2019 CVE Vulnerabilities

17,624 CVEs published in 2019.

Filter:UNKNOWNClear
CVE IDSeverityCVSSDescription
CVE-2019-7839——ColdFusion versions Update 3 and earlier, Update 10 and earlier, and Update 18 and earlier have a command injection vuln...
CVE-2019-7838——ColdFusion versions Update 3 and earlier, Update 10 and earlier, and Update 18 and earlier have a file extension blackli...
CVE-2019-10971——The application (Network Configurator for DeviceNet Safety 3.41 and prior) searches for resources by means of an untrust...
CVE-2019-9676——Buffer overflow vulnerability found in some Dahua IP Camera devices IPC-HFW1XXX,IPC-HDW1XXX,IPC-HFW2XXX Build before 201...
CVE-2019-3947——Fuji Electric V-Server before 6.0.33.0 stores database credentials in project files as plaintext. An attacker that can g...
CVE-2019-3946——Fuji Electric V-Server before 6.0.33.0 is vulnerable to denial of service via a crafted UDP message sent to port 8005. A...
CVE-2019-0308——An authenticated attacker in SAP E-Commerce (Business-to-Consumer application), versions 7.3, 7.31, 7.32, 7.33, 7.54, ca...
CVE-2019-0307——Diagnostics Agent in Solution Manager, version 7.2, stores several credentials such as SLD user connection as well as So...
CVE-2019-0306——SAP HANA Extended Application Services (advanced model), version 1, allows authenticated low privileged XS Advanced Plat...
CVE-2019-0305——Java Server Pages (JSPs) provided by the SAP NetWeaver Process Integration (SAP_XIESR and SAP_XITOOL: 7.10 to 7.11, 7.20...
CVE-2019-0304——FTP Function of SAP NetWeaver AS ABAP Platform, versions- KRNL32NUC 7.21, 7.21EXT, 7.22, 7.22EXT, KRNL32UC 7.21, 7.21EXT...
CVE-2019-10926——A vulnerability has been identified in SIMATIC MV400 family (All Versions < V7.0.6). Communication with the device is no...
CVE-2019-1036——A cross-site-scripting (XSS) vulnerability exists when Microsoft SharePoint Server does not properly sanitize a speciall...
CVE-2019-1034——A remote code execution vulnerability exists in Microsoft Word software when it fails to properly handle objects in memo...
CVE-2019-1033——A cross-site-scripting (XSS) vulnerability exists when Microsoft SharePoint Server does not properly sanitize a speciall...
CVE-2019-1032——A cross-site-scripting (XSS) vulnerability exists when Microsoft SharePoint Server does not properly sanitize a speciall...
CVE-2019-1031——A cross-site-scripting (XSS) vulnerability exists when Microsoft SharePoint Server does not properly sanitize a speciall...
CVE-2019-1029——A denial of service vulnerability exists in Skype for Business. An attacker who successfully exploited the vulnerability...
CVE-2019-0996——A spoofing vulnerability exists in Azure DevOps Server when it improperly handles requests to authorize applications, re...
CVE-2019-0943——An elevation of privilege vulnerability exists when Windows improperly handles calls to Advanced Local Procedure Call (A...
CVE-2019-12795——daemon/gvfsdaemon.c in gvfsd from GNOME gvfs before 1.38.3, 1.40.x before 1.40.2, and 1.41.x before 1.41.3 opened a priv...
CVE-2019-12149——SQL injection vulnerability in silverstripe/restfulserver module 1.0.x before 1.0.9, 2.0.x before 2.0.4, and 2.1.x befor...
CVE-2019-0196——A vulnerability was found in Apache HTTP Server 2.4.17 to 2.4.38. Using fuzzed network input, the http/2 request handlin...
CVE-2019-12154——XXE in the XML parser library in RealObjects PDFreactor before 10.1.10722 allows attackers to supply malicious XML conte...
CVE-2019-12153——Lack of validation in the HTML parser in RealObjects PDFreactor before 10.1.10722 leads to SSRF, allowing attackers to a...

Check if your code is affected by 2019 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now