2019 CVE Vulnerabilities

17,620 CVEs published in 2019.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2019-15858HIGH8.8admin/includes/class.import.snippet.php in the "Woody ad snippets" plugin before 2.2.5 for WordPress allows unauthentica...
CVE-2019-15847HIGH7.5The POWER9 backend in GNU Compiler Collection (GCC) before version 10 could optimize multiple calls of the __builtin_dar...
CVE-2019-2390HIGH7.8An unprivileged user or program on Microsoft Windows which can create OpenSSL configuration files in a fixed location ma...
CVE-2019-5612HIGH7.5In FreeBSD 12.0-STABLE before r351264, 12.0-RELEASE before 12.0-RELEASE-p10, 11.3-STABLE before r351265, 11.3-RELEASE be...
CVE-2019-5611HIGH7.5In FreeBSD 12.0-STABLE before r350828, 12.0-RELEASE before 12.0-RELEASE-p10, 11.3-STABLE before r350829, 11.3-RELEASE be...
CVE-2019-5610HIGH7.5In FreeBSD 12.0-STABLE before r350637, 12.0-RELEASE before 12.0-RELEASE-p9, 11.3-STABLE before r350638, 11.3-RELEASE bef...
CVE-2019-5609HIGH7.5In FreeBSD 12.0-STABLE before r350619, 12.0-RELEASE before 12.0-RELEASE-p9, 11.3-STABLE before r350619, 11.3-RELEASE bef...
CVE-2019-1968HIGH7.5A vulnerability in the NX-API feature of Cisco NX-OS Software could allow an unauthenticated, remote attacker to cause a...
CVE-2019-1967HIGH7.5A vulnerability in the Network Time Protocol (NTP) feature of Cisco NX-OS Software could allow an unauthenticated, remot...
CVE-2019-1966HIGH7.8A vulnerability in a specific CLI command within the local management (local-mgmt) context for Cisco UCS Fabric Intercon...
CVE-2019-12402HIGH7.5The file name encoding algorithm used internally in Apache Commons Compress 1.15 to 1.18 can get into an infinite loop w...
CVE-2019-13608HIGH7.5Citrix StoreFront Server before 1903, 7.15 LTSR before CU4 (3.12.4000), and 7.6 LTSR before CU8 (3.0.8000) allows XXE at...
CVE-2019-7307HIGH7Apport before versions 2.14.1-0ubuntu3.29+esm1, 2.20.1-0ubuntu2.19, 2.20.9-0ubuntu7.7, 2.20.10-0ubuntu27.1, 2.20.11-0ubu...
CVE-2019-13408HIGH7.5A relative path traversal vulnerability found in Advan VD-1 firmware versions up to 230. It allows attackers to download...
CVE-2019-11248HIGH8.2The debugging endpoint /debug/pprof is exposed over the unauthenticated Kubelet healthz port. The go pprof endpoint is e...
CVE-2019-11247HIGH8.1The Kubernetes kube-apiserver mistakenly allows access to a cluster-scoped custom resource if the request is made as if ...
CVE-2019-11060HIGH7.5The web api server on Port 8080 of ASUS HG100 firmware up to 1.05.12, which is vulnerable to Slowloris HTTP Denial of Se...
CVE-2019-15752HIGH7.8Docker Desktop Community Edition before 2.1.0.1 allows local users to gain privileges by placing a Trojan horse docker-c...
CVE-2019-1965HIGH7.7A vulnerability in the Virtual Shell (VSH) session management for Cisco NX-OS Software could allow an authenticated, rem...
CVE-2019-1964HIGH8.6A vulnerability in the IPv6 traffic processing of Cisco NX-OS Software could allow an unauthenticated, remote attacker t...
CVE-2019-1963HIGH7.7A vulnerability in the Simple Network Management Protocol (SNMP) input packet processor of Cisco FXOS Software and Cisco...
CVE-2019-1962HIGH8.6A vulnerability in the Cisco Fabric Services component of Cisco NX-OS Software could allow an unauthenticated, remote at...
CVE-2019-10390HIGH8.8A sandbox bypass vulnerability in Jenkins Splunk Plugin 1.7.4 and earlier allowed attackers with Overall/Read permission...
CVE-2019-10384HIGH8.8Jenkins 2.191 and earlier, LTS 2.176.2 and earlier allowed users to obtain CSRF tokens without an associated web session...
CVE-2019-15702HIGH7.5In the TCP implementation (gnrc_tcp) in RIOT through 2019.07, the parser for TCP options does not terminate on all input...

Check if your code is affected by 2019 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now