17,305 vulnerabilities published in 2019
Diagnostics Agent in Solution Manager, version 7.2, stores several credentials such as SLD user connection as well as So
Vulnerability in the Oracle Hyperion Workspace component of Oracle Hyperion (subcomponent: UI and Visualization). The su
Bypass lock protection in the Nextcloud Android app prior to version 3.6.2 causes leaking of thumbnails when requesting
On Ledger Nano S and Nano X devices, a side channel for the row-based OLED display was found. The power consumption of e
On ShapeShift KeepKey devices, a side channel for the row-based OLED display was found. The power consumption of each ro
On Mooltipass Mini devices, a side channel for the row-based OLED display was found. The power consumption of each row-b
On BC Vault devices, a side channel for the row-based SSD1309 OLED display was found. The power consumption of each row-
RSA BSAFE Micro Edition Suite versions prior to 4.4 (in 4.0.x, 4.1.x, 4.2.x and 4.3.x) are vulnerable to a Heap-based Bu
IBM Maximo Anywhere 7.6.0, 7.6.1, 7.6.2, and 7.6.3 does not have device root detection which could result in an attacker
Vulnerability in the Oracle JDeveloper and ADF product of Oracle Fusion Middleware (component: OAM). Supported versions
Information Leakage in PPPoE Packet Padding in AVM Fritz!Box 7490 with Firmware versions Fritz!OS 6.80 and 6.83 allows p
gdm3 3.14.2 and possibly later has an information leak before screen lock
Honor play smartphones with versions earlier than Cornell-AL00A 9.1.0.321(C00E320R1P1T8) have an insufficient authentica
Mate 20 RS smartphones with versions earlier than 9.1.0.135(C786E133R3P1) have an improper authorization vulnerability.
In the Linux kernel before 5.3.4, there is an info-leak bug that can be caused by a malicious USB device in the drivers/
In the Linux kernel before 5.3.11, there is an info-leak bug that can be caused by a malicious USB device in the drivers
An issue existed where partially entered passcodes may not clear when the device went to sleep. This issue was addressed
A logic issue was addressed with improved restrictions. This issue is fixed in iOS 12.3. A person with physical access t
The issue was addressed with improved UI handling. This issue is fixed in iOS 12.4, watchOS 5.3. A user may inadvertentl
The issue was addressed by restricting options offered on a locked device. This issue is fixed in iOS 13. A person with
The issue was addressed by restricting options offered on a locked device. This issue is fixed in iOS 13.1 and iPadOS 13
Insufficient access control in Kernel Mode Driver in Intel(R) Graphics Driver for Windows* before versions 10.18.x.5059
OpenShift Container Platform before version 4.1.3 writes OAuth tokens in plaintext to the audit logs for the Kubernetes
cPanel before 74.0.0 allows file-rename operations during account renames (SEC-442).
In the Android kernel in the video driver there is a kernel pointer leak due to a WARN_ON statement. This could lead to
Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). Supported versions that ar
Vulnerability in the Core RDBMS component of Oracle Database Server. Supported versions that are affected are 12.1.0.2,
IBM Cloud Orchestrator 2.4 through 2.4.0.5 and 2.5 through 2.5.0.9 contain APIs that could be used by a local user to se
Symantec Endpoint Protection (SEP), prior to 14.2 RU2 may be susceptible to a password protection bypass vulnerability w
In supportutils, before version 3.1-5.7.1 and if pacemaker is installed on the system, an unprivileged user could have o
In yast2-multipath before version 4.1.1 a static temporary filename allows local attackers to overwrite files on systems
Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: InnoDB). Supported versions that are affected
Postgresql, versions 11.x before 11.5, is vulnerable to a memory disclosure in cross-type comparison for hashed subplan.
A potential security vulnerability caused by incomplete obfuscation of application configuration information was discove
IBM Maximo Asset Management 7.6 could allow a physical user of the system to obtain sensitive information from a previou
A vulnerability in generate_filestorage_key of Ubuntu MAAS allows an attacker to brute-force filenames. This issue affec
All versions of unity-scope-gdrive logs search terms to syslog.
cPanel before 68.0.15 allows collisions because PostgreSQL databases can be assigned to multiple accounts (SEC-325).
A malicious webview could install long-lived unload handlers that re-use an incognito BrowserContext that is queued for
Vulnerability in the Oracle Solaris product of Oracle Systems (component: LDAP Library). The supported version that is a
In all versions of Unity8 a running but not active application on a large-screen device could talk with Maliit and consu
lmp_print_data_link_subobjs() in print-lmp.c in tcpdump before 4.9.3 lacks certain bounds checks.
Scan for 2019 Vulnerabilities
CyberStrike detects these CVEs across your infrastructure automatically.
Get Started