2019 CVE Vulnerabilities

17,619 CVEs published in 2019.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2019-11497HIGH7.5In Couchbase Server 5.0.0, when an invalid Remote Cluster Certificate was entered as part of the reference creation, XDC...
CVE-2019-11467HIGH7.5In Couchbase Server 4.6.3 and 5.5.0, secondary indexing encodes the entries to be indexed using collatejson. When index ...
CVE-2019-12105HIGH8.2In Supervisor through 4.0.2, an unauthenticated user can read log files or restart a service. Note: The maintainer respo...
CVE-2019-0365HIGH7.5SAP Kernel (RFC), KRNL32NUC, KRNL32UC and KRNL64NUC before versions 7.21, 7.21EXT, 7.22, 7.22EXT, KRNL64UC, before versi...
CVE-2019-0363HIGH7.1Attackers may misuse an HTTP/REST endpoint of SAP HANA Extended Application Services (Advanced model), before version 1....
CVE-2019-0355HIGH7.2SAP NetWeaver Application Server Java Web Container, ENGINEAPI (before versions 7.10, 7.20, 7.30, 7.31, 7.40, 7.50) and ...
CVE-2019-0352HIGH7.5In SAP Business Objects Business Intelligence Platform, before versions 4.1, 4.2 and 4.3, some dynamic pages (like jsp) ...
CVE-2019-16106HIGH7.5The Recruitment module in Humanica Humatrix 7 1.0.0.203 and 1.0.0.681 allows an unauthenticated attacker to change the p...
CVE-2019-12401HIGH7.5Solr versions 1.3.0 to 1.4.1, 3.1.0 to 3.6.2 and 4.0.0 to 4.10.4 are vulnerable to an XML resource consumption attack (a...
CVE-2019-16187HIGH7.5Limesurvey before 3.17.14 uses an anti-CSRF cookie without the HttpOnly flag, which allows attackers to access a cookie ...
CVE-2019-16186HIGH7.2In Limesurvey before 3.17.14, admin users can access the plugin manager without proper permissions.
CVE-2019-16185HIGH7.2In Limesurvey before 3.17.14, admin users can view, update, or delete reserved menu entries without proper permissions.
CVE-2019-16177HIGH7.5In Limesurvey before 3.17.14, the entire database is exposed through browser caching.
CVE-2019-16174HIGH8.8An XML injection vulnerability was found in Limesurvey before 3.17.14 that allows remote attackers to import specially c...
CVE-2019-6793HIGH7An issue was discovered in GitLab Enterprise Edition before 11.5.8, 11.6.x before 11.6.6, and 11.7.x before 11.7.1. The ...
CVE-2019-6788HIGH7.5An issue was discovered in GitLab Community and Enterprise Edition before 11.5.8, 11.6.x before 11.6.6, and 11.7.x befor...
CVE-2019-6783HIGH8.8An issue was discovered in GitLab Community and Enterprise Edition before 11.5.8, 11.6.x before 11.6.6, and 11.7.x befor...
CVE-2019-6782HIGH7.5An issue was discovered in GitLab Community and Enterprise Edition before 11.5.8, 11.6.x before 11.6.6, and 11.7.x befor...
CVE-2019-11605HIGH7.5An issue was discovered in GitLab Community and Enterprise Edition 11.8.x before 11.8.10, 11.9.x before 11.9.11, and 11....
CVE-2019-5473HIGH7.2An authentication issue was discovered in GitLab that allowed a bypass of email verification. This was addressed in GitL...
CVE-2019-16163HIGH7.5Oniguruma before 6.9.3 allows Stack Exhaustion in regcomp.c because of recursion in regparse.c.
CVE-2019-16162HIGH7.5Onigmo through 6.2.0 has an out-of-bounds read in parse_char_class because of missing codepoint validation in regenc.c.
CVE-2019-16161HIGH7.5Onigmo through 6.2.0 has a NULL pointer dereference in onig_error_code_to_str because of fetch_token in regparse.c.
CVE-2019-16159HIGH7.5BIRD Internet Routing Daemon 1.6.x through 1.6.7 and 2.x through 2.0.5 has a stack-based buffer overflow. The BGP daemon...
CVE-2019-12465HIGH8.1An issue was discovered in LibreNMS 1.50.1. A SQL injection flaw was identified in the ajax_rulesuggest.php file where t...

Check if your code is affected by 2019 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now