2019 CVE Vulnerabilities
17,620 CVEs published in 2019.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2019-19835 | HIGH | 7.5 | 1.8% | Jan 23, 2020 | SSRF in AjaxRestrictedCmdStat in zap in Ruckus Wireless Unleashed through 200.7.10.102.64 allows a remote denial of serv... |
| CVE-2019-20399 | MEDIUM | 5.9 | 0.9% | Jan 23, 2020 | A timing vulnerability in the Scalar::check_overflow function in Parity libsecp256k1-rs before 0.3.1 potentially allows ... |
| CVE-2019-20398 | MEDIUM | 6.5 | 1.8% | Jan 22, 2020 | A NULL pointer dereference is present in libyang before v1.0-r3 in the function lys_extension_instances_free() due to a ... |
| CVE-2019-20397 | HIGH | 8.8 | 2.5% | Jan 22, 2020 | A double-free is present in libyang before v1.0-r1 in the function yyparse() when an organization field is not terminate... |
| CVE-2019-20396 | MEDIUM | 6.5 | 1.9% | Jan 22, 2020 | A segmentation fault is present in yyparse in libyang before v1.0-r1 due to a malformed pattern statement value during l... |
| CVE-2019-20395 | MEDIUM | 6.5 | 1.8% | Jan 22, 2020 | A stack consumption issue is present in libyang before v1.0-r1 due to the self-referential union type containing leafref... |
| CVE-2019-20394 | HIGH | 8.8 | 2.8% | Jan 22, 2020 | A double-free is present in libyang before v1.0-r3 in the function yyparse() when a type statement in used in a notifica... |
| CVE-2019-20393 | HIGH | 8.8 | 2.8% | Jan 22, 2020 | A double-free is present in libyang before v1.0-r1 in the function yyparse() when an empty description is used. Applicat... |
| CVE-2019-20392 | MEDIUM | 6.5 | 1.9% | Jan 22, 2020 | An invalid memory access flaw is present in libyang before v1.0-r1 in the function resolve_feature_value() when an if-fe... |
| CVE-2019-20391 | MEDIUM | 6.5 | 1.9% | Jan 22, 2020 | An invalid memory access flaw is present in libyang before v1.0-r3 in the function resolve_feature_value() when an if-fe... |
| CVE-2019-19842 | CRITICAL | 9.8 | 5.0% | Jan 22, 2020 | emfd in Ruckus Wireless Unleashed through 200.7.10.102.64 allows remote attackers to execute OS commands via a POST requ... |
| CVE-2019-19841 | CRITICAL | 9.8 | 3.3% | Jan 22, 2020 | emfd in Ruckus Wireless Unleashed through 200.7.10.102.64 allows remote attackers to execute OS commands via a POST requ... |
| CVE-2019-19840 | CRITICAL | 9.8 | 4.1% | Jan 22, 2020 | A stack-based buffer overflow in zap_parse_args in zap.c in zap in Ruckus Unleashed through 200.7.10.102.64 allows remot... |
| CVE-2019-19843 | CRITICAL | 9.8 | 1.8% | Jan 22, 2020 | Incorrect access control in the web interface in Ruckus Wireless Unleashed through 200.7.10.102.64 allows remote credent... |
| CVE-2019-19836 | CRITICAL | 9.8 | 3.6% | Jan 22, 2020 | AjaxRestrictedCmdStat in zap in Ruckus Wireless Unleashed through 200.7.10.102.64 allows remote code execution via a POS... |
| CVE-2019-19834 | HIGH | 7.2 | 2.2% | Jan 22, 2020 | Directory Traversal in ruckus_cli2 in Ruckus Wireless Unleashed through 200.7.10.102.64 allows a remote attacker to jail... |
| CVE-2019-16792 | HIGH | 7.5 | 2.1% | Jan 22, 2020 | Waitress through version 1.3.1 allows request smuggling by sending the Content-Length header twice. Waitress would heade... |
| CVE-2019-5647 | HIGH | 7.1 | 0.3% | Jan 22, 2020 | The Chrome Plugin for Rapid7 AppSpider can incorrectly keep browser sessions active after recording a macro, even after ... |
| CVE-2019-6146 | MEDIUM | 6.1 | 3.0% | Jan 22, 2020 | It has been reported that cross-site scripting (XSS) is possible in Forcepoint Web Security, version 8.x, via host heade... |
| CVE-2019-18586 | — | — | — | Jan 22, 2020 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: The CNA or individual who requested this ca... |
| CVE-2019-18585 | — | — | — | Jan 22, 2020 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: The CNA or individual who requested this ca... |
| CVE-2019-18584 | — | — | — | Jan 22, 2020 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: The CNA or individual who requested this ca... |
| CVE-2019-18583 | — | — | — | Jan 22, 2020 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: The CNA or individual who requested this ca... |
| CVE-2019-6858 | HIGH | 7.8 | 0.4% | Jan 22, 2020 | A CWE-427:Uncontrolled Search Path Element vulnerability exists in MSX Configurator (Software Version prior to V1.0.8.1)... |
| CVE-2019-10781 | CRITICAL | 9.8 | 1.4% | Jan 22, 2020 | In schema-inspector before 1.6.9, a maliciously crafted JavaScript object can bypass the `sanitize()` and the `validate(... |
Check if your code is affected by 2019 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now