17,305 vulnerabilities published in 2019
UiPath Orchestrator before 2018.3.4 allows CSV Injection, related to the Audit export, Robot log export, and Transaction
An issue was discovered on D-Link 6600-AP and DWL-3600AP Ax 4.2.0.14 21/03/2019 devices. There is post-authenticated den
Huawei PCManager with the versions before 9.0.1.66 (Oversea) and versions before 9.0.1.70 (China) have an information le
Swann SWWHD-INTCAM-HD devices leave the PSK in logs after a factory reset. NOTE: all affected customers were migrated by
On Samsung mobile devices with N(7.x), and O(8.x), P(9.0) software, FotaAgent allows a malicious application to create p
An issue was discovered in the mysql (aka mysqljs) module 2.17.1 for Node.js. The LOAD DATA LOCAL INFILE option is open
An information disclosure vulnerability exists when the Windows Graphics component improperly handles objects in memory.
An information disclosure vulnerability exists when the Windows GDI component improperly discloses the contents of its m
An information disclosure vulnerability exists when the Microsoft Windows Graphics Component improperly handles objects
An information disclosure vulnerability exists when the Microsoft Windows Graphics Component improperly handles objects
An information disclosure vulnerability exists when the Windows GDI component improperly discloses the contents of its m
An information disclosure vulnerability exists when the Windows GDI component improperly discloses the contents of its m
A security feature bypass exists when Windows incorrectly validates CAB file signatures. An attacker who successfully ex
A denial of service vulnerability exists when the XmlLite runtime (XmlLite.dll) improperly parses XML input. An attacker
An information disclosure vulnerability exists when the Windows kernel improperly handles objects in memory. An attacker
An information disclosure vulnerability exists when the Windows kernel improperly handles objects in memory. An attacker
The read_chunk function in flif-dec.cpp in Free Lossless Image Format (FLIF) 0.3 allows remote attackers to cause a deni
A vulnerability was found in Linux kernel's, versions up to 3.10, implementation of overlayfs. An attacker with local ac
Division by zero in the predict_point function in stb_vorbis through 2019-03-04 allows an attacker to cause a denial of
A NULL pointer dereference in the get_window function in stb_vorbis through 2019-03-04 allows an attacker to cause a den
A reachable assertion in the lookup1_values function in stb_vorbis through 2019-03-04 allows an attacker to cause a deni
check_input_term in sound/usb/mixer.c in the Linux kernel through 5.2.9 mishandles recursion, leading to kernel stack ex
lib/install/install.go in cnlh nps through 0.23.2 uses 0777 permissions for /usr/local/bin/nps and/or /usr/bin/nps, lead
In DjVuLibre 3.5.27, DjVmDir.cpp in the DJVU reader component allows attackers to cause a denial-of-service (application
In DjVuLibre 3.5.27, the bitmap reader component allows attackers to cause a denial-of-service error (resource exhaustio
In DjVuLibre 3.5.27, the sorting functionality (aka GArrayTemplate<TYPE>::sort) allows attackers to cause a denial-of-se
DjVuLibre 3.5.27 allows attackers to cause a denial-of-service attack (application crash via an out-of-bounds read) by c
An issue was discovered in drivers/scsi/aacraid/commctrl.c in the Linux kernel before 4.13. There is potential exposure
An issue was discovered in drivers/scsi/aacraid/commctrl.c in the Linux kernel before 4.13. There is potential exposure
IBM MQ 9.1.0.0, 9.1.0.1, 9.1.1, and 9.1.0.2 is vulnerable to a denial of service due to a local user being able to fill
In Mfc_Transceive of phNxpExtns_MifareStd.cpp, there is a possible out of bounds read due to a missing bounds check. Thi
In Status::readFromParcel of Status.cpp, there is a possible out of bounds read due to improper input validation. This c
In the endCall() function of TelecomManager.java, there is a possible Denial of Service due to a missing permission chec
Buffer overflow in McAfee Data Loss Prevention (DLPe) for Windows 11.x prior to 11.3.2.8 allows local user to cause the
Buffer overflow in McAfee Data Loss Prevention (DLPe) for Windows 11.x prior to 11.3.2.8 allows local user to cause the
In Code42 Enterprise and Crashplan for Small Business through Client version 6.9.1, an attacker can craft a restore requ
A vulnerability in Cisco RoomOS Software could allow an authenticated, local attacker to write files to the underlying f
An insecure storage of sensitive information vulnerability is present in Hickory Smart for Android mobile devices from B
An insecure storage of sensitive information vulnerability is present in Hickory Smart for iOS mobile devices from Belwi
jc21 Nginx Proxy Manager before 2.0.13 allows %2e%2e%2f directory traversal.
Little Snitch versions 4.3.0 to 4.3.2 have a local privilege escalation vulnerability in their privileged helper tool. T
Little Snitch versions 4.4.0 fixes a vulnerability in a privileged helper tool. However, the operating system may have m
In version 2.0.3 Apache Santuario XML Security for Java, a caching mechanism was introduced to speed up creating new XML
WTF before 0.19.0 does not set the permissions of config.yml, which might make it easier for local attackers to read pas
In VideoLAN VLC media player 3.0.7.1, there is a NULL pointer dereference at the function SeekPercent of demux/asf/asf.c
Xpdf 2.00 allows a SIGSEGV in XRef::constructXRef in XRef.cc. NOTE: 2.00 is a version from November 2002.
A weakness was found in Encrypt Only boot mode in Zynq UltraScale+ devices. This could lead to an adversary being able t
An issue was discovered in the Linux kernel before 5.0.9. There is a NULL pointer dereference for a pf data structure if
An issue was discovered in the Linux kernel before 5.0.9. There is a NULL pointer dereference for a cd data structure if
An issue was discovered in the Linux kernel before 5.0.11. fm10k_init_module in drivers/net/ethernet/intel/fm10k/fm10k_m
Scan for 2019 Vulnerabilities
CyberStrike detects these CVEs across your infrastructure automatically.
Get Started