17,305 vulnerabilities published in 2019
PoDoFo::Impose::PdfTranslator::setSource() in pdftranslator.cpp in PoDoFo 0.9.6 has a NULL pointer dereference that can
A heap-based buffer underwrite exists in ImageStream::getLine() located at Stream.cc in Poppler 0.74.0 that can (for exa
In SkSwizzler::onSetSampleX of SkSwizzler.cpp, there is a possible out of bounds write due to a missing bounds check. Th
In sample6 of SkSwizzler.cpp, there is a possible out of bounds write due to improper input validation. This could lead
In btif_dm_data_copy of btif_core.cc, there is a possible out of bounds write due to a buffer overflow. This could lead
In refresh of DevelopmentTiles.java, there is the possibility of leaving development settings accessible due to an insec
Mozilla developers and community members reported memory safety bugs present in Firefox 62. Some of these bugs showed ev
Mozilla developers and community members reported memory safety bugs present in Firefox ESR 60.2. Some of these bugs sho
During HTTP Live Stream playback on Firefox for Android, audio data can be accessed across origins in violation of secur
Mozilla developers and community members reported memory safety bugs present in Firefox 63. Some of these bugs showed ev
When the RSS Feed preview about:feeds page is framed within another page, it can be used in concert with scripted conten
An issue was discovered in Poppler 0.74.0. A recursive function call, in JBIG2Stream::readGenericBitmap() located in JBI
An issue was discovered in Bento4 1.5.1-628. An out of bounds write occurs in AP4_CttsTableEntry::AP4_CttsTableEntry() l
An issue was discovered in Poppler 0.74.0. A recursive function call, in JBIG2Stream::readTextRegion() located in JBIG2S
An issue was discovered in PopojiCMS v2.0.1. It has CSRF via the po-admin/route.php?mod=user&act=addnew URI, as demonstr
An out-of-bounds read was addressed with improved input validation. This issue is fixed in iOS 12.1.3, macOS Mojave 10.1
A memory corruption issue was addressed with improved state management. This issue is fixed in iOS 12.1.3, macOS Mojave
Multiple memory corruption issues were addressed with improved memory handling. This issue is fixed in iOS 12.1.3, tvOS
A type confusion issue was addressed with improved memory handling. This issue is fixed in iOS 12.1.3, tvOS 12.1.2, Safa
Multiple memory corruption issues were addressed with improved memory handling. This issue is fixed in iOS 12.1.3, tvOS
Multiple memory corruption issues were addressed with improved memory handling. This issue is fixed in iOS 12.1.3, tvOS
A buffer overflow issue was addressed with improved memory handling. This issue is fixed in iOS 12.1.3, macOS Mojave 10.
Multiple memory corruption issues were addressed with improved memory handling. This issue is fixed in iOS 12.1.3, tvOS
A memory corruption issue was addressed with improved memory handling. This issue is fixed in iOS 12.1.3, tvOS 12.1.2, w
A memory corruption issue was addressed with improved memory handling. This issue is fixed in iOS 12.1.3, tvOS 12.1.2, S
A memory corruption issue was addressed with improved memory handling. This issue is fixed in iOS 12.1.3, tvOS 12.1.2, S
PSI GridConnect GmbH Telecontrol Gateway and Smart Telecontrol Unit family, IEC104 Security Proxy versions Telecontrol G
Cross-site request forgery has been identified in Moxa IKS and EDS, which may allow for the execution of unauthorized ac
The Alcatel Lucent I-240W-Q GPON ONT using firmware version 3FE54567BOZJ19 is vulnerable to command injection via crafte
The Alcatel Lucent I-240W-Q GPON ONT using firmware version 3FE54567BOZJ19 is vulnerable to authenticated command inject
The Alcatel Lucent I-240W-Q GPON ONT using firmware version 3FE54567BOZJ19 is vulnerable to a stack buffer overflow via
A remote code execution vulnerability exists in Microsoft SharePoint when the software fails to check the source markup
A remote code execution vulnerability exists in .NET Framework and Visual Studio software when the software fails to che
A remote code execution vulnerability exists in the way that the Windows Graphics Device Interface (GDI) handles objects
A remote code execution vulnerability exists in the way that the Microsoft Server Message Block 2.0 (SMBv2) server handl
A remote code execution vulnerability exists in the way that the Microsoft Server Message Block 2.0 (SMBv2) server handl
A remote code execution vulnerability exists in the way that the Windows Graphics Device Interface (GDI) handles objects
An elevation of privilege vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially c
phpscheduleit Booked Scheduler 2.7.5 allows arbitrary file upload via the Favicon field, leading to execution of arbitra
An issue was discovered in OFCMS before 1.1.3. Remote attackers can execute arbitrary code because blocking of .jsp and
An issue was discovered in OFCMS before 1.1.3. Remote attackers can execute arbitrary code because blocking of .jsp and
An issue was discovered in OFCMS before 1.1.3. Remote attackers can execute arbitrary code because blocking of .jsp and
An issue was discovered in OFCMS before 1.1.3. A command execution vulnerability exists via a template file with '<#assi
An issue was discovered in OFCMS before 1.1.3. Remote attackers can execute arbitrary code because blocking of .jsp and
JBMC DirectAdmin 1.55 allows CSRF via the /CMD_ACCOUNT_ADMIN URI to create a new admin account.
Cloud Foundry CLI, versions prior to v6.43.0, improperly exposes passwords when verbose/trace/debugging is turned on. A
Cloud Foundry Stratos, versions prior to 2.3.0, deploys with a public default session store secret. A malicious user wit
The domain management component of TIBCO Software Inc.'s TIBCO JasperReports Server, TIBCO JasperReports Server Communit
Simple Machines Forum (SMF) 2.0.4 allows local file inclusion, with resultant remote code execution, in install.php via
zzcms v8.3 has a SQL injection in /user/jobmanage.php via the bigclass parameter.
Scan for 2019 Vulnerabilities
CyberStrike detects these CVEs across your infrastructure automatically.
Get Started