17,305 vulnerabilities published in 2019
An elevation of privilege vulnerability exists in Windows 10 Update Assistant in the way it handles permissions.A locall
The web application portal of the Cobham EXPLORER 710, firmware version 1.07, sends the login password in cleartext. Thi
The Cobham EXPLORER 710, firmware version 1.07, does not validate its firmware image. Development scripts left in the fi
Insufficient path checking in the installer for Intel(R) Active System Console before version 8.0 Build 24 may allow an
Improper file permission in software installer for Intel(R) Smart Connect Technology for Intel(R) NUC may allow an authe
Pointer corruption in system firmware for Intel(R) NUC may allow a privileged user to potentially enable escalation of p
Memory corruption in system firmware for Intel(R) NUC may allow a privileged user to potentially enable escalation of pr
In the default privileges of NFC, there is a possible local bypass of user interaction requirements on package installat
In startActivityMayWait of ActivityStarter.java, there is a possible incorrect Activity launch due to an incorrect permi
A use-after-free in binder.c allows an elevation of privilege from an application to the Linux Kernel. No user interacti
An issue was discovered in Bento4 1.5.1.0. There is a heap-based buffer over-read in AP4_CencSampleEncryption::DoInspect
An issue was discovered in Bento4 1.5.1.0. There is a heap-based buffer over-read in AP4_PrintInspector::AddField in Cor
CloudCTI HIP Integrator Recognition Configuration Tool allows privilege escalation via its EXQUISE integration. This too
ESET Cyber Security 6.7.900.0 for macOS allows a local attacker to execute unauthorized commands as root by abusing an u
An issue was discovered in BMC Patrol Agent 9.0.10i. Weak execution permissions on the best1collect.exe SUID binary coul
An issue was discovered in BMC Patrol Agent 9.0.10i. Weak execution permissions on the PatrolAgent SUID binary could all
Ubisoft Uplay 92.0.0.6280 has Insecure Permissions.
"" In X.Org X Server 1.20.4, there is a stack-based buffer overflow in the function XQueryKeymap. For example, by sendin
IBM Workload Scheduler Distributed 9.2, 9.3, 9.4, and 9.5 contains a vulnerability that could allow a local user to writ
Jenkins Delphix Plugin stores credentials unencrypted in its global configuration file on the Jenkins master where they
NSA Ghidra through 9.0.4 uses a potentially untrusted search path. When executing Ghidra from a given path, the Java pro
NSA Ghidra before 9.0.2 is vulnerable to DLL hijacking because it loads jansi.dll from the current working directory.
GNU Guix 1.0.1 allows local users to gain access to an arbitrary user's account because the parent directory of the user
In Horner Automation Cscape 9.90 and prior, an improper input validation vulnerability has been identified that may be e
In Horner Automation Cscape 9.90 and prior, improper validation of data may cause the system to write outside the intend
In the Linux kernel before 5.3.4, a reference count usage error in the fib6_rule_suppress() function in the fib6 suppres
cdf_read_property_info in cdf.c in file through 5.37 does not restrict the number of CDF_VECTOR elements, which allows a
Trend Micro Anti-Threat Toolkit (ATTK) versions 1.62.0.1218 and below have a vulnerability that may allow an attacker to
A stack-based buffer overflow in the processPrivilage() function in IOS/process-general.c in nipper-ng 0.11.10 allows re
IBM DB2 High Performance Unload load for LUW 6.1 and 6.5 is vulnerable to a buffer overflow, caused by improper bounds c
Jenkins Bitbucket OAuth Plugin 0.9 and earlier stored credentials unencrypted in the global config.xml configuration fil
Jenkins Dynatrace Application Monitoring Plugin 2.1.3 and earlier stored credentials unencrypted in its global configura
Jenkins Zulip Plugin 1.1.0 and earlier stored credentials unencrypted in its global configuration file on the Jenkins ma
When executing VideoLAN VLC media player 3.0.8 with libqt on Windows, Data from a Faulting Address controls Code Flow st
An issue was discovered in Avast antivirus before 19.8 and AVG antivirus before 19.8. A DLL Preloading vulnerability all
Integer overflow in the new[] operator in gcc before 4.8.0 allows attackers to have unspecified impacts.
The ruby_parser-legacy (aka legacy) gem 1.0.0 for Ruby allows local privilege escalation because of world-writable files
A malicious DLL preload vulnerability in Fortinet FortiClient for Windows 6.2.0 and below allows a privileged attacker t
An exploitable privilege escalation vulnerability exists in the Wacom, driver version 6.3.32-3, update helper service in
An exploitable privilege escalation vulnerability exists in the Wacom, driver version 6.3.32-3, update helper service in
Bounds checking in Tianocompress before November 7, 2017 may allow an authenticated user to potentially enable an escala
rpcbind 0.2.0 does not properly validate (1) /tmp/portmap.xdr and (2) /tmp/rpcbind.xdr, which can be created by an attac
drbd8 allows local users to bypass intended restrictions for certain actions via netlink packets, similar to CVE-2009-37
An issue was discovered in Bitdefender BOX firmware versions before 2.1.37.37-34 that allows an attacker to pass arbitra
An exploitable uninitialized pointer vulnerability exists in the Word document parser of the the Atlantis Word Processor
An issue was discovered in PHOENIX CONTACT PC Worx through 1.86, PC Worx Express through 1.86, and Config+ through 1.86.
ovirt-engine 3.2 running on Linux kernel 3.1 and newer creates certain files world-writeable due to an upstream kernel c
There is a possible tty hijacking in shadow 4.x before 4.1.5 and sudo 1.x before 1.7.4 via "su - user -c program". The u
The scipy.weave component in SciPy before 0.12.1 creates insecure temporary directories.
Integer overflow in the check_offset function in b/wrestool/fileread.c in icoutils before 0.31.1 allows local users to c
Scan for 2019 Vulnerabilities
CyberStrike detects these CVEs across your infrastructure automatically.
Get Started