17,305 vulnerabilities published in 2019
Improper permissions for Intel(R) USB 3.0 Creator Utility all versions may allow an authenticated user to potentially en
Improper permissions in the installer for Intel(R) Accelerated Storage Manager in Intel(R) RSTe before version 5.5.0.201
An issue was discovered in CapMon Access Manager 5.4.1.1005. CALRunElevated.exe provides "NT AUTHORITY\SYSTEM" access to
An issue was discovered in CapMon Access Manager 5.4.1.1005. An unprivileged user can read the cal_whitelist table in th
An issue was discovered in CapMon Access Manager 5.4.1.1005. The client applications of AccessManagerCoreService.exe com
An issue was discovered in CapMon Access Manager 5.4.1.1005. A regular user can obtain local administrator privileges if
In yast2-samba-provision up to and including version 1.0.1 the password for samba shares was provided on the command lin
Avast Free Antivirus prior to 19.1.2360 stores user credentials in memory upon login, which allows local users to obtain
KioWare Server version 4.9.6 and older installs by default to "C:\kioware_com" with weak folder permissions granting any
An issue where a provided address with access_ok() is not checked was discovered in i915_gem_execbuffer2_ioctl in driver
IBM DB2 for Linux, UNIX and Windows (includes DB2 Connect Server) 9.7, 10.1, 10.5, and 11.1 binaries load shared librari
In Artifex Ghostscript through 9.26, ephemeral or transient procedures can allow access to system operators, leading to
The barracudavpn component of the Barracuda VPN Client prior to version 5.0.2.7 for Linux, macOS, and OpenBSD runs as a
In QEMU 3.0.0, tcp_emu in slirp/tcp_subr.c has a heap-based buffer overflow.
The KVM implementation in the Linux kernel through 4.20.5 has a Use-after-Free.
An issue was discovered on Systrome Cumilon ISG-600C, ISG-600H, and ISG-800W devices with firmware V1.1-R2.1_TRUNK-20181
An authenticated shell command injection issue has been discovered in Raisecom ISCOM HT803G-U, HT803G-W, HT803G-1GE, and
An authenticated shell command injection issue has been discovered in Raisecom ISCOM HT803G-U, HT803G-W, HT803G-1GE, and
There is an invalid memory access vulnerability in the function TextPage::findGaps() located at TextOutputDev.c in Xpdf
There is an invalid memory access in the function GfxIndexedColorSpace::mapColorToBase() located in GfxState.cc in Xpdf
In PuTTY versions before 0.71 on Windows, local attackers could hijack the application by putting a malicious help file
An exploitable vulnerability exists in the verified boot protection of the CUJO Smart Firewall. It is possible to add ar
Opera before 57.0.3098.106 is vulnerable to a DLL Search Order hijacking attack where an attacker can send a ZIP archive
rbash in Bash before 4.4-beta2 did not prevent the shell user from modifying BASH_CMDS, thus allowing the user to execut
XnView MP 0.93.1 on Windows allows remote attackers to cause a denial of service (application crash) or possibly have un
XnView MP 0.93.1 on Windows allows remote attackers to cause a denial of service (application crash) or possibly have un
XnView MP 0.93.1 on Windows allows remote attackers to cause a denial of service (application crash) or possibly have un
XnView MP 0.93.1 on Windows allows remote attackers to cause a denial of service (application crash) or possibly have un
XnView Classic 2.48 on Windows allows remote attackers to cause a denial of service (application crash) or possibly have
XnView Classic 2.48 on Windows allows remote attackers to cause a denial of service (application crash) or possibly have
XnView Classic 2.48 on Windows allows remote attackers to cause a denial of service (application crash) or possibly have
XnView Classic 2.48 on Windows allows remote attackers to cause a denial of service (application crash) or possibly have
Mitigates a remote code execution issue in ArcSight Logger versions prior to 6.7.
It was found that libreoffice before versions 6.0.7 and 6.1.3 was vulnerable to a directory traversal attack which could
A specially crafted configuration file could be used to cause a stack-based buffer overflow condition in the OPCTest.exe
A specifically crafted Docker image running under the root user can overwrite the init helper binary of the container ru
A vulnerability was found in ceilometer before version 12.0.0.0rc1. An Information Exposure in ceilometer-agent prints s
Opening a specially crafted LCDS LAquis SCADA before 4.3.1.71 ELS file may result in a write past the end of an allocate
Improper configuration in system firmware for EDK II may allow unauthenticated user to potentially enable escalation of
Logic issue in variable service module for EDK II/UDK2018/UDK2017/UDK2015 may allow an authenticated user to potentially
A vulnerability in Cisco IOS XE Software could allow an authenticated, local attacker to inject arbitrary commands that
A vulnerability in Jenkins PRQA Plugin 3.1.0 and earlier allows attackers with local file system access to the Jenkins h
Privilege escalation in Nagios XI before 5.5.11 allows local attackers to elevate privileges to root via write access to
An exploitable local privilege escalation vulnerability exists in the privileged helper tool of GOG Galaxy's Games, vers
In the Linux Kernel before versions 4.20.8 and 4.19.21 a use-after-free error in the "sctp_sendmsg()" function (net/sctp
An exploitable local privilege elevation vulnerability exists in the file system permissions of GOG Galaxy's install dir
An exploitable local privilege elevation vulnerability exists in the file system permissions of GOG Galaxy's “Games” dir
IBM DB2 for Linux, UNIX and Windows (includes DB2 Connect Server) 9.7, 10.1, 10.5, and 11.1 is vulnerable to a buffer ov
A configuration issue was addressed with additional restrictions. This issue affected versions prior to macOS X El Capit
A memory corruption issue was addressed with improved memory handling. This issue affected versions prior to iOS 12, mac
Scan for 2019 Vulnerabilities
CyberStrike detects these CVEs across your infrastructure automatically.
Get Started