2019 CVE Vulnerabilities

17,624 CVEs published in 2019.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2019-16319HIGH7.5In Wireshark 3.0.0 to 3.0.3 and 2.6.0 to 2.6.10, the Gryphon dissector could go into an infinite loop. This was addresse...
CVE-2019-16318HIGH8.8In Pimcore before 5.7.1, an attacker with limited privileges can bypass file-extension restrictions via a 256-character ...
CVE-2019-16317HIGH8.8In Pimcore before 5.7.1, an attacker with limited privileges can trigger execution of a .phar file via a phar:// URL in ...
CVE-2019-16313HIGH7.5ifw8 Router ROM v4.31 allows credential disclosure by reading the action/usermanager.htm HTML source code.
CVE-2019-16311HIGH8.8NIUSHOP V1.11 has CSRF via search_info to index.php.
CVE-2019-16294HIGH7.8SciLexer.dll in Scintilla in Notepad++ (x64) before 7.7 allows remote code execution or denial of service via Unicode ch...
CVE-2019-16305HIGH8.8In MobaXterm 11.1 and 12.1, the protocol handler is vulnerable to command injection. A crafted link can trigger a popup ...
CVE-2019-5484HIGH7.5Bower before 1.8.8 has a path traversal vulnerability permitting file write in arbitrary locations via install command, ...
CVE-2019-11660HIGH7.8Privileges manipulation in Micro Focus Data Protector, versions 10.00, 10.01, 10.02, 10.03, 10.04, 10.10, 10.20, 10.30, ...
CVE-2019-5315HIGH7.2A command injection vulnerability is present in the web management interface of ArubaOS that permits an authenticated us...
CVE-2019-16293HIGH8.8The Create Discoveries feature of Open-AudIT before 3.2.0 allows an authenticated attacker to execute arbitrary OS comma...
CVE-2019-13532HIGH7.5CODESYS V3 web server, all versions prior to 3.5.14.10, allows an attacker to send specially crafted http or https reque...
CVE-2019-10937HIGH7.5A vulnerability has been identified in SIMATIC TDC CP51M1 (All versions < V1.1.7). An attacker with network access to th...
CVE-2019-16288HIGH7.5On Tenda N301 wireless routers, a long string in the wifiSSID parameter of a goform/setWifi POST request causes the devi...
CVE-2019-12516HIGH8.8The slickquiz plugin through 1.3.7.1 for WordPress allows SQL Injection by Subscriber users, as demonstrated by a /wp-ad...
CVE-2019-16277HIGH7.8PicoC 2.1 has a heap-based buffer overflow in StringStrcpy in cstdlib/string.c when called from ExpressionParseFunctionC...
CVE-2019-13534HIGH7.2Philips IntelliVue WLAN, portable patient monitors, WLAN Version A, Firmware A.03.09, WLAN Version A, Firmware A.03.09, ...
CVE-2019-13530HIGH7.2Philips IntelliVue WLAN, portable patient monitors, WLAN Version A, Firmware A.03.09, WLAN Version A, Firmware A.03.09, ...
CVE-2019-8076HIGH7.8Adobe application manager installer version 10.0 have an Insecure Library Loading (DLL hijacking) vulnerability. Success...
CVE-2019-11899HIGH7.5An unauthenticated attacker can achieve unauthorized access to sensitive data by exploiting Windows SMB protocol on a cl...
CVE-2019-11774HIGH7.4Prior to 0.1, all builds of Eclipse OMR contain a bug where the loop versioner may fail to privatize a value that is pul...
CVE-2019-11773HIGH7.8Prior to 0.1, AIX builds of Eclipse OMR contain unused RPATHs which may facilitate code injection and privilege elevatio...
CVE-2019-6007HIGH8.8Integer overflow vulnerability in apng-drawable 1.0.0 to 1.6.0 allows an attacker to cause a denial of service (DoS) con...
CVE-2019-5996HIGH8.8SQL injection vulnerability in the Video Insight VMS 7.3.2.5 and earlier allows remote authenticated attackers to execut...
CVE-2019-5993HIGH8.8Cross-site request forgery (CSRF) vulnerability in Category Specific RSS feed Subscription version v2.0 and earlier allo...

Check if your code is affected by 2019 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now