform dire
A vulnerability in the filesystem of Cisco IOS XE Software could allow an authenticated, local attacker within the IOx G
A vulnerability in a CLI command related to the virtualization manager (VMAN) in Cisco IOS XR Software for Cisco ASR 900
In the Bluetooth stack, there is a possible out of bounds write due to a use after free. This could lead to local escala
In sensorservice, there is a possible out of bounds write due to a missing bounds check. This could lead to local escala
In LockPatternUtils, there is a possible escalation of privilege due to an improper permissions check. This could lead t
A vulnerability in the command line interface (CLI) of Cisco Firepower Threat Defense (FTD) Software could allow an auth
Avira Software Updater before 2.0.6.21094 allows a DLL side-loading attack. NOTE: The vendor thinks that this vulnerabil
An issue was discovered in Kaseya VSA RMM through 9.5.0.22. When using the default configuration, the LAN Cache feature
A potential security vulnerability has been identified with certain versions of HP Touchpoint Analytics prior to version
A vulnerability in the CLI of Cisco TelePresence Collaboration Endpoint (CE) Software could allow an authenticated, loca
A vulnerability in the CLI of Cisco TelePresence Collaboration Endpoint (CE) Software could allow an authenticated, loca
A vulnerability in the CLI of Cisco TelePresence Collaboration Endpoint (CE) Software could allow an authenticated, loca
A DLL side loading vulnerability in the Windows Service in TeamViewer versions up to 11.0.133222 (fixed in 11.0.214397),
In createSessionInternal of PackageInstallerService.java, there is a possible permissions bypass. This could lead to loc
In the Bootloader, there is a possible kernel command injection due to missing command sanitization. This could lead to
Insufficient access control in system firmware for Intel(R) Xeon(R) Scalable Processors, 2nd Generation Intel(R) Xeon(R)
Insufficient access control in firmware for Intel(R) Ethernet 700 Series Controllers before version 7.0 may allow a priv
Insufficient memory protection in Intel(R) TXT for certain Intel(R) Core Processors and Intel(R) Xeon(R) Processors may
Insufficient memory protection in System Management Mode (SMM) and Intel(R) TXT for certain Intel(R) Xeon(R) Processors
The AX.25 daemon (ax25d) in ax25-tools before 0.0.8-13 does not check the return value of a setuid call. The setuid call
Symantec Endpoint Protection, prior to 14.2 RU2, may be susceptible to an unsigned code execution vulnerability, which m
NVIDIA NVFlash, NVUFlash Tool prior to v5.588.0 and GPUModeSwitch Tool prior to 2019-11, NVIDIA kernel mode driver (nvfl
A vulnerability in the CLI of Cisco Unity Express could allow an authenticated, local attacker to inject arbitrary comma
A vulnerability in Cisco DNA Spaces: Connector could allow an authenticated, local attacker to elevate privileges and ex
A vulnerability in Cisco DNA Spaces: Connector could allow an authenticated, local attacker to perform a command injecti
Kaspersky Secure Connection, Kaspersky Internet Security, Kaspersky Total Security, Kaspersky Security Cloud prior to ve
In the Linux kernel 5.3.10, there is a use-after-free (read) in the perf_trace_lock_acquire function (related to include
In Apache SpamAssassin before 3.4.3, nefarious CF files can be configured to run system commands without any output or e
Improper conditions check in voltage settings for some Intel(R) Processors may allow a privileged user to potentially en
Improper input validation in firmware for Intel(R) NUC(R) may allow a privileged user to potentially enable escalation o
Integer overflow in firmware for Intel(R) NUC(R) may allow a privileged user to potentially enable escalation of privile
Out of bounds write in firmware for Intel(R) NUC(R) may allow a privileged user to potentially enable escalation of priv
Insufficient input validation in the subsystem for Intel(R) CSME before versions 11.8.70, 11.11.70, 11.22.70, 12.0.45, 1
Logic issue in subsystem for Intel(R) CSME before versions 12.0.45, 13.0.10 and 14.0.10 may allow a privileged user to p
Insufficient session validation in the subsystem for Intel(R) CSME before versions 11.8.70, 12.0.45, 13.0.10 and 14.0.10
Insufficient input validation in subsystem for Intel(R) CSME before versions 12.0.45 and 13.0.10 may allow a privileged
Authentication bypass in the subsystem for Intel(R) CSME before versions 11.8.70, 11.11.70, 11.22.70, 12.0.45, 13.0.10 a
When processing project files, the application (Omron CX-Programmer v9.70 and prior and Common Components January 2019 a
Vulnerability in the RDBMS DataPump component of Oracle Database Server. Supported versions that are affected are 11.2.0
The Simple - Better Banking application 2.45.0 through 2.45.3 (fixed in 2.46.0) for Android was affected by an informati
An issue was discovered in MISP 2.4.108. Organization admins could reset credentials for site admins (organization admin
OnApp before 5.0.0-88, 5.5.0-93, and 6.0.0-196 allows an attacker to run arbitrary commands with root privileges on serv
An out-of-bounds read vulnerability has been identified in Fuji Electric Alpha7 PC Loader Versions 1.1 and prior, which
A vulnerability in Cisco Small Business SPA500 Series IP Phones could allow a physically proximate attacker to execute a
In Valve Steam Client for Windows through 2019-08-07, HKLM\SOFTWARE\Wow6432Node\Valve\Steam has explicit "Full control"
A vulnerability has been identified in SCALANCE SC-600 (V2.0). An authenticated attacker with access to port 22/tcp as w
On STMicroelectronics STM32F7 devices, Proprietary Code Read Out Protection (PCROP) (a software IP protection method) ca
On NXP Kinetis KV1x, Kinetis KV3x, and Kinetis K8x devices, Flash Access Controls (FAC) (a software IP protection method
Scan for 2019 Vulnerabilities
CyberStrike detects these CVEs across your infrastructure automatically.
Get Started