2019 CVE Vulnerabilities

17,620 CVEs published in 2019.

CVE IDSeverityCVSSDescription
CVE-2019-20478CRITICAL9.8In ruamel.yaml through 0.16.7, the load method allows remote code execution if the application calls this method with an...
CVE-2019-20477CRITICAL9.8PyYAML 5.1 through 5.1.2 has insufficient restrictions on the load and load_all functions because of a class deserializa...
CVE-2019-10791CRITICAL9.8promise-probe before 0.10.0 allows remote attackers to perform a command injection attack. The file, outputFile and opti...
CVE-2019-5613CRITICAL9.8In FreeBSD 12.0-RELEASE before 12.0-RELEASE-p13, a missing check in the ipsec packet processor allows reinjection of an ...
CVE-2019-18352HIGH8.2Improper access control exists on PHOENIX CONTACT FL NAT 2208 devices before V2.90 and FL NAT 2304-2GC-2SFP devices befo...
CVE-2019-15875LOW3.3In FreeBSD 12.1-STABLE before r354734, 12.1-RELEASE before 12.1-RELEASE-p2, 12.0-RELEASE before 12.0-RELEASE-p13, 11.3-S...
CVE-2019-10795MEDIUM6.3undefsafe before 2.0.3 is vulnerable to Prototype Pollution. The 'a' function could be tricked into adding or modifying ...
CVE-2019-10794MEDIUM6.3All versions of component-flatten are vulnerable to Prototype Pollution. The a function could be tricked into adding or ...
CVE-2019-10793MEDIUM6.3dot-object before 2.1.3 is vulnerable to Prototype Pollution. The set function could be tricked into adding or modifying...
CVE-2019-10792MEDIUM6.3bodymen before 1.1.1 is vulnerable to Prototype Pollution. The handler function could be tricked into adding or modifyin...
CVE-2019-19325MEDIUM6.1SilverStripe through 4.4.x before 4.4.5 and 4.5.x before 4.5.2 allows Reflected XSS on the login form and custom forms. ...
CVE-2019-10790HIGH7.5taffydb npm module, vulnerable in all versions up to and including 2.7.3, allows attackers to forge adding additional pr...
CVE-2019-20474MEDIUM4.3An issue was discovered in Zoho ManageEngine Remote Access Plus 10.0.447. The service to test the mail-server configurat...
CVE-2019-18998HIGH7.1Insufficient access control in the web interface of ABB Asset Suite versions 9.0 to 9.3, 9.4 prior to 9.4.2.6, 9.5 prior...
CVE-2019-12954MEDIUM5.4SolarWinds Network Performance Monitor (Orion Platform 2018, NPM 12.3, NetPath 1.1.3) allows XSS by authenticated users ...
CVE-2019-12825MEDIUM4.3Unauthorized Access to the Container Registry of other groups was discovered in GitLab Enterprise 12.0.0-pre. In other w...
CVE-2019-20456HIGH7.8Goverlan Reach Console before 9.50, Goverlan Reach Server before 3.50, and Goverlan Client Agent before 9.20.50 have an ...
CVE-2019-5187HIGH8.8An exploitable out-of-bounds write vulnerability exists in the TIFreadstripdata function of the igcore19d.dll library of...
CVE-2019-4392CRITICAL9.8HCL AppScan Standard Edition 9.0.3.13 and earlier uses hard-coded credentials which can be exploited by attackers to get...
CVE-2019-15594MEDIUM4.3GitLab 11.8 and later contains a security vulnerability that allows a user to obtain details of restricted pipelines via...
CVE-2019-15592MEDIUM4.3GitLab 12.2.2 and below contains a security vulnerability that allows a guest user in a private project to see the merge...
CVE-2019-13967HIGH7.5iTop 2.2.0 through 2.6.0 allows remote attackers to cause a denial of service (application outage) via many requests to ...
CVE-2019-13966MEDIUM6.1In iTop through 2.6.0, an XSS payload can be delivered in certain fields (such as icon) of the XML file used to build th...
CVE-2019-13965MEDIUM6.1Because of a lack of sanitization around error messages, multiple Reflective XSS issues exist in iTop through 2.6.0 via ...
CVE-2019-11215HIGH8.1In Combodo iTop 2.2.0 through 2.6.0, if the configuration file is writable, then execution of arbitrary code can be acco...

Check if your code is affected by 2019 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now