17,305 vulnerabilities published in 2019
This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Foxit Reader. User i
This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Foxit PhantomPDF. Us
AirTies Air5341 1.0.0.12 devices allow cgi-bin/login CSRF.
ZyXEL VMG3312-B10B DSL-491HNU-B1B v2 devices allow login/login-page.cgi CSRF.
PHP Scripts Mall Rental Bike Script 2.0.3 has Cross-Site Request Forgery (CSRF) via the Edit Profile feature.
RISI Gestao de Horarios v3201.09.08 rev.23 allows SQL Injection.
Moxa SoftCMS 1.3 and prior is susceptible to a buffer overflow condition that may crash or allow remote code execution.
Moxa SoftCMS 1.3 and prior is susceptible to a buffer overflow condition that may crash or allow remote code execution.
An integer overflow flaw which could lead to an out of bounds write was discovered in libssh2 before 1.8.1 in the way pa
A code injection issue was discovered in ipycache through 2016-05-31.
The SHAREit application before 4.0.36 for Android allows a remote attacker (on the same network or joining public "open"
Hospira Symbiq Infusion System 3.13 and earlier allows remote authenticated users to trigger "unanticipated operations"
In ImageMagick 7.0.8-35 Q16, there is a stack-based buffer overflow in the function PopHexPixel of coders/ps.c, which al
The renderer process in the entertainment system on Tesla Model 3 vehicles mishandles JIT compilation, which allows atta
ManageEngine ServiceDesk Plus before 9312 contains an XML injection at add Configuration items CMDB API.
In ovirt-engine 4.1, if a host was provisioned with cloud-init, the root password could be revealed through the REST int
An integer overflow flaw, which could lead to an out of bounds write, was discovered in libssh2 before 1.8.1 in the way
An integer overflow flaw which could lead to an out of bounds write was discovered in libssh2 before 1.8.1 in the way SS
Telegram Desktop before 1.5.12 on Windows, and the Telegram applications for Android, iOS, and Linux, is vulnerable to a
An issue was discovered in CMS Made Simple 2.2.8. In the module DesignManager (in the files action.admin_bulk_css.php an
An issue was discovered in CMS Made Simple 2.2.8. In the module FilePicker, it is possible to reach an unserialize call
An issue was discovered in CMS Made Simple 2.2.8. In the module ModuleManager (in the file action.installmodule.php), it
A vulnerability was found in moodle before versions 3.6.3, 3.5.5 and 3.4.8. Users could assign themselves an escalated r
An issue was discovered on PHOENIX CONTACT RAD-80211-XD and RAD-80211-XD/HP-BUS devices. Command injection can occur in
An issue was discovered on PHOENIX CONTACT FL NAT SMCS 8TX, FL NAT SMN 8TX, FL NAT SMN 8TX-M, and FL NAT SMN 8TX-M-DMG d
S-CMS PHP v1.0 has a CSRF vulnerability to add a new admin user via the 4.edu.php/admin/ajax.php?type=admin&action=add&l
Buffer overflow in BlockIo service for EDK II may allow an unauthenticated user to potentially enable escalation of priv
An issue was discovered in ADTRAN PMAA 1.6.2-1, 1.6.3, and 1.6.4. NETCONF Access Management (NACM) allows unprivileged u
A vulnerability in the web UI framework of Cisco IOS XE Software could allow an authenticated, remote attacker to make u
A vulnerability in the web UI of Cisco IOS XE Software could allow an authenticated but unprivileged (level 1), remote a
A vulnerability in the authorization subsystem of Cisco IOS XE Software could allow an authenticated but unprivileged (l
In Dovecot before 2.2.36.3 and 2.3.x before 2.3.5.1, a local attacker can cause a buffer overflow in the indexer-worker
LibreNMS through 1.47 allows SQL injection via the html/ajax_table.php sort[hostname] parameter, exploitable by authenti
Laravel 5.4.15 is vulnerable to Error based SQL injection in save.php via dhx_user and dhx_version parameters.
Command injection in Nagios XI before 5.5.11 allows an authenticated users to execute arbitrary remote commands via a ne
Nagios IM (component of Nagios XI) before 2.2.7 allows authenticated users to execute arbitrary code via API key issues.
PHP Scripts Mall Online Lottery PHP Readymade Script 1.7.0 has Cross-Site Request Forgery (CSRF) for Edit Profile action
An issue was discovered in the Harmis JE Messenger component 1.2.2 for Joomla!. It is possible to perform an action with
An issue was discovered in HYBBS 2.2. /?admin/user.html has a CSRF vulnerability that can add an administrator account.
Grandstream GWN7000 before 1.0.6.32 devices allow remote authenticated users to execute arbitrary code via shell metacha
Grandstream GWN7610 before 1.0.8.18 devices allow remote authenticated users to execute arbitrary code via shell metacha
Grandstream GXV3370 before 1.0.1.41 and WP820 before 1.0.3.6 devices allow remote authenticated users to execute arbitra
Grandstream GXV3611IR_HD before 1.0.3.23 devices allow remote authenticated users to execute arbitrary code via shell me
Grandstream UCM6204 before 1.0.19.20 devices allow remote authenticated users to execute arbitrary code via shell metach
Grandstream UCM6204 before 1.0.19.20 devices allow remote authenticated users to conduct SQL injection attacks via the s
OMERO before 5.0.6 has multiple CSRF vulnerabilities because the framework for OMERO's web interface lacks CSRF protecti
Lack of administrator control over security vulnerability in client.cgi in Synology SSL VPN Client before 1.2.5-0226 all
An issue was discovered in OverIT Geocall 6.3 before build 2:346977. Weak authentication and session management allows a
An issue was discovered on AudioCodes 450HD IP Phone devices with firmware 3.0.0.535.106. The traceroute and ping functi
Remote code execution vulnerability exists in KaKaoTalk PC messenger when user clicks specially crafted link in the mess
Scan for 2019 Vulnerabilities
CyberStrike detects these CVEs across your infrastructure automatically.
Get Started