17,305 vulnerabilities published in 2019
Vulnerability in the Oracle Payments component of Oracle E-Business Suite (subcomponent: File Transmission). Supported v
cPanel before 64.0.21 allows demo and suspended accounts to use SSH port forwarding (SEC-247).
A vulnerability in the packet filtering features of Cisco SD-WAN Solution could allow an unauthenticated, remote attacke
A vulnerability in the Secure Sockets Layer (SSL)/Transport Layer Security (TLS) protocol inspection engine of Cisco Fir
A denial of service vulnerability exists when Microsoft Hyper-V Network Switch on a host server fails to properly valida
A denial of service vulnerability exists when Microsoft Hyper-V Network Switch on a host server fails to properly valida
A denial of service vulnerability exists when Windows improperly handles objects in memory. An attacker who successfully
A denial of service vulnerability exists when Microsoft Hyper-V Network Switch on a host server fails to properly valida
A denial of service vulnerability exists when Microsoft Hyper-V Network Switch on a host server fails to properly valida
A denial of service vulnerability exists when Microsoft Hyper-V Network Switch on a host server fails to properly valida
A vulnerability in the file and malware inspection feature of Cisco Firepower Management Center (FMC) Software could all
Vulnerability in the Oracle Content Manager product of Oracle E-Business Suite (component: Content). Supported versions
A vulnerability in the stream reassembly component of Cisco Firepower Threat Defense Software, Cisco FirePOWER Services
A vulnerability in the normalization functionality of Cisco Firepower Threat Defense Software, Cisco FirePOWER Services
Medtronic Valleylab Exchange Client version 3.4 and below, Valleylab FT10 Energy Platform (VLFT10GEN) software version 4
In RubyGem excon before 0.71.0, there was a race condition around persistent connections, where a connection which is in
WordPress users with lower privileges (like contributors) can inject JavaScript code in the block editor using a specifi
In WordPress before 5.3.1, authenticated users with lower privileges (like contributors) can inject JavaScript code in t
It was found Ceph versions before 13.2.4 that authenticated ceph users with read only permissions could steal dm-crypt e
MyWebSQL 3.7 has a Cross-site request forgery (CSRF) vulnerability for deleting a database via the /?q=wrkfrm&type=datab
An issue was discovered in idreamsoft iCMS through 7.0.14. A CSRF vulnerability can delete users' articles via the publi
Ekiga versions before 3.3.0 attempted to load a module from /tmp/ekiga_test.so.
python-dbusmock before version 0.15.1 AddTemplate() D-Bus method call or DBusTestCase.spawn_server_template() method cou
A spoofing vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted web requ
A spoofing vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted web requ
An issue was discovered in GNOME gvfs 1.29.4 through 1.41.2. daemon/gvfsbackendadmin.c mishandles a file's user and grou
A potential improper access control vulnerability exists in the backup mechanism of the Bosch Smart Home Controller (SHC
Gemalto DS3 Authentication Server 2.6.1-SP01 allows Local File Disclosure.
Gemalto DS3 Authentication Server 2.6.1-SP01 has Broken Access Control.
The ABB IDAL FTP server is vulnerable to a buffer overflow when a long string is sent by an authenticated attacker. This
Use after free in Bluetooth in Google Chrome prior to 68.0.3440.75 allowed an attacker who convinced a user to install a
ZTE MW NR8000V2.4.4.03 and NR8000V2.4.4.04 are impacted by path traversal vulnerability. Due to path traversal,users can
Vulnerability in the Oracle FLEXCUBE Universal Banking component of Oracle Financial Services Applications (subcomponent
Vulnerability in the Oracle FLEXCUBE Investor Servicing component of Oracle Financial Services Applications (subcomponen
bin/csvprocess in cPanel before 68.0.27 allows insecure file operations (SEC-354).
The admin-renamer-extended (aka Admin renamer extended) plugin 3.2.1 for WordPress allows wp-admin/plugins.php?page=admi
The codection "Import users from CSV with meta" plugin before 1.14.2.2 for WordPress allows wp-admin/admin-ajax.php?acti
IBM Business Automation Workflow 18.0.0.0, 18.0.0.1, and 18.0.0.2 could allow a user to obtain highly sensitive informat
Libra Core before 2019-09-03 has an erroneous regular expression for inline comments, which makes it easier for attacker
Vulnerability in the Core RDBMS (jackson-databind) component of Oracle Database Server. Supported versions that are affe
Vulnerability in the Oracle FLEXCUBE Direct Banking product of Oracle Financial Services Applications (component: Paymen
A missing check on incoming client requests can be exploited to cause a situation where the Kea server's lease storage c
A security vulnerability exists in a management port in the version of ZTE's ZXMP M721V3.10P01B10_M2NCP. An attacker cou
A specially crafted Bitcoin script can cause a discrepancy between the specified SLP consensus rules and the validation
A specially crafted Bitcoin script can cause a discrepancy between the specified SLP consensus rules and the validation
The Huawei Share function of P20 phones with versions earlier than Emily-L29C 9.1.0.311 has an improper file management
This issue was addressed with improved transparency. This issue is fixed in iOS 12.2. A user may authorize an enterprise
An inconsistency in Wi-Fi network configuration settings was addressed. This issue is fixed in iOS 13.2 and iPadOS 13.2.
Vulnerability in the Oracle VM VirtualBox component of Oracle Virtualization (subcomponent: Core). Supported versions th
A prototype pollution vulnerability was found in lodash <4.17.11 where the functions merge, mergeWith, and defaultsDeep
Scan for 2019 Vulnerabilities
CyberStrike detects these CVEs across your infrastructure automatically.
Get Started