2019 CVE Vulnerabilities

17,620 CVEs published in 2019.

Filter:UNKNOWNClear
CVE IDSeverityCVSSDescription
CVE-2019-7838ColdFusion versions Update 3 and earlier, Update 10 and earlier, and Update 18 and earlier have a file extension blackli...
CVE-2019-10971The application (Network Configurator for DeviceNet Safety 3.41 and prior) searches for resources by means of an untrust...
CVE-2019-9676Buffer overflow vulnerability found in some Dahua IP Camera devices IPC-HFW1XXX,IPC-HDW1XXX,IPC-HFW2XXX Build before 201...
CVE-2019-3947Fuji Electric V-Server before 6.0.33.0 stores database credentials in project files as plaintext. An attacker that can g...
CVE-2019-3946Fuji Electric V-Server before 6.0.33.0 is vulnerable to denial of service via a crafted UDP message sent to port 8005. A...
CVE-2019-0308An authenticated attacker in SAP E-Commerce (Business-to-Consumer application), versions 7.3, 7.31, 7.32, 7.33, 7.54, ca...
CVE-2019-0307Diagnostics Agent in Solution Manager, version 7.2, stores several credentials such as SLD user connection as well as So...
CVE-2019-0306SAP HANA Extended Application Services (advanced model), version 1, allows authenticated low privileged XS Advanced Plat...
CVE-2019-0305Java Server Pages (JSPs) provided by the SAP NetWeaver Process Integration (SAP_XIESR and SAP_XITOOL: 7.10 to 7.11, 7.20...
CVE-2019-0304FTP Function of SAP NetWeaver AS ABAP Platform, versions- KRNL32NUC 7.21, 7.21EXT, 7.22, 7.22EXT, KRNL32UC 7.21, 7.21EXT...
CVE-2019-10926A vulnerability has been identified in SIMATIC MV400 family (All Versions < V7.0.6). Communication with the device is no...
CVE-2019-1036A cross-site-scripting (XSS) vulnerability exists when Microsoft SharePoint Server does not properly sanitize a speciall...
CVE-2019-1034A remote code execution vulnerability exists in Microsoft Word software when it fails to properly handle objects in memo...
CVE-2019-1033A cross-site-scripting (XSS) vulnerability exists when Microsoft SharePoint Server does not properly sanitize a speciall...
CVE-2019-1032A cross-site-scripting (XSS) vulnerability exists when Microsoft SharePoint Server does not properly sanitize a speciall...
CVE-2019-1031A cross-site-scripting (XSS) vulnerability exists when Microsoft SharePoint Server does not properly sanitize a speciall...
CVE-2019-1029A denial of service vulnerability exists in Skype for Business. An attacker who successfully exploited the vulnerability...
CVE-2019-0996A spoofing vulnerability exists in Azure DevOps Server when it improperly handles requests to authorize applications, re...
CVE-2019-0943An elevation of privilege vulnerability exists when Windows improperly handles calls to Advanced Local Procedure Call (A...
CVE-2019-12795daemon/gvfsdaemon.c in gvfsd from GNOME gvfs before 1.38.3, 1.40.x before 1.40.2, and 1.41.x before 1.41.3 opened a priv...
CVE-2019-12149SQL injection vulnerability in silverstripe/restfulserver module 1.0.x before 1.0.9, 2.0.x before 2.0.4, and 2.1.x befor...
CVE-2019-0196A vulnerability was found in Apache HTTP Server 2.4.17 to 2.4.38. Using fuzzed network input, the http/2 request handlin...
CVE-2019-12154XXE in the XML parser library in RealObjects PDFreactor before 10.1.10722 allows attackers to supply malicious XML conte...
CVE-2019-12153Lack of validation in the HTML parser in RealObjects PDFreactor before 10.1.10722 leads to SSRF, allowing attackers to a...
CVE-2019-12146A Directory Traversal issue was discovered in SSHServerAPI.dll in Progress ipswitch WS_FTP Server 2018 before 8.6.1. Att...

Check if your code is affected by 2019 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now