2019 CVE Vulnerabilities

17,620 CVEs published in 2019.

CVE IDSeverityCVSSDescription
CVE-2019-16065HIGH8.8A remote SQL injection web vulnerability was discovered in the Enigma NMS 65.0.0 and prior web application that allows a...
CVE-2019-16064CRITICAL9.6NETSAS Enigma NMS 65.0.0 and prior suffers from a directory traversal vulnerability that can allow an authenticated user...
CVE-2019-16062MEDIUM6.5NETSAS Enigma NMS 65.0.0 and prior does not encrypt sensitive data stored within the SQL database. It is possible for an...
CVE-2019-16061HIGH8.8A number of files on the NETSAS Enigma NMS server 65.0.0 and prior are granted weak world-readable and world-writable pe...
CVE-2019-15656HIGH7.5D-Link DSL-2875AL and DSL-2877AL devices through 1.00.05 are prone to information disclosure via a simple crafted reques...
CVE-2019-15655HIGH7.5D-Link DSL-2875AL devices through 1.00.05 are prone to password disclosure via a simple crafted /romfile.cfg request to ...
CVE-2019-15654HIGH7.5Comba AC2400 devices are prone to password disclosure via a simple crafted /09/business/upgrade/upcfgAction.php?download...
CVE-2019-15653HIGH7.5Comba AP2600-I devices through A02,0202N00PD2 are prone to password disclosure via an insecure authentication mechanism....
CVE-2019-12127CRITICAL9.8In ONAP OOM through Dublin, by accessing an applicable port (30234, 30290, 32010, 30270, 30224, 30281, 30254, 30285, and...
CVE-2019-12126CRITICAL9.8In ONAP DCAE through Dublin, by accessing an applicable port (30234, 30290, 32010, 30270, 30224, 30281, 30254, 30285, an...
CVE-2019-12125CRITICAL9.8In ONAP Logging through Dublin, by accessing an applicable port (30234, 30290, 32010, 30270, 30224, 30281, 30254, 30285,...
CVE-2019-16382CRITICAL9.8An issue was discovered in Ivanti Workspace Control 10.3.110.0. One is able to bypass Ivanti's FileGuard folder protecti...
CVE-2019-11361HIGH8.8Zoho ManageEngine Remote Access Plus 10.0.258 does not validate user permissions properly, allowing for privilege escala...
CVE-2019-16012HIGH8.1A vulnerability in the web UI of Cisco SD-WAN Solution vManage software could allow an authenticated, remote attacker to...
CVE-2019-16010MEDIUM4.8A vulnerability in the web UI of the Cisco SD-WAN vManage software could allow an authenticated, remote attacker to cond...
CVE-2019-14878MEDIUM6.5In the __d2b function of the newlib libc library, all versions prior to 3.3.0 (see newlib/libc/stdlib/mprec.c), Balloc i...
CVE-2019-14877MEDIUM6.5In the __mdiff function of the newlib libc library, all versions prior to 3.3.0 (see newlib/libc/stdlib/mprec.c), Balloc...
CVE-2019-14876MEDIUM6.5In the __lshift function of the newlib libc library, all versions prior to 3.3.0 (see newlib/libc/stdlib/mprec.c), Ballo...
CVE-2019-14875MEDIUM6.5In the __multiply function of the newlib libc library, all versions prior to 3.3.0 (see newlib/libc/stdlib/mprec.c), Bal...
CVE-2019-14874MEDIUM6.5In the __i2b function of the newlib libc library, all versions prior to 3.3.0 (see newlib/libc/stdlib/mprec.c), Balloc i...
CVE-2019-14873MEDIUM6.5In the __multadd function of the newlib libc library, prior to versions 3.3.0 (see newlib/libc/stdlib/mprec.c), Balloc i...
CVE-2019-5104Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2019-9013. Reason: This candidate is a duplicate of C...
CVE-2019-12416MEDIUM6.1we got reports for 2 injection attacks against the DeltaSpike windowhandler.js. This is only active if a developer selec...
CVE-2019-20527MEDIUM6.1Ignite Realtime Openfire 4.4.1 allows XSS via the setup/setup-datasource-standard.jsp serverURL parameter.
CVE-2019-20524MEDIUM6.1ilchCMS 2.1.23 allows XSS via the index.php/partner/index Banner parameter.

Check if your code is affected by 2019 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now