2019 CVE Vulnerabilities

17,619 CVEs published in 2019.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2019-4558HIGH7.8A security vulnerability has been identified in all levels of IBM Spectrum Scale V5.0.0.0 through V5.0.3.2 and IBM Spect...
CVE-2019-17375HIGH8.8cPanel before 82.0.15 allows API token credentials to persist after an account has been renamed or terminated (SEC-517).
CVE-2019-17128HIGH7.5Netreo OmniCenter through 12.1.1 allows unauthenticated SQL Injection (Boolean Based Blind) in the redirect parameters a...
CVE-2019-15226HIGH7.5Upon receiving each incoming request header data, Envoy will iterate over existing request headers to verify that the to...
CVE-2019-13529HIGH8.8An attacker could send a malicious link to an authenticated operator, which may allow remote attackers to perform action...
CVE-2019-17372HIGH8.1Certain NETGEAR devices allow remote attackers to disable all authentication requirements by visiting genieDisableLanCha...
CVE-2019-17370HIGH7.2OTCMS v3.85 allows arbitrary PHP Code Execution because admin/sysCheckFile_deal.php blocks "into outfile" in a SELECT st...
CVE-2019-17353HIGH8.2An issue discovered on D-Link DIR-615 devices with firmware version 20.05 and 20.07. wan.htm can be accessed directly wi...
CVE-2019-15719HIGH8Altair PBS Professional through 19.1.2 allows Privilege Escalation because an attacker can send a message directly to pb...
CVE-2019-13051HIGH8.8Pi-Hole 4.3 allows Command Injection.
CVE-2019-17186HIGH8.8/var/WEB-GUI/cgi-bin/telnet.cgi on FiberHome HG2201T 1.00.M5007_JS_201804 devices allows pre-authentication remote code ...
CVE-2019-14846HIGH7.8In Ansible, all Ansible Engine versions up to ansible-engine 2.8.5, ansible-engine 2.7.13, ansible-engine 2.6.19, were l...
CVE-2019-10969HIGH7.2Moxa EDR 810, all versions 5.1 and prior, allows an authenticated attacker to abuse the ping feature to execute unauthor...
CVE-2019-17187HIGH7.5/var/WEB-GUI/cgi-bin/downloadfile.cgi on FiberHome HG2201T 1.00.M5007_JS_201804 devices allows pre-authentication Direct...
CVE-2019-17359HIGH7.5The ASN.1 parser in Bouncy Castle Crypto (aka BC Java) 1.63 can trigger a large attempted memory allocation, and resulta...
CVE-2019-17352HIGH7.5In JFinal cos before 2019-08-13, as used in JFinal 4.4, there is a vulnerability that can bypass the isSafeFile() functi...
CVE-2019-17107HIGH8.8minPlayCommand.php in Centreon Web before 2.8.27 allows authenticated attackers to execute arbitrary code via the comman...
CVE-2019-17104HIGH7.5In Centreon VM through 19.04.3, the cookie configuration within the Apache HTTP Server does not protect against theft be...
CVE-2019-16929HIGH7.5Auth0 auth0.net before 6.5.4 has Incorrect Access Control because IdentityTokenValidator can be accidentally used to val...
CVE-2019-14657HIGH8.8Yealink phones through 2019-08-04 have an issue with OpenVPN file upload. They execute tar as root to extract files, but...
CVE-2019-14656HIGH8.8Yealink phones through 2019-08-04 do not properly check user roles in POST requests. Consequently, the default User acco...
CVE-2019-17262HIGH7.8XnView Classic 2.49.1 allows a User Mode Write AV starting at Xwsq+0x0000000000001fc0.
CVE-2019-17261HIGH7.8XnView Classic 2.49.1 allows a User Mode Write AV starting at Xwsq+0x0000000000001e51.
CVE-2019-17260HIGH7.8MPC-HC through 1.7.13 allows a Read Access Violation on a Block Data Move starting at mpc_hc!memcpy+0x000000000000004e.
CVE-2019-17259HIGH7.8KMPlayer 4.2.2.31 allows a User Mode Write AV starting at utils!src_new+0x000000000014d6ee.

Check if your code is affected by 2019 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now