2019 CVE Vulnerabilities

17,620 CVEs published in 2019.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2019-12465HIGH8.1An issue was discovered in LibreNMS 1.50.1. A SQL injection flaw was identified in the ajax_rulesuggest.php file where t...
CVE-2019-12464HIGH7.5An issue was discovered in LibreNMS 1.50.1. An authenticated user can perform a directory traversal attack against the /...
CVE-2019-12463HIGH8.8An issue was discovered in LibreNMS 1.50.1. The scripts that handle graphing options (includes/html/graphs/common.inc.ph...
CVE-2019-10671HIGH8.8An issue was discovered in LibreNMS through 1.47. It does not parameterize all user supplied input within database queri...
CVE-2019-15895HIGH7.5search-exclude.php in the "Search Exclude" plugin before 1.2.4 for WordPress allows unauthenticated options changes.
CVE-2019-15639HIGH7.5main/translate.c in Sangoma Asterisk 13.28.0 and 16.5.0 allows a remote attacker to send a specific RTP packet during a ...
CVE-2019-10669HIGH7.2An issue was discovered in LibreNMS through 1.47. There is a command injection vulnerability in html/includes/graphs/dev...
CVE-2019-10666HIGH8.1An issue was discovered in LibreNMS through 1.47. Several of the scripts perform dynamic script inclusion via the includ...
CVE-2019-16144HIGH7.5An issue was discovered in the generator crate before 0.6.18 for Rust. Uninitialized memory is used by Scope, done, and ...
CVE-2019-16141HIGH7.5An issue was discovered in the once_cell crate before 1.0.1 for Rust. There is a panic during initialization of Lazy.
CVE-2019-16137HIGH7.5An issue was discovered in the spin crate before 0.5.2 for Rust, when RwLock is used. Because memory ordering is mishand...
CVE-2019-16131HIGH8.8framework/admin/modulec_control.php in OKLite v1.2.25 has an Arbitrary File Upload Vulnerability because a .php file fro...
CVE-2019-16123HIGH7.5In Kartatopia PilusCart 1.4.1, the parameter filename in the file catalog.php is mishandled, leading to ../ Local File D...
CVE-2019-16120HIGH8.8CSV injection in the event-tickets (Event Tickets) plugin before 4.10.7.2 for WordPress exists via the "All Post> Ticket...
CVE-2019-16115HIGH7.8In Xpdf 4.01.01, a stack-based buffer under-read could be triggered in IdentityFunction::transform in Function.cc, used ...
CVE-2019-16113HIGH8.8Bludit 3.9.2 allows remote code execution via bl-kernel/ajax/upload-images.php because PHP code can be entered with a .j...
CVE-2019-16096HIGH7.5Kilo 0.0.1 has a heap-based buffer overflow because there is an integer overflow in a calculation involving the number o...
CVE-2019-16095HIGH7.5Symonics libmysofa 0.7 has an invalid read in getDimension in hrtf/reader.c.
CVE-2019-16094HIGH7.5Symonics libmysofa 0.7 has an invalid read in readOHDRHeaderMessageDataLayout in hdf/dataobject.c.
CVE-2019-16091HIGH7.5Symonics libmysofa 0.7 has an out-of-bounds read in directblockRead in hdf/fractalhead.c.
CVE-2019-9458HIGH7In the Android kernel in the video driver there is a use after free due to a race condition. This could lead to local es...
CVE-2019-9270HIGH7.8In the Android kernel in unifi and r8180 WiFi drivers there is a possible out of bounds write due to a missing bounds ch...
CVE-2019-2182HIGH7.8In the Android kernel in the kernel MMU code there is a possible execution path leaving some kernel text and rodata page...
CVE-2019-9854HIGH7.8LibreOffice has a feature where documents can specify that pre-installed macros can be executed on various script events...
CVE-2019-16056HIGH7.5An issue was discovered in Python through 2.7.16, 3.x through 3.5.7, 3.6.x through 3.6.9, and 3.7.x through 3.7.4. The e...

Check if your code is affected by 2019 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now