17,305 vulnerabilities published in 2019
An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properly handle objects in
A remote code execution vulnerability exists in Microsoft PowerPoint software when the software fails to properly handle
An elevation of privilege vulnerability exists when Windows AppX Deployment Service (AppXSVC) improperly handles hard li
An elevation of privilege vulnerability exists when the Windows Printer Service improperly validates file paths while lo
An elevation of privilege vulnerability exists when Windows improperly handles COM object creation, aka 'Windows COM Ser
An elevation of privilege vulnerability exists when the Windows AppX Deployment Server improperly handles junctions.To e
A remote code execution vulnerability exists when Microsoft Windows OLE fails to properly validate user input, aka 'Wind
Arbitrary command execution is possible in Git before 2.20.2, 2.21.x before 2.21.1, 2.22.x before 2.22.2, 2.23.x before
SafeNet Sentinel LDK License Manager, all versions prior to 7.101(only Microsoft Windows versions are affected) is vulne
Reliable Controls LicenseManager versions 3.4 and prior may allow an authenticated user to insert malicious code into th
OpenBSD through 6.6 allows local users to escalate to root because a check for LD_LIBRARY_PATH in setuid programs can be
Lack of check of data truncation on user supplied data in kernel leads to buffer overflow in Snapdragon Auto, Snapdragon
Buffer overflow can occur due to usage of wrong datatype and missing length check before copying into buffer in Snapdrag
Snapshot of IB can lead to invalid address access due to missing check for size in the related function in Snapdragon Au
Possible integer overflow while multiplying two integers of 32 bit in QDCM API of get display modes as there is no check
Out of bound write in TZ while copying the secure dump structure on HLOS provided buffer as a part of memory dump in Sna
HLOS could corrupt CPZ page table memory for S1 managed VMs in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectiv
Incorrect length used while validating the qsee log buffer sent from HLOS which could then lead to remap conflict in Sna
Electronic Arts Origin through 10.5.x allows Elevation of Privilege (issue 1 of 2).
Electronic Arts Origin through 10.5.x allows Elevation of Privilege (issue 2 of 2).
IBM DB2 High Performance Unload load for LUW 6.1 and 6.5 could allow a local attacker to execute arbitrary code on the s
A vulnerability has been identified in SPPA-T3000 MS3000 Migration Server (All versions). An attacker with local access
A vulnerability has been identified in SPPA-T3000 MS3000 Migration Server (All versions). An attacker with local access
A vulnerability has been identified in SPPA-T3000 MS3000 Migration Server (All versions). An attacker with local access
VeraCrypt 1.24 allows Local Privilege Escalation during execution of VeraCryptExpander.exe.
suPHP before 0.7.2 source-highlighting feature allows security bypass which could lead to arbitrary code execution
Mate 20 Pro smartphones with versions earlier than 9.1.0.135(C00E133R3P1) have an improper authorization vulnerability.
ATasm 1.06 has a stack-based buffer overflow in the to_comma() function in asm.c via a crafted .m65 file.
ATasm 1.06 has a stack-based buffer overflow in the parse_expr() function in setparse.c via a crafted .m65 file.
ATasm 1.06 has a stack-based buffer overflow in the get_signed_expression() function in setparse.c via a crafted .m65 fi
samurai 0.7 has a heap-based buffer overflow in canonpath in util.c via a crafted build file.
Yabasic 2.86.2 has a heap-based buffer overflow in myformat in function.c via a crafted BASIC source file.
In the Linux kernel before 5.3.11, sound/core/timer.c has a use-after-free caused by erroneous code refactoring, aka CID
Improper permissions in the Intel(R) Dynamic Platform and Thermal Framework v8.3.10208.5643 and before may allow an auth
Insufficient memory protection in the Linux Administrative Tools for Intel(R) Network Adapters before version 24.3 may a
In Yarn before 1.21.1, the package install functionality can be abused to generate arbitrary symlinks on the host filesy
Improper permissions in the executable for Intel(R) RST before version 17.7.0.1006 may allow an authenticated user to po
Unquoted service path in Control Center-I version 2.1.0.0 and earlier may allow an authenticated user to potentially ena
Improper permissions in the installer for the License Server software for Intel® Quartus® Prime Pro Edition before versi
Improper permissions in the installer for the Intel(R) SCS Platform Discovery Utility, all versions, may allow an authen
Improper buffer restrictions in firmware for Intel(R) NUC(R) may allow an authenticated user to potentially enable escal
Improper access control in firmware for Intel(R) NUC(R) may allow an authenticated user to potentially enable escalation
In the Linux kernel 5.0.21, mounting a crafted f2fs filesystem image can cause __remove_dirty_segment slab-out-of-bounds
In the Linux kernel 5.0.21, mounting a crafted btrfs filesystem image and performing some operations can cause slab-out-
Barco ClickShare Button R9861500D01 devices before 1.10.0.13 have Missing Support for Integrity Check. The Barco signed
In Ivanti Workspace Control before 10.3.180.0. a locally authenticated user with low privileges can bypass Managed Appli
In the Quick Access Service (QAAdminAgent.exe) in Acer Quick Access V2.01.3000 through 2.01.3027 and V3.00.3000 through
In the Linux kernel before 5.4.2, the io_uring feature leads to requests that inadvertently have UID 0 and full capabili
When a fake broadcast/multicast 11w rmf without mmie received, since no proper length check in wma_process_bip, buffer o
Out of bound write can happen in WMI firmware event handler due to lack of validation of data received from WLAN firmwar
Scan for 2019 Vulnerabilities
CyberStrike detects these CVEs across your infrastructure automatically.
Get Started