17,305 vulnerabilities published in 2019
The Screen Stream application through 3.0.15 for Android allows remote attackers to cause a denial of service via many s
rdesktop versions up to and including v1.8.3 contain an Out-Of-Bounds Read in the function ui_clip_handle_data() that re
rdesktop versions up to and including v1.8.3 contains several Integer Signedness errors that lead to Out-Of-Bounds Reads
rdesktop versions up to and including v1.8.3 contain several Out-Of- Bounds Reads in the file secure.c that result in a
rdesktop versions up to and including v1.8.3 contain an Out-Of-Bounds Read in the function process_demand_active() that
An Integer overflow vulnerability exists in the batchTransfer function of a smart contract implementation for CryptoBots
Topvision CC8800 CMTS C-E devices allow remote attackers to obtain sensitive information via a direct request for /WebCo
A malicious attacker can trigger a remote buffer overflow in the Communication Server in Fatek Automation PM Designer V3
NetIQ eDirectory versions prior to 9.0.2, under some circumstances, could be susceptible to downgrade of communication s
LibTIFF 4.0.8 has multiple memory leak vulnerabilities, which allow attackers to cause a denial of service (memory consu
When accessing the heron-ui webpage, people can modify the file paths outside of the current container to access any fil
An issue was discovered in FasterXML jackson-databind prior to 2.7.9.4, 2.8.11.2, and 2.9.6. When Default Typing is enab
An issue was discovered in FasterXML jackson-databind prior to 2.7.9.4, 2.8.11.2, and 2.9.6. When Default Typing is enab
Five9 Agent Desktop Plus 10.0.70 has Incorrect Access Control allowing a remote attackers to cause a denial of service v
An issue was discovered in Repute ARForms 3.5.1 and prior. An attacker is able to delete any file on the server with web
libhttp/url.c in shellinabox through 2.20 has an implementation flaw in the HTTP request parsing logic. By sending a cra
The email-ingestion feature in Best Practical Request Tracker 4.1.13 through 4.4 allows denial of service by remote atta
ColossusCoinXT through 1.0.5 (a chain-based proof-of-stake cryptocurrency) allows a remote denial of service, exploitabl
The WP-jobhunt plugin before version 2.4 for WordPress does not control AJAX requests sent to the cs_employer_ajax_profi
In Webgalamb through 7.0, log files are exposed to the internet with predictable files/logs/sql_error_log/YYYY-MM-DD-sql
An issue was discovered on Teracue ENC-400 devices with firmware 2.56 and below. While the web interface requires authen
An out-of-bounds read issue was discovered in the HTTP/2 protocol decoder in HAProxy 1.8.x and 1.9.x through 1.9.0 which
PHP Scripts Mall Charity Foundation Script 1 through 3 allows directory traversal via a direct request for a listing of
Prior to version 0.3.0, chloride's use of net-ssh resulted in host fingerprints for previously unknown hosts getting add
A bug in handling the ignore files and directories feature in serve 6.5.3 allows an attacker to read a file or list the
A path traversal vulnerability in localhost-now npm package version 1.0.2 allows the attackers to read content of arbitr
A path traversal vulnerability in serve npm package version 7.0.1 allows the attackers to read content of arbitrary file
Matrix Synapse before 0.34.0.1, when the macaroon_secret_key authentication parameter is not set, uses a predictable val
python-gnupg 0.4.3 allows context-dependent attackers to trick gnupg to decrypt other ciphertext than intended. To perfo
Moodle 3.5.x before 3.5.4 allows SSRF.
Sricam IP CCTV cameras are vulnerable to denial of service via multiple incomplete HTTP requests because the web server
An issue was discovered in Zoho ManageEngine ADSelfService Plus 5.x through build 5704. It uses fixed ciphering keys to
A remotely triggerable memory overwrite in RSA key exchange in PuTTY before 0.71 can occur before host key verification.
Multiple denial-of-service attacks that can be triggered by writing to the terminal exist in PuTTY versions before 0.71.
An exploitable integer underflow vulnerability exists in the mdnscap binary of the CUJO Smart Firewall, version 7003. Wh
An exploitable vulnerability exists the safe browsing function of the CUJO Smart Firewall, version 7003. The bug lies in
A vulnerability has been identified in SICAM A8000 CP-8000 (All versions < V14), SICAM A8000 CP-802X (All versions < V14
A Denial of Service vulnerability related to preemptive item deletion in lmgrd and vendor daemon components of FlexNet P
A Denial of Service vulnerability related to message decoding in lmgrd and vendor daemon components of FlexNet Publisher
A Denial of Service vulnerability related to adding an item to a list in lmgrd and vendor daemon components of FlexNet P
pax_decode_header in sparse.c in GNU Tar before 1.32 had a NULL pointer dereference when parsing certain archives that h
In SQLite 3.27.2, running fts5 prefix queries inside a transaction could trigger a heap-based buffer over-read in fts5Ha
In SQLite 3.27.2, interleaving reads and writes in a single transaction with an fts5 virtual table will lead to a NULL P
IBM API Connect 2018.1 and 2018.4.1.2 apis can be leveraged by unauthenticated users to discover login ids of registered
A vulnerability in the web-based management interface of Session Initiation Protocol (SIP) Software for Cisco IP Phone 7
A vulnerability in the web-based management interface of Session Initiation Protocol (SIP) Software for Cisco IP Phone 8
A vulnerability in the web-based management interface of Session Initiation Protocol (SIP) Software for Cisco IP Phone 8
hostapd before 2.6 does not prevent use of the low-quality PRNG that is reached by an os_random() function call.
Wireless keys are stored in plain text on Hospira Plum A+ Infusion System version 13.4 and prior, Plum A+3 Infusion Syst
An issue was discovered in GitLab Community and Enterprise Edition before 11.4. It allows Directory Traversal.
Scan for 2019 Vulnerabilities
CyberStrike detects these CVEs across your infrastructure automatically.
Get Started