17,305 vulnerabilities published in 2019
A remote code execution vulnerability exists when Windows Hyper-V on a host server fails to properly validate input from
Vulnerability in the Oracle Retail Xstore Office component of Oracle Retail Applications (subcomponent: Internal Operati
Vulnerability in the Oracle Retail Customer Management and Segmentation Foundation component of Oracle Retail Applicatio
Vulnerability in the Core RDBMS component of Oracle Database Server. Supported versions that are affected are 12.1.0.2,
A remote code execution vulnerability exists when Windows Hyper-V on a host server fails to properly validate input from
Authentication bypass in the web console for Intel(R) Raid Web Console 2 all versions may allow an unauthenticated attac
SQL injection vulnerability in the Cybozu Garoon 4.0.0 to 4.10.3 allows remote authenticated attackers to execute arbitr
Simply-Blog through 2019-01-01 has SQL Injection via the admin/deleteCategories.php delete parameter.
The demangle_template function in cplus-dem.c in GNU libiberty, as distributed in GNU Binutils 2.31.1, has a memory leak
The server in Core FTP 2.0 build 653 on 32-bit platforms allows remote attackers to cause a denial of service (daemon cr
Kubernetes Dashboard before 1.10.1 allows attackers to bypass authentication and use Dashboard's Service Account for rea
OpenRefine through 3.1 allows arbitrary file write because Directory Traversal can occur during the import of a crafted
The Stripe API v1 allows remote attackers to bypass intended access restrictions by replaying api.stripe.com /v1/tokens
Apache Thrift Java client library versions 0.5.0 through 0.11.0 can bypass SASL negotiation isComplete validation in the
EARCLINK ESPCMS-P8 has SQL injection in the install_pack/index.php?ac=Member&at=verifyAccount verify_key parameter. inst
A security weakness in SAP Financial Consolidation Cube Designer (BOBJ_EADES fixed in versions 8.0, 10.1) may allow an a
SAP Business Objects Mobile for Android (before 6.3.5) application allows an attacker to provide malicious input in the
SAP Work and Inventory Manager (Agentry_SDK , before 7.0, 7.1) allows an attacker to prevent legitimate users from acces
Under certain conditions SAP Landscape Management (VCM 3.0) allows an attacker to access information which would otherwi
A remote code execution vulnerability exists in the way that the Chakra scripting engine handles objects in memory in Mi
An information disclosure vulnerability exists in .NET Framework and .NET Core which allows bypassing Cross-origin Resou
A denial of service vulnerability exists when ASP.NET Core improperly handles web requests, aka "ASP.NET Core Denial of
A denial of service vulnerability exists when ASP.NET Core improperly handles web requests, aka "ASP.NET Core Denial of
A remote code execution vulnerability exists when Microsoft Edge improperly accesses objects in memory, aka "Microsoft E
A remote code execution vulnerability exists in the way that the Chakra scripting engine handles objects in memory in Mi
A remote code execution vulnerability exists in the way that the Chakra scripting engine handles objects in memory in Mi
qibosoft through V7 allows remote attackers to read arbitrary files via the member/index.php main parameter, as demonstr
Improper input validation in the proxy component of McAfee Web Gateway 7.8.2.0 and later allows remote attackers to caus
An issue was discovered in BusyBox before 1.30.0. An out of bounds read in udhcp components (consumed by the DHCP server
An issue was discovered in BusyBox through 1.30.0. An out of bounds read in udhcp components (consumed by the DHCP clien
A race condition in Oilpan in Google Chrome prior to 68.0.3440.75 allowed a remote attacker to potentially exploit heap
Directory traversal vulnerability in Cybozu Mailwise 5.0.0 to 5.4.5 allows remote attackers to delete arbitrary files vi
Directory traversal vulnerability in Cybozu Office 10.0.0 to 10.8.1 allows remote attackers to delete arbitrary files vi
Directory traversal vulnerability in Cybozu Office 10.0.0 to 10.8.1 allows remote attackers to delete arbitrary files vi
Cybozu Garoon 3.0.0 to 4.10.0 allows remote attackers to bypass access restriction to view information available only fo
Multiple Yokogawa products that contain Vnet/IP Open Communication Driver (CENTUM CS 3000(R3.05.00 - R3.09.50), CENTUM C
An issue was discovered in ShopXO 1.2.0. In the UnlinkDir method of the FileUtil.php file, the input parameters are not
In WinSCP before 5.14 beta, due to missing validation, the scp implementation would accept arbitrary files sent by the s
The Admin Panel of PHP Scripts Mall Advance Peer to Peer MLM Script v1.7.0 allows remote attackers to bypass intended ac
An issue was discovered in Bento4 v1.5.1-627. There is a memory leak in AP4_DescriptorFactory::CreateDescriptorFromStrea
An issue has been found in libIEC61850 v1.3.1. Memory_malloc in hal/memory/lib_memory.c has a memory leak when called fr
An issue has been found in libIEC61850 v1.3.1. Ethernet_setProtocolFilter in hal/ethernet/linux/ethernet_linux.c has a S
An issue was discovered in lib60870 2.1.1. LinkLayer_setAddress in link_layer/link_layer.c has a NULL pointer dereferenc
An issue has been found in libIEC61850 v1.3.1. Memory_malloc and Memory_calloc in hal/memory/lib_memory.c have memory le
In macOS High Sierra before 10.13.2, a logic issue existed in APFS when deleting keys during hibernation. This was addre
In iOS before 11.2, a type confusion issue was addressed with improved memory handling.
In iOS before 11.3, tvOS before 11.3, watchOS before 4.3, and macOS before High Sierra 10.13.4, an information disclosur
In Safari before 11.1, an information leakage issue existed in the handling of downloads in Safari Private Browsing. Thi
In macOS High Sierra before 10.13.5, a privacy issue in the handling of Open Directory records was addressed with improv
In iOS before 11.4.1, watchOS before 4.3.2, tvOS before 11.4.1, Safari before 11.1.1, macOS High Sierra before 10.13.6,
Scan for 2019 Vulnerabilities
CyberStrike detects these CVEs across your infrastructure automatically.
Get Started