17,305 vulnerabilities published in 2019
A remote code execution vulnerability exists when the Windows Jet Database Engine improperly handles objects in memory,
An elevation of privilege vulnerability exists when the Windows AppX Deployment Server improperly handles junctions.To e
An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properly handle objects in
A security feature bypass vulnerability exists when Microsoft Office improperly handles input, aka 'Microsoft Office Sec
An elevation of privilege vulnerability exists in Microsoft Compatibility Appraiser where a configuration file, with loc
An elevation of privilege exists when Winlogon does not properly handle file path information, aka 'Winlogon Elevation o
An elevation of privilege vulnerability exists when Windows improperly handles calls to Advanced Local Procedure Call (A
An elevation of privilege exists in hdAudio.sys which may lead to an out of band write, aka 'Windows Media Elevation of
An elevation of privilege vulnerability exists when Windows improperly handles calls to Advanced Local Procedure Call (A
An elevation of privilege vulnerability exists in Windows Audio Service when a malformed parameter is processed, aka 'Wi
An elevation of privilege vulnerability exists in the way that the unistore.dll handles objects in memory, aka 'Windows
A remote code execution vulnerability exists in Microsoft Windows that could allow remote code execution if a .LNK file
An elevation of privilege vulnerability exists when DirectX improperly handles objects in memory, aka 'DirectX Elevation
An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properly handle objects in
An elevation of privilege vulnerability exists in the way that the Windows Network Connectivity Assistant handles object
An elevation of privilege vulnerability exists when the Windows AppX Deployment Server improperly handles junctions.To e
Prior to 0.1, AIX builds of Eclipse OMR contain unused RPATHs which may facilitate code injection and privilege elevatio
Adobe application manager installer version 10.0 have an Insecure Library Loading (DLL hijacking) vulnerability. Success
PicoC 2.1 has a heap-based buffer overflow in StringStrcpy in cstdlib/string.c when called from ExpressionParseFunctionC
Privileges manipulation in Micro Focus Data Protector, versions 10.00, 10.01, 10.02, 10.03, 10.04, 10.10, 10.20, 10.30,
SciLexer.dll in Scintilla in Notepad++ (x64) before 7.7 allows remote code execution or denial of service via Unicode ch
A buffer overflow flaw was found, in versions from 2.6.34 to 5.2.x, in the way Linux kernel's vhost functionality that t
A CWE-426: Untrusted Search Path vulnerability exists in SoMachine HVAC v2.4.1 and earlier versions, which could cause a
GnuCOBOL 2.2 has a stack-based buffer overflow in the cb_name() function in cobc/tree.c via crafted COBOL source code.
GnuCOBOL 2.2 has a use-after-free in the end_scope_of_program_name() function in cobc/parser.y via crafted COBOL source
Integer overflow vulnerability in LINE(Android) from 4.4.0 to the version before 9.15.1 allows remote attackers to cause
There is heap-based buffer overflow in Linux kernel, all versions up to, excluding 5.3, in the marvell wifi chip driver
There is heap-based buffer overflow in kernel, all versions up to, excluding 5.3, in the marvell wifi chip driver in Lin
In radare2 before 3.9.0, a command injection vulnerability exists in bin_symbols() in libr/core/cbin.c. By using a craft
Red Lion Controls Crimson, version 3.0 and prior and version 3.1 prior to release 3112.00, allow multiple vulnerabilitie
Red Lion Controls Crimson, version 3.0 and prior and version 3.1 prior to release 3112.00, allow multiple vulnerabilitie
Red Lion Controls Crimson, version 3.0 and prior and version 3.1 prior to release 3112.00, allow multiple vulnerabilitie
pam-python before 1.0.7-1 has an issue in regard to the default environment variable handling of Python, which could all
In Total Defense Anti-virus 9.0.0.773, insecure access control for the directory %PROGRAMDATA%\TotalDefense\Consumer\ISS
In Total Defense Anti-virus 9.0.0.773, insecure access control for the directory %PROGRAMDATA%\TotalDefense\Consumer\ISS
In Total Defense Anti-virus 9.0.0.773, resource acquisition from the untrusted search path C:\ used by caschelp.exe allo
In Rockwell Automation Arena Simulation Software Cat. 9502-Ax, Versions 16.00.00 and earlier, a maliciously crafted Aren
In IrfanView 4.53, Data from a Faulting Address controls a subsequent Write Address starting at image00400000+0x00000000
A vulnerability in the CLI of Cisco IOS XE Software could allow an authenticated, local attacker to gain shell access on
A vulnerability in a CLI command related to the virtualization manager (VMAN) in Cisco NX-OS Software could allow an aut
The Text-to-speech Engine (aka SamsungTTS) application before 3.0.02.7 and 3.0.00.101 for Android allows a local attacke
The Netskope client service, v57 before 57.2.0.219 and v60 before 60.2.0.214, running with NT\SYSTEM privilege, accepts
The Netskope client service, v57 before 57.2.0.219 and v60 before 60.2.0.214, running with NT\SYSTEM privilege, accepts
The "CLink4Service" service is installed with Corsair Link 4.9.7.35 with insecure permissions by default. This allows un
LibreOffice documents can contain macros. The execution of those macros is controlled by the document security settings,
The Firefox installer allows Firefox to be installed to a custom user writable location, leaving it unprotected from man
In Platform, there is a possible bypass of user interaction requirements due to missing permission checks. This could le
In Bluetooth, there is a possible out of bounds write due to an integer overflow. This could lead to local escalation of
In wifilogd, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation
In telephony, there is a possible bypass of user interaction requirements due to missing permission checks. This could l
Scan for 2019 Vulnerabilities
CyberStrike detects these CVEs across your infrastructure automatically.
Get Started