17,305 vulnerabilities published in 2019
A remote code execution vulnerability exists when the Microsoft XML Core Services MSXML parser processes user input, aka
A remote code execution vulnerability exists when the Microsoft XML Core Services MSXML parser processes user input, aka
A remote code execution vulnerability exists when the Microsoft XML Core Services MSXML parser processes user input, aka
A remote code execution vulnerability exists when the Microsoft XML Core Services MSXML parser processes user input, aka
A remote code execution vulnerability exists when OLE automation improperly handles objects in memory, aka 'OLE Automati
A remote code execution vulnerability exists when the Microsoft XML Core Services MSXML parser processes user input, aka
A remote code execution vulnerability exists in the way that the VBScript engine handles objects in memory, aka 'Windows
A remote code execution vulnerability exists when the IOleCvt interface renders ASP webpage content, aka 'Windows IOleCv
A remote code execution vulnerability exists in the way that the Windows Graphics Device Interface (GDI) handles objects
An issue was discovered in Rancher 2 through 2.1.5. Any project member with access to the default namespace can mount th
In Ubiquiti Networks EdgeSwitch X v1.1.0 and prior, a privileged user can execute arbitrary shell commands over the SSH
In Ubiquiti Networks EdgeSwitch X v1.1.0 and prior, an authenticated user can execute arbitrary shell commands over the
A number of HTTP endpoints in the Airflow webserver (both RBAC and classic) did not have adequate protection and were vu
Kentico CMS before 11.0.45 allows unrestricted upload of a file with a dangerous type.
ABAP BASIS function modules INST_CREATE_R3_RFC_DEST, INST_CREATE_TCPIP_RFCDEST, and INST_CREATE_TCPIP_RFC_DEST in SAP BA
SPIP 3.1 before 3.1.10 and 3.2 before 3.2.4 allows authenticated visitors to execute arbitrary code on the host server b
FastAdmin V1.0.0.20190111_beta has a CSRF vulnerability to add a new admin user via the admin/auth/admin/add?dialog=1 UR
MKCMS V5.0 has a CSRF vulnerability to add a new admin user via the ucenter/userinfo.php URI.
UiPath Orchestrator through 2018.2.4 allows any authenticated user to change the information of arbitrary users (even ad
The Boa server configuration on DASAN H660RM devices with firmware 1.03-0022 logs POST data to the /tmp/boa-temp file, w
An issue was discovered in CMS Made Simple 2.2.8. In the module FrontEndUsers (in the file class.FrontEndUsersManipulate
An issue was discovered in the firewall3 component in Inteno IOPSYS 1.0 through 3.16. The attacker must make a JSON-RPC
AVEVA Wonderware System Platform 2017 Update 2 and prior uses an ArchestrA network user account for authentication of sy
Heap-based Buffer Overflow in Graphite2 library in Firefox before 54 in lz4::decompress function.
Subrion CMS 4.1.5 has CSRF in blog/delete/.
Heap-based Buffer Overflow write in Graphite2 library in Firefox before 54 in lz4::decompress src/Decompressor.
Use of uninitialized memory in Graphite2 library in Firefox before 54 in graphite2::GlyphCache::Loader::read_glyph funct
models/repo_mirror.go in Gitea before 1.7.6 and 1.8.x before 1.8-RC3 mishandles mirror repo URL settings, leading to rem
The WP Fastest Cache plugin 0.8.8.5 for WordPress has CSRF via the wp-admin/admin.php wpfastestcacheoptions page.
There is a CSRF vulnerability in the mndpsingh287 File Manager plugin 3.0 for WordPress via the page=wp_file_manager_roo
A vulnerability has been identified in SINEMA Remote Connect Server (All versions < V2.0). Due to insufficient checking
Contao 4.7 allows CSRF.
A vulnerability in the web-based management interface of Cisco Wireless LAN Controller (WLC) Software could allow an una
A missing permission check in Jenkins GitLab Plugin 1.5.11 and earlier in the GitLabConnectionConfig#doTestConnection fo
Jenkins jira-ext Plugin 0.8 and earlier stored credentials unencrypted in its global configuration file on the Jenkins m
Jenkins Azure PublisherSettings Credentials Plugin 1.2 and earlier stored credentials unencrypted in the credentials.xml
Confluence Server and Data Center had a path traversal vulnerability in the downloadallattachments resource. A remote at
Dell SupportAssist Client versions prior to 3.2.0.90 contain an improper origin validation vulnerability. An unauthentic
MKCMS 5.0 allows remote attackers to take over arbitrary user accounts by posting a username and e-mail address to ucent
libavcodec/hevcdec.c in FFmpeg 3.4 and 4.1.2 mishandles detection of duplicate first slices, which allows remote attacke
The studio profile decoder in libavcodec/mpeg4videodec.c in FFmpeg 4.0 before 4.0.4 and 4.1 before 4.1.2 allows remote a
In floor0_inverse1 of floor0.c, there is a possible out of bounds write due to an incorrect bounds check. This could lea
In numerous hand-crafted functions in libmpeg2, NEON registers are not preserved. This could lead to remote code executi
In btm_proc_smp_cback of tm_ble.cc, there is a possible memory corruption due to a use after free. This could lead to re
TeamSpeak 3 Client before 3.2.5 allows remote code execution in the Qt framework.
74CMS v5.0.1 has a CSRF vulnerability to add a new admin user via the index.php?m=Admin&c=admin&a=add URI.
wcms/wex/finder/action.php in WCMS v0.3.2 has a Arbitrary File Upload Vulnerability via developer/finder because .php is
An issue was discovered in ProjectSend r1053. upload-process-form.php allows finished_files[]=../ directory traversal. I
An issue was discovered on Intelbras IWR 3000N 1.5.0 devices. When the administrator password is changed from a certain
A CSRF issue was discovered on Intelbras IWR 3000N 1.5.0 devices, leading to complete control of the router, as demonstr
Scan for 2019 Vulnerabilities
CyberStrike detects these CVEs across your infrastructure automatically.
Get Started