2019 CVE Vulnerabilities

17,620 CVEs published in 2019.

CVE IDSeverityCVSSDescription
CVE-2019-11261Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. Reason: The CNA or individual who requested this candidate did not as...
CVE-2019-11260Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. Reason: The CNA or individual who requested this candidate did not as...
CVE-2019-11259Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. Reason: The CNA or individual who requested this candidate did not as...
CVE-2019-11258Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. Reason: The CNA or individual who requested this candidate did not as...
CVE-2019-11257Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. Reason: The CNA or individual who requested this candidate did not as...
CVE-2019-11256Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. Reason: The CNA or individual who requested this candidate did not as...
CVE-2019-18193HIGH7.5In Unisys Stealth (core) 3.4.108.0, 3.4.209.x, 4.0.027.x and 4.0.114, key material inadvertently logged under certain co...
CVE-2019-20446MEDIUM6.5In xml.rs in GNOME librsvg before 2.46.2, a crafted SVG file with nested patterns can cause denial of service when passe...
CVE-2019-3016MEDIUM4.7In a Linux KVM guest that has PV TLB enabled, a process in the guest kernel may be able to read memory locations from an...
CVE-2019-13000HIGH7.5Eclair through 0.3 allows attackers to trigger loss of funds because of Incorrect Access Control. NOTE: README.md states...
CVE-2019-12999HIGH7.5Lightning Network Daemon (lnd) before 0.7 allows attackers to trigger loss of funds because of Incorrect Access Control.
CVE-2019-12998HIGH7.5c-lightning before 0.7.1 allows attackers to trigger loss of funds because of Incorrect Access Control. NOTE: README.md ...
CVE-2019-4720HIGH7.5IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 is vulnerable to a denial of service, caused by sending a specia...
CVE-2019-19550HIGH7.5Remote Authentication Bypass in Senior Rubiweb 6.2.34.28 and 6.2.34.37 allows admin access to sensitive information of a...
CVE-2019-18913MEDIUM6.8A potential security vulnerability with pre-boot DMA may allow unauthorized UEFI code execution using open-case attacks....
CVE-2019-10782MEDIUM5.3All versions of com.puppycrawl.tools:checkstyle before 8.29 are vulnerable to XML External Entity (XXE) Injection due to...
CVE-2019-20358HIGH7.8Trend Micro Anti-Threat Toolkit (ATTK) versions 1.62.0.1218 and below have a vulnerability that may allow an attacker to...
CVE-2019-17273MEDIUM6.5E-Series SANtricity OS Controller Software version 11.60.0 is susceptible to a vulnerability which allows an attacker to...
CVE-2019-20050MEDIUM6.8Pandora FMS ≤ 7.42 suffers from a remote code execution vulnerability. To exploit the vulnerability, an authenticated us...
CVE-2019-10783CRITICAL9.8All versions including 0.0.4 of lsof npm module are vulnerable to Command Injection. Every exported method used by the p...
CVE-2019-20445CRITICAL9.1HttpObjectDecoder.java in Netty before 4.1.44 allows a Content-Length header to be accompanied by a second Content-Lengt...
CVE-2019-20444CRITICAL9.1HttpObjectDecoder.java in Netty before 4.1.44 allows an HTTP header that lacks a colon, which might be interpreted as a ...
CVE-2019-18634HIGH7.8In Sudo before 1.8.26, if pwfeedback is enabled in /etc/sudoers, users can trigger a stack-based buffer overflow in the ...
CVE-2019-7656HIGH7.8A privilege escalation vulnerability in Wowza Streaming Engine 4.8.0 and earlier allows any unprivileged Linux user to e...
CVE-2019-7655MEDIUM5.4Wowza Streaming Engine 4.8.0 and earlier from multiple authenticated XSS vulnerabilities via the (1) customList%5B0%5D.v...

Check if your code is affected by 2019 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now