2019 CVE Vulnerabilities

17,620 CVEs published in 2019.

CVE IDSeverityCVSSDescription
CVE-2019-19607CRITICAL9.8A SQL injection vulnerability in the web conferencing component of Mitel MiCollab AWV before 8.1.2.2 could allow an unau...
CVE-2019-19371MEDIUM6.1A cross-site scripting (XSS) vulnerability in the web conferencing component of Mitel MiCollab AWV before 8.1.2.2 could ...
CVE-2019-19370MEDIUM6.1A cross-site scripting (XSS) vulnerability in the web conferencing component of the Mitel MiCollab application before 9....
CVE-2019-18863MEDIUM5.9A key length vulnerability in the implementation of the SRTP 128-bit key on Mitel 6800 and 6900 SIP series phones, versi...
CVE-2019-18903CRITICAL9.8A Use After Free vulnerability in wicked of SUSE Linux Enterprise Server 12, SUSE Linux Enterprise Server 15; openSUSE L...
CVE-2019-18902CRITICAL9.8A Use After Free vulnerability in wicked of SUSE Linux Enterprise Server 12, SUSE Linux Enterprise Server 15; openSUSE L...
CVE-2019-14892CRITICAL9.8A flaw was discovered in jackson-databind in versions before 2.9.10, 2.8.11.5 and 2.6.7.3, where it would permit polymor...
CVE-2019-20489CRITICAL9.8An issue was discovered on NETGEAR WNR1000V4 1.1.0.54 devices. The web management interface (setup.cgi) has an authentic...
CVE-2019-20488CRITICAL9.8An issue was discovered on NETGEAR WNR1000V4 1.1.0.54 devices. Multiple actions within the web management interface (set...
CVE-2019-20487HIGH8.8An issue was discovered on NETGEAR WNR1000V4 1.1.0.54 devices. Multiple actions within the WNR1000V4 web management cons...
CVE-2019-20486MEDIUM6.1An issue was discovered on NETGEAR WNR1000V4 1.1.0.54 devices. Multiple pages (setup.cgi and adv_index.htm) within the w...
CVE-2019-18901MEDIUM5.5A UNIX Symbolic Link (Symlink) Following vulnerability in the mysql-systemd-helper of the mariadb packaging of SUSE Linu...
CVE-2019-18897HIGH7.8A UNIX Symbolic Link (Symlink) Following vulnerability in the packaging of salt of SUSE Linux Enterprise Server 12, SUSE...
CVE-2019-12183HIGH7.5Incorrect Access Control in Safescan Timemoto TM-616 and TA-8000 series allows remote attackers to read any file via the...
CVE-2019-17026HIGH8.8Incorrect alias information in IonMonkey JIT compiler for setting array elements could lead to a type confusion. We are ...
CVE-2019-7007HIGH8.6A directory traversal vulnerability has been found in the Avaya Equinox Management(iView)versions R9.1.9.0 and earlier. ...
CVE-2019-4301HIGH8.4BigFix Self-Service Application (SSA) is vulnerable to arbitrary code execution if Javascript code is included in Runnin...
CVE-2019-10805HIGH7.5valib through 2.0.0 allows Internal Property Tampering. A maliciously crafted JavaScript object can bypass several inspe...
CVE-2019-10804CRITICAL9.8serial-number through 1.3.0 allows execution of arbritary commands. The "cmdPrefix" argument in serialNumber function is...
CVE-2019-10803CRITICAL9.8push-dir through 0.4.1 allows execution of arbritary commands. Arguments provided as part of the variable "opt.branch" i...
CVE-2019-10802CRITICAL9.8giting version prior to 0.0.8 allows execution of arbritary commands. The first argument "repo" of function "pull()" is ...
CVE-2019-10801CRITICAL9.8enpeem through 2.2.0 allows execution of arbitrary commands. The "options.dir" argument is provided to the "exec" functi...
CVE-2019-19943HIGH7.5The HTTP service in quickweb.exe in Pablo Quick 'n Easy Web Server 3.3.8 allows Remote Unauthenticated Heap Memory Corru...
CVE-2019-15609CRITICAL9.8The kill-port-process package version < 2.2.0 is vulnerable to a Command Injection vulnerability.
CVE-2019-10064HIGH7.5hostapd before 2.6, in EAP mode, makes calls to the rand() and random() standard library functions without any preceding...

Check if your code is affected by 2019 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now