17,305 vulnerabilities published in 2019
Cordaware bestinformed Microsoft Windows client before 6.2.1.0 is affected by insecure SSL certificate verification and
In the GNU C Library (aka glibc or libc6) through 2.29, proceed_next_node in posix/regexec.c has a heap-based buffer ove
SQL injection vulnerability in the J2Store plugin 3.x before 3.3.7 for Joomla! allows remote attackers to execute arbitr
elFinder before 2.1.48 has a command injection vulnerability in the PHP connector.
util/src/zip.rs in Grin before 1.0.2 mishandles suspicious files. An attacker can execute arbitrary code via directory t
Multiple Phoenix Contact devices allow remote attackers to establish TCP sessions to port 1962 and obtain sensitive info
SOFA-Hessian through 4.0.2 allows remote attackers to execute arbitrary commands via a crafted serialized Hessian object
In Live555 before 2019.02.27, malformed headers lead to invalid memory access in the parseAuthorizationHeader function.
An issue was discovered in baigo CMS 2.1.1. There is a vulnerability that allows remote attackers to execute arbitrary c
Mozilla developers and community members reported memory safety bugs present in Firefox 62 and Firefox ESR 60.2. Some of
When manipulating user events in nested loops while opening a document through script, it is possible to trigger a poten
Mozilla developers and community members reported memory safety bugs present in Firefox 63 and Firefox ESR 60.3. Some of
A buffer overflow occurs when drawing and validating elements with the ANGLE graphics library, used for WebGL content, w
A use-after-free vulnerability can occur after deleting a selection element due to a weak reference to the select elemen
A buffer overflow can occur in the Skia library during buffer offset calculations with hardware accelerated canvas 2D ac
A potential vulnerability leading to an integer overflow can occur during buffer size calculations for images when a raw
A vulnerability in the web-based management interface of the Cisco RV110W Wireless-N VPN Firewall, Cisco RV130W Wireless
SolarWinds Orion Platform before 2018.4 Hotfix 2 allows privilege escalation through the RabbitMQ service.
Eloan V3.0 through 2018-09-20 allows remote attackers to list files via a direct request to the p2p/api/ or p2p/lib/ or
FlarumChina v0.1.0-beta.7C has SQL injection via a /?q= request.
An issue existed with autofill resuming after it was canceled. The issue was addressed with improved state management. T
UltraVNC revision 1198 has a buffer underflow vulnerability in VNC client code, which can potentially result in code exe
UltraVNC revision 1198 has a heap buffer overflow vulnerability in VNC client code which results code execution. This at
UltraVNC revision 1199 has a out-of-bounds read vulnerability in VNC client RRE decoder code, caused by multiplication o
UltraVNC revision 1199 has a out-of-bounds read vulnerability in VNC code inside client CoRRE decoder, caused by multipl
UltraVNC revision 1203 has multiple heap buffer overflow vulnerabilities in VNC client code inside Ultra decoder, which
IBM Financial Transaction Manager for Digital Payments for Multi-Platform 3.1.0 is vulnerable to SQL injection. A remote
Adobe Acrobat and Reader versions 2019.010.20069 and earlier, 2017.011.30113 and earlier version, and 2015.006.30464 and
Moxa IKS and EDS do not implement sufficient measures to prevent multiple failed authentication attempts, which may allo
Several buffer overflow vulnerabilities have been identified in Moxa IKS and EDS, which may allow remote code execution.
Moxa IKS and EDS generate a predictable cookie calculated with an MD5 hash, allowing an attacker to capture the administ
The Alcatel Lucent I-240W-Q GPON ONT using firmware version 3FE54567BOZJ19 contains multiple hard coded credentials for
The Alcatel Lucent I-240W-Q GPON ONT using firmware version 3FE54567BOZJ19 is vulnerable to a stack buffer overflow via
A remote code execution vulnerability exists in Microsoft SharePoint when the software fails to check the source markup
A memory corruption vulnerability exists in the Windows Server DHCP service when an attacker sends specially crafted pac
An Elevation of Privilege vulnerability exists in the way Azure IoT Java SDK generates symmetric keys for encryption, al
BlueCMS 1.6 allows SQL Injection via the user_id parameter in an uploads/admin/user.php?act=edit request.
Unauthenticated RCE is possible when JMeter is used in distributed mode (-r or -R command line options). Attacker can es
Feng Office 3.7.0.5 allows remote attackers to execute arbitrary code via "<!--#exec cmd=" in a .shtml file to ck_upload
PHPSHE 1.7 allows module/index/cart.php pintuan_id SQL Injection to index.php.
A heap-based overflow vulnerability exists in the PowerPoint document conversion function of Rainbow PDF Office Server D
In Apache Solr versions 5.0.0 to 5.5.5 and 6.0.0 to 6.6.5, the Config API allows to configure the JMX server via an HTTP
An issue was discovered in Dolibarr through 7.0.0. expensereport/card.php in the expense reports module allows SQL injec
zzcms v8.3 contains a SQL Injection vulnerability in /user/logincheck.php via an X-Forwarded-For HTTP header.
LayerBB 1.1.1 and 1.1.3 has SQL Injection via the search.php search_query parameter.
An issue was discovered on Motorola C1 and M2 devices with firmware 1.01 and 1.07 respectively. This issue is a Command
An issue was discovered on Motorola C1 and M2 devices with firmware 1.01 and 1.07 respectively. This issue is a Command
An issue was discovered on Motorola C1 and M2 devices with firmware 1.01 and 1.07 respectively. This issue is a Command
An issue was discovered on Motorola C1 and M2 devices with firmware 1.01 and 1.07 respectively. This issue is a Command
An issue was discovered on Motorola C1 and M2 devices with firmware 1.01 and 1.07 respectively. This issue is a Command
Scan for 2019 Vulnerabilities
CyberStrike detects these CVEs across your infrastructure automatically.
Get Started