2019 CVE Vulnerabilities

17,620 CVEs published in 2019.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2019-12806HIGH8.8UniSign 2.0.4.0 and earlier version contains a stack-based buffer overflow vulnerability which can overwrite the stack w...
CVE-2019-10943HIGH7.5A vulnerability has been identified in SIMATIC Drive Controller family (All versions), SIMATIC ET 200SP Open Controller ...
CVE-2019-10942HIGH8.6A vulnerability has been identified in SCALANCE X-200 switch family (incl. SIPLUS NET variants) (All versions < V5.2.5),...
CVE-2019-14530HIGH8.8An issue was discovered in custom/ajax_download.php in OpenEMR before 5.0.2 via the fileName parameter. An attacker can ...
CVE-2019-13418HIGH7.5Search Guard versions before 24.0 had an issue that values of string arrays in documents are not properly anonymized.
CVE-2019-14934HIGH7.8An issue was discovered in PDFResurrect before 0.18. pdf_load_pages_kids in pdf.c doesn't validate a certain size value,...
CVE-2019-12258HIGH7.5Wind River VxWorks 6.6 through vx7 has Session Fixation in the TCP component. This is a IPNET security vulnerability: Do...
CVE-2019-11042HIGH7.1When PHP EXIF extension is parsing EXIF information from an image, e.g. via exif_read_data() function, in PHP versions 7...
CVE-2019-11041HIGH7.1When PHP EXIF extension is parsing EXIF information from an image, e.g. via exif_read_data() function, in PHP versions 7...
CVE-2019-3744HIGH7.8Dell/Alienware Digital Delivery versions prior to 4.0.41 contain a privilege escalation vulnerability. A local non-privi...
CVE-2019-3742HIGH7.8Dell/Alienware Digital Delivery versions prior to 3.5.2013 contain a privilege escalation vulnerability. A local non-pri...
CVE-2019-12263HIGH8.1Wind River VxWorks 6.9.4 and vx7 has a Buffer Overflow in the TCP component (issue 4 of 4). There is an IPNET security v...
CVE-2019-12259HIGH7.5Wind River VxWorks 6.6, 6.7, 6.8, 6.9 and vx7 has an array index error in the IGMPv3 client component. There is an IPNET...
CVE-2019-12257HIGH8.8Wind River VxWorks 6.6 through 6.9 has a Buffer Overflow in the DHCP client component. There is an IPNET security vulner...
CVE-2019-12805HIGH8.8NCSOFT Game Launcher, NC Launcher2 2.4.1.691 and earlier versions have a vulnerability in the custom protocol handler th...
CVE-2019-14806HIGH7.5Pallets Werkzeug before 0.15.3, when used with Docker, has insufficient debugger PIN randomness because Docker container...
CVE-2019-14693HIGH8.5Zoho ManageEngine AssetExplorer 6.2.0 is vulnerable to an XML External Entity Injection (XXE) attack when processing lic...
CVE-2019-1970HIGH7.5A vulnerability in the Secure Sockets Layer (SSL)/Transport Layer Security (TLS) protocol inspection engine of Cisco Fir...
CVE-2019-1958HIGH8.8A vulnerability in the web-based management interface of Cisco HyperFlex Software could allow an unauthenticated, remote...
CVE-2019-1957HIGH7.5A vulnerability in the web interface of Cisco IoT Field Network Director could allow an unauthenticated, remote attacker...
CVE-2019-1955HIGH7.5A vulnerability in the Sender Policy Framework (SPF) functionality of Cisco AsyncOS Software for Cisco Email Security Ap...
CVE-2019-1944HIGH7.3Multiple vulnerabilities in the smart tunnel functionality of Cisco Adaptive Security Appliance (ASA) could allow an aut...
CVE-2019-1934HIGH8.8A vulnerability in the web-based management interface of Cisco Adaptive Security Appliance (ASA) Software could allow an...
CVE-2019-1929HIGH7.8Multiple vulnerabilities in Cisco Webex Network Recording Player for Microsoft Windows and Cisco Webex Player for Micros...
CVE-2019-1928HIGH7.8Multiple vulnerabilities in Cisco Webex Network Recording Player for Microsoft Windows and Cisco Webex Player for Micros...

Check if your code is affected by 2019 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now