17,305 vulnerabilities published in 2019
FasterXML jackson-databind 2.x before 2.9.7 might allow remote attackers to conduct server-side request forgery (SSRF) a
Zoho ManageEngine ADSelfService Plus 5.x before build 5703 has SSRF.
Juniper ATP ships with hard coded credentials in the Web Collector instance which gives an attacker the ability to take
Juniper ATP ships with hard coded credentials in the Cyphort Core instance which gives an attacker the ability to take f
MailEnable before 8.60 allows XXE via an XML document in the request.aspx Options parameter.
A reliance on a static, hard-coded credential in the design of the cloud-based storage system of Practecol's Guardzilla
An earlier fix for an Inter-process Communication (IPC) vulnerability, CVE-2011-3079, added authentication to communicat
An exploitable heap overflow vulnerability exists in the WkbProgramLow function of WibuKey Network server management, ve
A memory corruption issue was addressed with improved validation. This issue is fixed in iOS 12.1.3, macOS Mojave 10.14.
The REST API component of TIBCO Software Inc.'s TIBCO JasperReports Server, TIBCO JasperReports Server Community Edition
Kibana versions before 5.6.15 and 6.6.1 contain an arbitrary code execution flaw in the Timelion visualizer. An attacker
An SSRF vulnerability was found in an API from Ctrip Apollo through 1.4.0-SNAPSHOT. An attacker may use it to do an intr
An access issue was addressed with additional sandbox restrictions. This issue affected versions prior to iOS 12, macOS
IBM API Connect 5.0.0.0 and 5.0.8.6 Developer Portal is vulnerable to command injection. An attacker with a specially cr
An issue was discovered in GitLab Community and Enterprise Edition before 11.6.10, 11.7.x before 11.7.6, and 11.8.x befo
In Pulse Secure Pulse Connect Secure (PCS) 8.2 before 8.2R12.1, 8.3 before 8.3R7.1, and 9.0 before 9.0R3.4, an unauthent
A vulnerability in the REST API of Cisco Elastic Services Controller (ESC) could allow an unauthenticated, remote attack
Citrix Application Delivery Management (ADM) 12.1.x before 12.1.50.33 has Incorrect Access Control.
Lack of validation in the HTML parser in RealObjects PDFreactor before 10.1.10722 leads to SSRF, allowing attackers to a
BD Alaris Gateway Workstation Versions, 1.1.3 Build 10, 1.1.3 MR Build 11, 1.2 Build 15, 1.3.0 Build 14, 1.3.1 Build 13,
Linear eMerge 50P/5000P devices allow Unauthenticated File Upload.
Linear eMerge E3-Series devices allow Unrestricted File Upload.
A SQL injection vulnerability in the reporting component of Avaya Control Manager could allow an unauthenticated attacke
Insufficient vetting of parameters passed with the Prompt:Open IPC message between child and parent processes can result
NVIDIA Windows GPU Display Driver (all versions) contains a vulnerability in DirectX drivers, in which a specially craft
The nelio-ab-testing plugin before 4.5.9 for WordPress has SSRF in ajax/iesupport.php.
The nelio-ab-testing plugin before 4.5.11 for WordPress has SSRF in ajax/iesupport.php.
The fetch API in Tightrope Media Carousel before 7.1.3 has CarouselAPI/v0/fetch?url= SSRF. This has two potential areas
A vulnerability in the Cisco REST API virtual service container for Cisco IOS XE Software could allow an unauthenticated
A broken access control vulnerability in HG100 firmware versions up to 4.00.06 allows an attacker in the same local area
A broken access control vulnerability in SmartHome app (Android versions up to 3.0.42_190515, ios versions up to 2.0.22)
NPM package gitlabhook version 0.0.17 is vulnerable to a Command Injection vulnerability. Arbitrary commands can be inje
The server component of TIBCO Software Inc.'s TIBCO Enterprise Runtime for R - Server Edition, and TIBCO Spotfire Analyt
On Supermicro H11, H12, M11, X9, X10, and X11 products, a combination of encryption and authentication problems in the v
On Supermicro X10 and X11 products, a client's access privileges may be transferred to a different client that later has
A blind SSRF vulnerability exists in the Visualizer plugin before 3.3.1 for WordPress via wp-json/visualizer/v1/upload-d
An remote code execution vulnerability exists when Azure App Service/ Antares on Azure Stack fails to check the length o
An “invalid command” handler issue was discovered in HiNet GPON firmware < I040GWR190731. It allows an attacker to execu
An “invalid command” handler issue was discovered in HiNet GPON firmware < I040GWR190731. It allows an attacker to execu
An exploitable memory corruption vulnerability exists in AMD ATIDXX64.DLL driver, versions 25.20.15031.5004 and 25.20.15
An exploitable SQL injection vulnerability exist in YouPHPTube 7.7. A specially crafted unauthenticated HTTP request can
An exploitable vulnerability exists in the safe browsing function of the CUJO Smart Firewall, version 7003. The flaw lie
Computing For Good's Basic Laboratory Information System (also known as C4G BLIS) version 3.4 and earlier suffers from a
Computing For Good's Basic Laboratory Information System (also known as C4G BLIS) version 3.5 and earlier suffers from a
SAS XML Mapper 9.45 has an XML External Entity (XXE) vulnerability that can be leveraged by malicious attackers in multi
Dell EMC Storage Monitoring and Reporting version 4.3.1 contains a Java RMI Deserialization of Untrusted Data vulnerabil
An attacker could use specially crafted paths in a specific request to read or delete files from Relion 670 Series (vers
Grandstream GXV3501, GXV3504, GXV3601, GXV3601HD/LL, GXV3611HD/LL, GXV3615W/P, GXV3651FHD, GXV3662HD, GXV3615WP_HD, GXV3
An access issue was addressed with additional sandbox restrictions. This issue is fixed in Shortcuts 2.1.3 for iOS. A sa
A logic issue applied the incorrect restrictions. This issue was addressed by updating the logic to apply the correct re
Scan for 2019 Vulnerabilities
CyberStrike detects these CVEs across your infrastructure automatically.
Get Started