2019 CVE Vulnerabilities

17,620 CVEs published in 2019.

CVE IDSeverityCVSSDescription
CVE-2019-19000MEDIUM6.5For ABB eSOMS 4.0 to 6.0.3, the Cache-Control and Pragma HTTP header(s) have not been properly configured within the app...
CVE-2019-14868HIGH7.8In ksh version 20120801, a flaw was found in the way it evaluates certain environment variables. An attacker could use t...
CVE-2019-20635MEDIUM6.1codeBeamer before 9.5.0-RC3 does not properly restrict the ability to execute custom Java code and access the Java class...
CVE-2019-7017Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was n...
CVE-2019-7016Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was n...
CVE-2019-7015Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was n...
CVE-2019-7014Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was n...
CVE-2019-7013Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was n...
CVE-2019-7012Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was n...
CVE-2019-7011Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was n...
CVE-2019-7010Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was n...
CVE-2019-7009Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was n...
CVE-2019-7008Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was n...
CVE-2019-6999Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was n...
CVE-2019-17564CRITICAL9.8Unsafe deserialization occurs within a Dubbo application which has HTTP remoting enabled. An attacker may submit a POST ...
CVE-2019-9163CRITICAL9.8The connection initiation process in March Networks Command Client before 2.7.2 allows remote attackers to execute arbit...
CVE-2019-11254MEDIUM6.5The Kubernetes API Server component in versions 1.1-1.14, and versions prior to 1.15.10, 1.16.7 and 1.17.3 allows an aut...
CVE-2019-3945HIGH7.5Web server running on Parrot ANAFI can be crashed due to the SDK command "Common_CurrentDateTime" being sent to control ...
CVE-2019-3944HIGH7.5Parrot ANAFI is vulnerable to Wi-Fi deauthentication attack, allowing remote and unauthenticated attackers to disconnect...
CVE-2019-3942HIGH7.5Advantech WebAccess 8.3.4 does not properly restrict an RPC call that allows unauthenticated, remote users to read files...
CVE-2019-13495MEDIUM5.4In firmware version 4.50 of Zyxel XGS2210-52HP, multiple stored cross-site scripting (XSS) issues allows remote authenti...
CVE-2019-14905MEDIUM5.6A vulnerability was found in Ansible Engine versions 2.9.x before 2.9.3, 2.8.x before 2.8.8, 2.7.x before 2.7.16 and ear...
CVE-2019-10180MEDIUM4.8A vulnerability was found in all pki-core 10.x.x version, where the Token Processing Service (TPS) did not properly sani...
CVE-2019-14880CRITICAL9.1A vulnerability was found in Moodle versions 3.7 before 3.7.3, 3.6 before 3.6.7, 3.5 before 3.5.9 and earlier. OAuth 2 p...
CVE-2019-2391MEDIUM5.4Incorrect parsing of certain JSON input may result in js-bson not correctly serializing BSON. This may cause unexpected ...

Check if your code is affected by 2019 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now