2019 CVE Vulnerabilities

17,619 CVEs published in 2019.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2019-11661HIGH8.3Allow changes to some table by non-SysAdmin in Micro Focus Service Manager product versions 9.30, 9.31, 9.32, 9.33, 9.34...
CVE-2019-5534HIGH7.7VMware vCenter Server (6.7.x prior to 6.7 U3, 6.5 prior to 6.5 U3 and 6.0 prior to 6.0 U3j) contains an information disc...
CVE-2019-5532HIGH7.7VMware vCenter Server (6.7.x prior to 6.7 U3, 6.5 prior to 6.5 U3 and 6.0 prior to 6.0 U3j) contains an information disc...
CVE-2019-5042HIGH8.8An exploitable Use-After-Free vulnerability exists in the way FunctionType 0 PDF elements are processed in Aspose.PDF 19...
CVE-2019-13552HIGH8.8In WebAccess versions 8.4.1 and prior, multiple command injection vulnerabilities are caused by a lack of proper validat...
CVE-2019-9679HIGH8.8Some of Dahua's Debug functions do not have permission separation. Low-privileged users can use the Debug function after...
CVE-2019-9678HIGH7.5Some Dahua products have the problem of denial of service during the login process. An attacker can cause a device crash...
CVE-2019-14458HIGH7.5VIVOTEK IP Camera devices with firmware before 0x20x allow a denial of service via a crafted HTTP header.
CVE-2019-14252HIGH7.2An issue was discovered in the secure portal in Publisure 2.1.2. Once successfully authenticated as an administrator, on...
CVE-2019-15843HIGH7.4A malicious file upload vulnerability was discovered in Xiaomi Millet mobile phones 1-6.3.9.3. A particular condition in...
CVE-2019-16403HIGH8.8In Webkul Bagisto before 0.1.5, the functionalities for customers to change their own values (such as address, review, o...
CVE-2019-16396HIGH7.8GnuCOBOL 2.2 has a use-after-free in the end_scope_of_program_name() function in cobc/parser.y via crafted COBOL source ...
CVE-2019-16395HIGH7.8GnuCOBOL 2.2 has a stack-based buffer overflow in the cb_name() function in cobc/tree.c via crafted COBOL source code.
CVE-2019-6839HIGH8.8A CWE-434: Unrestricted Upload of File with Dangerous Type vulnerability exists in U.motion Server (MEG6501-0001 - U.mot...
CVE-2019-6836HIGH7.5A CWE-863: Incorrect Authorization vulnerability exists in U.motion Server (MEG6501-0001 - U.motion KNX server, MEG6501-...
CVE-2019-6832HIGH8.3A CWE-287: Authentication vulnerability exists in spaceLYnk (all versions before 2.4.0) and Wiser for KNX (all versions ...
CVE-2019-6831HIGH8.6A CWE-754: Improper Check for Unusual or Exceptional Conditions vulnerability exists in BMXNOR0200H Ethernet / Serial RT...
CVE-2019-6829HIGH7.5A CWE-248: Uncaught Exception vulnerability exists in Modicon M580 (firmware version prior to V2.90) and Modicon M340 (f...
CVE-2019-6828HIGH7.5A CWE-248: Uncaught Exception vulnerability exists Modicon M580 (firmware version prior to V2.90), Modicon M340 (firmwar...
CVE-2019-6826HIGH7.8A CWE-426: Untrusted Search Path vulnerability exists in SoMachine HVAC v2.4.1 and earlier versions, which could cause a...
CVE-2019-6813HIGH7.5A CWE-754: Improper Check for Unusual or Exceptional Conditions vulnerability exists in BMXNOR0200H Ethernet / Serial RT...
CVE-2019-6811HIGH7.5An Improper Check for Unusual or Exceptional Conditions (CWE-754) vulnerability exists in Modicon Quantum 140 NOE771x1 v...
CVE-2019-6810HIGH8.8CWE-284: Improper Access Control vulnerability exists in BMXNOR0200H Ethernet / Serial RTU module (all firmware versions...
CVE-2019-6809HIGH7.5A CWE-248: Uncaught Exception vulnerability exists in Modicon M580 (firmware versions prior to V2.90), Modicon M340 (fir...
CVE-2019-13538HIGH8.63S-Smart Software Solutions GmbH CODESYS V3 Library Manager, all versions prior to 3.5.16.0, allows the system to displa...

Check if your code is affected by 2019 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now