2019 CVE Vulnerabilities

17,624 CVEs published in 2019.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2019-14811HIGH7.8A flaw was found in, ghostscript versions prior to 9.50, in the .pdf_hook_DSC_Creator procedure where it did not properl...
CVE-2019-13156HIGH7.5NDrive(1.2.2).sys in Naver Cloud Explorer has a stack-based buffer overflow, which allows attackers to cause a denial of...
CVE-2019-15858HIGH8.8admin/includes/class.import.snippet.php in the "Woody ad snippets" plugin before 2.2.5 for WordPress allows unauthentica...
CVE-2019-15847HIGH7.5The POWER9 backend in GNU Compiler Collection (GCC) before version 10 could optimize multiple calls of the __builtin_dar...
CVE-2019-2390HIGH7.8An unprivileged user or program on Microsoft Windows which can create OpenSSL configuration files in a fixed location ma...
CVE-2019-5612HIGH7.5In FreeBSD 12.0-STABLE before r351264, 12.0-RELEASE before 12.0-RELEASE-p10, 11.3-STABLE before r351265, 11.3-RELEASE be...
CVE-2019-5611HIGH7.5In FreeBSD 12.0-STABLE before r350828, 12.0-RELEASE before 12.0-RELEASE-p10, 11.3-STABLE before r350829, 11.3-RELEASE be...
CVE-2019-5610HIGH7.5In FreeBSD 12.0-STABLE before r350637, 12.0-RELEASE before 12.0-RELEASE-p9, 11.3-STABLE before r350638, 11.3-RELEASE bef...
CVE-2019-5609HIGH7.5In FreeBSD 12.0-STABLE before r350619, 12.0-RELEASE before 12.0-RELEASE-p9, 11.3-STABLE before r350619, 11.3-RELEASE bef...
CVE-2019-1968HIGH7.5A vulnerability in the NX-API feature of Cisco NX-OS Software could allow an unauthenticated, remote attacker to cause a...
CVE-2019-1967HIGH7.5A vulnerability in the Network Time Protocol (NTP) feature of Cisco NX-OS Software could allow an unauthenticated, remot...
CVE-2019-1966HIGH7.8A vulnerability in a specific CLI command within the local management (local-mgmt) context for Cisco UCS Fabric Intercon...
CVE-2019-12402HIGH7.5The file name encoding algorithm used internally in Apache Commons Compress 1.15 to 1.18 can get into an infinite loop w...
CVE-2019-13608HIGH7.5Citrix StoreFront Server before 1903, 7.15 LTSR before CU4 (3.12.4000), and 7.6 LTSR before CU8 (3.0.8000) allows XXE at...
CVE-2019-7307HIGH7Apport before versions 2.14.1-0ubuntu3.29+esm1, 2.20.1-0ubuntu2.19, 2.20.9-0ubuntu7.7, 2.20.10-0ubuntu27.1, 2.20.11-0ubu...
CVE-2019-13408HIGH7.5A relative path traversal vulnerability found in Advan VD-1 firmware versions up to 230. It allows attackers to download...
CVE-2019-11248HIGH8.2The debugging endpoint /debug/pprof is exposed over the unauthenticated Kubelet healthz port. The go pprof endpoint is e...
CVE-2019-11247HIGH8.1The Kubernetes kube-apiserver mistakenly allows access to a cluster-scoped custom resource if the request is made as if ...
CVE-2019-11060HIGH7.5The web api server on Port 8080 of ASUS HG100 firmware up to 1.05.12, which is vulnerable to Slowloris HTTP Denial of Se...
CVE-2019-15752HIGH7.8Docker Desktop Community Edition before 2.1.0.1 allows local users to gain privileges by placing a Trojan horse docker-c...
CVE-2019-1965HIGH7.7A vulnerability in the Virtual Shell (VSH) session management for Cisco NX-OS Software could allow an authenticated, rem...
CVE-2019-1964HIGH8.6A vulnerability in the IPv6 traffic processing of Cisco NX-OS Software could allow an unauthenticated, remote attacker t...
CVE-2019-1963HIGH7.7A vulnerability in the Simple Network Management Protocol (SNMP) input packet processor of Cisco FXOS Software and Cisco...
CVE-2019-1962HIGH8.6A vulnerability in the Cisco Fabric Services component of Cisco NX-OS Software could allow an unauthenticated, remote at...
CVE-2019-10390HIGH8.8A sandbox bypass vulnerability in Jenkins Splunk Plugin 1.7.4 and earlier allowed attackers with Overall/Read permission...

Check if your code is affected by 2019 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now