2019 CVE Vulnerabilities

17,619 CVEs published in 2019.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2019-16701HIGH8.8pfSense through 2.3.4 through 2.4.4-p3 allows Remote Code Injection via a methodCall XML document with a pfsense.exec_ph...
CVE-2019-10428HIGH7.5Jenkins Aqua Security Scanner Plugin 3.0.17 and earlier transmitted configured credentials in plain text as part of the ...
CVE-2019-10412HIGH7.5Jenkins Inedo ProGet Plugin 1.2 and earlier transmitted configured credentials in plain text as part of the global Jenki...
CVE-2019-10411HIGH7.5Jenkins Inedo BuildMaster Plugin 2.4.0 and earlier transmitted configured credentials in plain text as part of the globa...
CVE-2019-5094HIGH7.5An exploitable code execution vulnerability exists in the quota file functionality of E2fsprogs 1.45.3. A specially craf...
CVE-2019-13527HIGH7.8In Rockwell Automation Arena Simulation Software Cat. 9502-Ax, Versions 16.00.00 and earlier, a maliciously crafted Aren...
CVE-2019-16754HIGH7.5RIOT 2019.07 contains a NULL pointer dereference in the MQTT-SN implementation (asymcute), potentially allowing an attac...
CVE-2019-14753HIGH7.5SICK FX0-GPNT00000 and FX0-GENT00000 devices through 3.4.0 have a Buffer Overflow
CVE-2019-13357HIGH7.8In Total Defense Anti-virus 9.0.0.773, resource acquisition from the untrusted search path C:\ used by caschelp.exe allo...
CVE-2019-13356HIGH7.8In Total Defense Anti-virus 9.0.0.773, insecure access control for the directory %PROGRAMDATA%\TotalDefense\Consumer\ISS...
CVE-2019-13355HIGH7.8In Total Defense Anti-virus 9.0.0.773, insecure access control for the directory %PROGRAMDATA%\TotalDefense\Consumer\ISS...
CVE-2019-16729HIGH7.8pam-python before 1.0.7-1 has an issue in regard to the default environment variable handling of Python, which could all...
CVE-2019-10754HIGH8.1Multiple classes used within Apereo CAS before release 6.1.0-RC5 makes use of apache commons-lang3 RandomStringUtils for...
CVE-2019-1367HIGH7.5A remote code execution vulnerability exists in the way that the scripting engine handles objects in memory in Internet ...
CVE-2019-1255HIGH7.5A denial of service vulnerability exists when Microsoft Defender improperly handles files, aka 'Microsoft Defender Denia...
CVE-2019-11277HIGH8.1Cloud Foundry NFS Volume Service, 1.7.x versions prior to 1.7.11 and 2.x versions prior to 2.3.0, is vulnerable to LDAP ...
CVE-2019-10996HIGH7.8Red Lion Controls Crimson, version 3.0 and prior and version 3.1 prior to release 3112.00, allow multiple vulnerabilitie...
CVE-2019-10984HIGH7.8Red Lion Controls Crimson, version 3.0 and prior and version 3.1 prior to release 3112.00, allow multiple vulnerabilitie...
CVE-2019-10978HIGH7.8Red Lion Controls Crimson, version 3.0 and prior and version 3.1 prior to release 3112.00, allow multiple vulnerabilitie...
CVE-2019-13063HIGH7.5Within Sahi Pro 8.0.0, an attacker can send a specially crafted URL to include any victim files on the system via the sc...
CVE-2019-16720HIGH7.5ZZZCMS zzzphp v1.7.2 does not properly restrict file upload in plugins/ueditor/php/controller.php?upfolder=news&action=c...
CVE-2019-16718HIGH7.8In radare2 before 3.9.0, a command injection vulnerability exists in bin_symbols() in libr/core/cbin.c. By using a craft...
CVE-2019-16714HIGH7.5In the Linux kernel before 5.2.14, rds6_inc_info_copy in net/rds/recv.c allows attackers to obtain sensitive information...
CVE-2019-16706HIGH8.8kkcms v1.3 has a CSRF vulnerablity that can add an user account via admin/cms_user_add.php.
CVE-2019-16660HIGH8.8joyplus-cms 1.6.0 has admin_ajax.php?action=savexml&tab=vodplay CSRF.

Check if your code is affected by 2019 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now