2019 CVE Vulnerabilities

17,620 CVEs published in 2019.

CVE IDSeverityCVSSDescription
CVE-2019-18242HIGH7.5In Moxa ioLogik 2500 series firmware, Version 3.0 or lower, and IOxpress configuration utility, Version 2.3.0 or lower, ...
CVE-2019-4681MEDIUM6.1IBM Tivoli Netcool Impact 7.1.0.0 through 7.1.0.17 is vulnerable to cross-site scripting. This vulnerability allows user...
CVE-2019-4553HIGH7.5IBM API Connect V5.0.0.0 through 5.0.8.7iFix3 uses weaker than expected cryptographic algorithms that could allow an att...
CVE-2019-17565CRITICAL9.8There is a vulnerability in Apache Traffic Server 6.0.0 to 6.2.3, 7.0.0 to 7.1.8, and 8.0.0 to 8.0.5 with a smuggling at...
CVE-2019-17559CRITICAL9.8There is a vulnerability in Apache Traffic Server 6.0.0 to 6.2.3, 7.0.0 to 7.1.8, and 8.0.0 to 8.0.5 with a smuggling at...
CVE-2019-6558HIGH7.5In Auto-Maskin RP210E Versions 3.7 and prior, DCU210E Versions 3.7 and prior and Marine Observer Pro (Android App), the ...
CVE-2019-6560CRITICAL9.1In Auto-Maskin RP210E Versions 3.7 and prior, DCU210E Versions 3.7 and prior and Marine Observer Pro (Android App), the ...
CVE-2019-20627CRITICAL9.8AutoUpdater.cs in AutoUpdater.NET before 1.5.8 allows XXE.
CVE-2019-20626MEDIUM6.5The remote keyless system on Honda HR-V 2017 vehicles sends the same RF signal for each door-open request, which might a...
CVE-2019-19034HIGH7.2Zoho ManageEngine Asset Explorer 6.5 does not validate the System Center Configuration Manager (SCCM) database username ...
CVE-2019-4718MEDIUM5.4IBM Jazz for Service Management 3.13 is vulnerable to cross-site scripting. This vulnerability allows users to embed arb...
CVE-2019-5186HIGH7An exploitable stack buffer overflow vulnerability vulnerability exists in the iocheckd service "I/O-Check" functionalit...
CVE-2019-5185HIGH7An exploitable stack buffer overflow vulnerability vulnerability exists in the iocheckd service "I/O-Check" functionalit...
CVE-2019-5184HIGH7.8An exploitable double free vulnerability exists in the iocheckd service "I/O-Check" functionality of WAGO PFC 200. A spe...
CVE-2019-19964LOW2.7On NETGEAR GS728TPS devices through 5.3.0.35, a remote attacker having network connectivity to the web-administration pa...
CVE-2019-15510MEDIUM6.1ManageEngine_DesktopCentral.exe in Zoho ManageEngine Desktop Central 10 allows HTML injection on the user administration...
CVE-2019-18936HIGH7.5UniValue::read() in UniValue before 1.0.5 allow attackers to cause a denial of service (the class internal data reaches ...
CVE-2019-17185HIGH7.5In FreeRADIUS 3.0.x before 3.0.20, the EAP-pwd module used a global OpenSSL BN_CTX instance to handle all handshakes. Th...
CVE-2019-12767CRITICAL9.8An issue was discovered on D-Link DAP-1650 devices before 1.04B02_J65H Hot Fix. Attackers can execute arbitrary commands...
CVE-2019-11574CRITICAL9.8An issue was discovered in Simple Machines Forum (SMF) before release 2.0.17. There is SSRF related to Subs-Package.php ...
CVE-2019-18860MEDIUM6.1Squid before 4.9, when certain web browsers are used, mishandles HTML in the host (aka hostname) parameter to cachemgr.c...
CVE-2019-18641CRITICAL9.8Rock RMS before 1.8.6 mishandles vCard access control within the People/GetVCard/REST controller.
CVE-2019-16528HIGH7.5An issue was discovered in the AbuseFilter extension for MediaWiki. includes/special/SpecialAbuseLog.php allows attacker...
CVE-2019-15522CRITICAL9.8An issue was discovered in LINBIT csync2 through 2.0. csync_daemon_session in daemon.c neglects to force a failure of a ...
CVE-2019-13463MEDIUM6.1An XSS vulnerability in qcopd-shortcode-generator.php in the Simple Link Directory plugin before 7.3.5 for WordPress all...

Check if your code is affected by 2019 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now