2019 CVE Vulnerabilities

17,620 CVEs published in 2019.

CVE IDSeverityCVSSDescription
CVE-2019-19835HIGH7.5SSRF in AjaxRestrictedCmdStat in zap in Ruckus Wireless Unleashed through 200.7.10.102.64 allows a remote denial of serv...
CVE-2019-20399MEDIUM5.9A timing vulnerability in the Scalar::check_overflow function in Parity libsecp256k1-rs before 0.3.1 potentially allows ...
CVE-2019-20398MEDIUM6.5A NULL pointer dereference is present in libyang before v1.0-r3 in the function lys_extension_instances_free() due to a ...
CVE-2019-20397HIGH8.8A double-free is present in libyang before v1.0-r1 in the function yyparse() when an organization field is not terminate...
CVE-2019-20396MEDIUM6.5A segmentation fault is present in yyparse in libyang before v1.0-r1 due to a malformed pattern statement value during l...
CVE-2019-20395MEDIUM6.5A stack consumption issue is present in libyang before v1.0-r1 due to the self-referential union type containing leafref...
CVE-2019-20394HIGH8.8A double-free is present in libyang before v1.0-r3 in the function yyparse() when a type statement in used in a notifica...
CVE-2019-20393HIGH8.8A double-free is present in libyang before v1.0-r1 in the function yyparse() when an empty description is used. Applicat...
CVE-2019-20392MEDIUM6.5An invalid memory access flaw is present in libyang before v1.0-r1 in the function resolve_feature_value() when an if-fe...
CVE-2019-20391MEDIUM6.5An invalid memory access flaw is present in libyang before v1.0-r3 in the function resolve_feature_value() when an if-fe...
CVE-2019-19842CRITICAL9.8emfd in Ruckus Wireless Unleashed through 200.7.10.102.64 allows remote attackers to execute OS commands via a POST requ...
CVE-2019-19841CRITICAL9.8emfd in Ruckus Wireless Unleashed through 200.7.10.102.64 allows remote attackers to execute OS commands via a POST requ...
CVE-2019-19840CRITICAL9.8A stack-based buffer overflow in zap_parse_args in zap.c in zap in Ruckus Unleashed through 200.7.10.102.64 allows remot...
CVE-2019-19843CRITICAL9.8Incorrect access control in the web interface in Ruckus Wireless Unleashed through 200.7.10.102.64 allows remote credent...
CVE-2019-19836CRITICAL9.8AjaxRestrictedCmdStat in zap in Ruckus Wireless Unleashed through 200.7.10.102.64 allows remote code execution via a POS...
CVE-2019-19834HIGH7.2Directory Traversal in ruckus_cli2 in Ruckus Wireless Unleashed through 200.7.10.102.64 allows a remote attacker to jail...
CVE-2019-16792HIGH7.5Waitress through version 1.3.1 allows request smuggling by sending the Content-Length header twice. Waitress would heade...
CVE-2019-5647HIGH7.1The Chrome Plugin for Rapid7 AppSpider can incorrectly keep browser sessions active after recording a macro, even after ...
CVE-2019-6146MEDIUM6.1It has been reported that cross-site scripting (XSS) is possible in Forcepoint Web Security, version 8.x, via host heade...
CVE-2019-18586Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: The CNA or individual who requested this ca...
CVE-2019-18585Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: The CNA or individual who requested this ca...
CVE-2019-18584Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: The CNA or individual who requested this ca...
CVE-2019-18583Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: The CNA or individual who requested this ca...
CVE-2019-6858HIGH7.8A CWE-427:Uncontrolled Search Path Element vulnerability exists in MSX Configurator (Software Version prior to V1.0.8.1)...
CVE-2019-10781CRITICAL9.8In schema-inspector before 1.6.9, a maliciously crafted JavaScript object can bypass the `sanitize()` and the `validate(...

Check if your code is affected by 2019 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now