2019 CVE Vulnerabilities

17,624 CVEs published in 2019.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2019-17043HIGH7.8An issue was discovered in BMC Patrol Agent 9.0.10i. Weak execution permissions on the best1collect.exe SUID binary coul...
CVE-2019-16279HIGH7.5A memory error in the function SSL_accept in nostromo nhttpd through 1.9.6 allows an attacker to trigger a denial of ser...
CVE-2019-14226HIGH8.1OX App Suite through 7.10.2 has Insecure Permissions.
CVE-2019-17583HIGH7.5idreamsoft iCMS 7.0.15 allows remote attackers to cause a denial of service (resource consumption) via a query for many ...
CVE-2019-17511HIGH7.5There are some web interfaces without authentication requirements on D-Link DIR-412 A1-1.14WW routers. An attacker can g...
CVE-2019-16519HIGH7.8ESET Cyber Security 6.7.900.0 for macOS allows a local attacker to execute unauthorized commands as root by abusing an u...
CVE-2019-9745HIGH7.8CloudCTI HIP Integrator Recognition Configuration Tool allows privilege escalation via its EXQUISE integration. This too...
CVE-2019-17575HIGH7.2A file-rename filter bypass exists in admin/media/rename.php in WBCE CMS 1.4.0 and earlier. This can be exploited by an ...
CVE-2019-17547HIGH8.8In ImageMagick before 7.0.8-62, TraceBezier in MagickCore/draw.c has a use-after-free.
CVE-2019-17546HIGH8.8tif_getimage.c in LibTIFF through 4.0.10, as used in GDAL through 3.0.1 and other products, has an integer overflow that...
CVE-2019-17543HIGH8.1LZ4 before 1.9.2 has a heap-based buffer overflow in LZ4_write32 (related to LZ4_compress_destSize), affecting applicati...
CVE-2019-17541HIGH8.8ImageMagick before 7.0.8-55 has a use-after-free in DestroyStringInfo in MagickCore/string.c because the error manager i...
CVE-2019-17540HIGH8.8ImageMagick before 7.0.8-54 has a heap-based buffer overflow in ReadPSInfo in coders/ps.c.
CVE-2019-17501HIGH8.8Centreon 19.04 allows attackers to execute arbitrary OS commands via the Command Line field of main.php?p=60807&type=4 (...
CVE-2019-17538HIGH7.5Jiangnan Online Judge (aka jnoj) 0.8.0 has Directory Traversal for file reading via the web/polygon/problem/viewfile?id=...
CVE-2019-17537HIGH7.5Jiangnan Online Judge (aka jnoj) 0.8.0 has Directory Traversal for file deletion via the web/polygon/problem/deletefile?...
CVE-2019-17534HIGH8.8vips_foreign_load_gif_scan_image in foreign/gifload.c in libvips before 8.8.2 tries to access a color map before a DGifG...
CVE-2019-17533HIGH8.2Mat_VarReadNextInfo4 in mat4.c in MATIO 1.5.17 omits a certain '\0' character, leading to a heap-based buffer over-read ...
CVE-2019-17532HIGH7.5An issue was discovered on Belkin Wemo Switch 28B WW_2.00.11057.PVT-OWRT-SNS devices. They allow remote attackers to cau...
CVE-2019-17530HIGH7.8An issue was discovered in Bento4 1.5.1.0. There is a heap-based buffer over-read in AP4_PrintInspector::AddField in Cor...
CVE-2019-17529HIGH7.8An issue was discovered in Bento4 1.5.1.0. There is a heap-based buffer over-read in AP4_CencSampleEncryption::DoInspect...
CVE-2019-17528HIGH7.5An issue was discovered in Bento4 1.5.1.0. There is a SEGV in the function AP4_TfhdAtom::SetDefaultSampleSize at Core/Ap...
CVE-2019-17502HIGH7.5Hydra through 0.1.8 has a NULL pointer dereference and daemon crash when processing POST requests that lack a Content-Le...
CVE-2019-17514HIGH7.5library/glob.html in the Python 2 and 3 documentation before 2016 has potentially misleading information about whether s...
CVE-2019-17507HIGH7.5An issue was discovered on D-Link DIR-816 A1 1.06 devices. An attacker could access management pages of the router via a...

Check if your code is affected by 2019 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now