2019 CVE Vulnerabilities

17,624 CVEs published in 2019.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2019-16714HIGH7.5In the Linux kernel before 5.2.14, rds6_inc_info_copy in net/rds/recv.c allows attackers to obtain sensitive information...
CVE-2019-16706HIGH8.8kkcms v1.3 has a CSRF vulnerablity that can add an user account via admin/cms_user_add.php.
CVE-2019-16660HIGH8.8joyplus-cms 1.6.0 has admin_ajax.php?action=savexml&tab=vodplay CSRF.
CVE-2019-16659HIGH8.8TuziCMS 2.0.6 has index.php/manage/link/do_add CSRF.
CVE-2019-16658HIGH8.8TuziCMS 2.0.6 has index.php/manage/notice/do_add CSRF.
CVE-2019-16655HIGH7.5joyplus-cms 1.6.0 allows reinstallation if the install/ URI remains available.
CVE-2019-15138HIGH7.5The html-pdf package 2.2.0 for Node.js has an arbitrary file read vulnerability via an HTML file that uses XMLHttpReques...
CVE-2019-16645HIGH8.6An issue was discovered in Embedthis GoAhead 2.5.0. Certain pages (such as goform/login and config/log_off_page.htm) cre...
CVE-2019-14816HIGH7.8There is heap-based buffer overflow in kernel, all versions up to, excluding 5.3, in the marvell wifi chip driver in Lin...
CVE-2019-14814HIGH7.8There is heap-based buffer overflow in Linux kernel, all versions up to, excluding 5.3, in the marvell wifi chip driver ...
CVE-2019-11326HIGH8.8An issue was discovered on Topcon Positioning Net-G5 GNSS Receiver devices with firmware 5.2.2. The web interface of the...
CVE-2019-11280HIGH8.8Pivotal Apps Manager, included in Pivotal Application Service versions 2.3.x prior to 2.3.18, 2.4.x prior to 2.4.14, 2.5...
CVE-2019-4565HIGH7.5IBM Security Key Lifecycle Manager 3.0 and 3.0.1 does not require that users should have strong passwords by default, wh...
CVE-2019-15089HIGH8.8An issue was discovered in PRiSE adAS 1.7.0. Forms have no CSRF protection, letting an attacker execute actions as the a...
CVE-2019-15087HIGH7.2An issue was discovered in PRiSE adAS 1.7.0. An authenticated user can change the function used to hash passwords to any...
CVE-2019-15085HIGH7.5An issue was discovered in PRiSE adAS 1.7.0. The current database password is embedded in the change password form.
CVE-2019-16531HIGH8.8LayerBB before 1.1.4 has multiple CSRF issues, as demonstrated by changing the System Settings via admin/general.php.
CVE-2019-9719HIGH8.8A stack-based buffer overflow in the subtitle decoder in Libav 12.3 allows attackers to corrupt the stack via a crafted ...
CVE-2019-14821HIGH8.8An out-of-bounds access issue was found in the Linux kernel, all versions through 5.3, in the way Linux kernel's KVM hyp...
CVE-2019-15033HIGH7.7Pydio 6.0.8 allows Authenticated SSRF during a Remote Link Feature download. An attacker can specify an intranet address...
CVE-2019-16510HIGH7.5libIEC61850 through 1.3.3 has a use-after-free in MmsServer_waitReady in mms/iso_mms/server/mms_server.c, as demonstrate...
CVE-2019-16412HIGH7.5In goform/setSysTools on Tenda N301 wireless routers, attackers can trigger a device crash via a zero wanMTU value. (Pro...
CVE-2019-15001HIGH7.2The Jira Importers Plugin in Atlassian Jira Server and Data Cente from version with 7.0.10 before 7.6.16, from 7.7.0 bef...
CVE-2019-14994HIGH7.5The Customer Context Filter in Atlassian Jira Service Desk Server and Jira Service Desk Data Center before version 3.9.1...
CVE-2019-6010HIGH7.8Integer overflow vulnerability in LINE(Android) from 4.4.0 to the version before 9.15.1 allows remote attackers to cause...

Check if your code is affected by 2019 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now