2019 CVE Vulnerabilities

17,619 CVEs published in 2019.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2019-17583HIGH7.5idreamsoft iCMS 7.0.15 allows remote attackers to cause a denial of service (resource consumption) via a query for many ...
CVE-2019-17511HIGH7.5There are some web interfaces without authentication requirements on D-Link DIR-412 A1-1.14WW routers. An attacker can g...
CVE-2019-16519HIGH7.8ESET Cyber Security 6.7.900.0 for macOS allows a local attacker to execute unauthorized commands as root by abusing an u...
CVE-2019-9745HIGH7.8CloudCTI HIP Integrator Recognition Configuration Tool allows privilege escalation via its EXQUISE integration. This too...
CVE-2019-17575HIGH7.2A file-rename filter bypass exists in admin/media/rename.php in WBCE CMS 1.4.0 and earlier. This can be exploited by an ...
CVE-2019-17547HIGH8.8In ImageMagick before 7.0.8-62, TraceBezier in MagickCore/draw.c has a use-after-free.
CVE-2019-17546HIGH8.8tif_getimage.c in LibTIFF through 4.0.10, as used in GDAL through 3.0.1 and other products, has an integer overflow that...
CVE-2019-17543HIGH8.1LZ4 before 1.9.2 has a heap-based buffer overflow in LZ4_write32 (related to LZ4_compress_destSize), affecting applicati...
CVE-2019-17541HIGH8.8ImageMagick before 7.0.8-55 has a use-after-free in DestroyStringInfo in MagickCore/string.c because the error manager i...
CVE-2019-17540HIGH8.8ImageMagick before 7.0.8-54 has a heap-based buffer overflow in ReadPSInfo in coders/ps.c.
CVE-2019-17501HIGH8.8Centreon 19.04 allows attackers to execute arbitrary OS commands via the Command Line field of main.php?p=60807&type=4 (...
CVE-2019-17538HIGH7.5Jiangnan Online Judge (aka jnoj) 0.8.0 has Directory Traversal for file reading via the web/polygon/problem/viewfile?id=...
CVE-2019-17537HIGH7.5Jiangnan Online Judge (aka jnoj) 0.8.0 has Directory Traversal for file deletion via the web/polygon/problem/deletefile?...
CVE-2019-17534HIGH8.8vips_foreign_load_gif_scan_image in foreign/gifload.c in libvips before 8.8.2 tries to access a color map before a DGifG...
CVE-2019-17533HIGH8.2Mat_VarReadNextInfo4 in mat4.c in MATIO 1.5.17 omits a certain '\0' character, leading to a heap-based buffer over-read ...
CVE-2019-17532HIGH7.5An issue was discovered on Belkin Wemo Switch 28B WW_2.00.11057.PVT-OWRT-SNS devices. They allow remote attackers to cau...
CVE-2019-17530HIGH7.8An issue was discovered in Bento4 1.5.1.0. There is a heap-based buffer over-read in AP4_PrintInspector::AddField in Cor...
CVE-2019-17529HIGH7.8An issue was discovered in Bento4 1.5.1.0. There is a heap-based buffer over-read in AP4_CencSampleEncryption::DoInspect...
CVE-2019-17528HIGH7.5An issue was discovered in Bento4 1.5.1.0. There is a SEGV in the function AP4_TfhdAtom::SetDefaultSampleSize at Core/Ap...
CVE-2019-17502HIGH7.5Hydra through 0.1.8 has a NULL pointer dereference and daemon crash when processing POST requests that lack a Content-Le...
CVE-2019-17514HIGH7.5library/glob.html in the Python 2 and 3 documentation before 2016 has potentially misleading information about whether s...
CVE-2019-17507HIGH7.5An issue was discovered on D-Link DIR-816 A1 1.06 devices. An attacker could access management pages of the router via a...
CVE-2019-17505HIGH7.5D-Link DAP-1320 A2-V1.21 routers have some web interfaces without authentication requirements, as demonstrated by uplink...
CVE-2019-2215HIGH7.8A use-after-free in binder.c allows an elevation of privilege from an application to the Linux Kernel. No user interacti...
CVE-2019-2186HIGH8.8In GetMBheader of combined_decode.cpp, there is a possible out of bounds write due to a missing bounds check. This could...

Check if your code is affected by 2019 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now