2019 CVE Vulnerabilities

17,624 CVEs published in 2019.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2019-25021HIGH7.5An issue was discovered in Scytl sVote 2.1. Due to the implementation of the database manager, an attacker can access th...
CVE-2019-25020HIGH7.5An issue was discovered in Scytl sVote 2.1. Because the sdm-ws-rest API does not require authentication, an attacker can...
CVE-2019-18945HIGH8Micro Focus Solutions Business Manager Application Repository versions prior to 11.7.1 are vulnerable to privilege escal...
CVE-2019-18943HIGH8Micro Focus Solutions Business Manager versions prior to 11.7.1 are vulnerable to XML External Entity Processing (XXE) o...
CVE-2019-19005HIGH7.8A bitmap double free in main.c in autotrace 0.31.1 allows attackers to cause an unspecified impact via a malformed bitma...
CVE-2019-25018HIGH7.5In the rcp client in MIT krb5-appl through 1.0.3, malicious servers could bypass intended access restrictions via the fi...
CVE-2019-20471HIGH7.8An issue was discovered on TK-Star Q90 Junior GPS horloge 3.1042.9.8656 devices. When using the device at initial setup,...
CVE-2019-20470HIGH7.5An issue was discovered on TK-Star Q90 Junior GPS horloge 3.1042.9.8656 devices. It performs actions based on certain SM...
CVE-2019-25016HIGH8.8In OpenDoas from 6.6 to 6.8 the users PATH variable was incorrectly inherited by authenticated executions if the authent...
CVE-2019-4702HIGH8.1IBM Security Guardium Data Encryption (GDE) 3.0.0.2 specifies permissions for a security-critical resource in a way that...
CVE-2019-4160HIGH7.5IBM Security Guardium Data Encryption (GDE) 3.0.0.2 uses weaker than expected cryptographic algorithms that could allow ...
CVE-2019-20484HIGH8.1An issue was discovered in Viki Vera 4.9.1.26180. A user without access to a project could download or upload project fi...
CVE-2019-4728HIGH8.8IBM Sterling B2B Integrator Standard Edition 5.2.0.0 through 5.2.6.5_2, 6.0.0.0 through 6.0.3.2, and 6.1.0.0 could allow...
CVE-2019-25012HIGH7.5The Webform Report project 7.x-1.x-dev for Drupal allows remote attackers to view submissions by visiting the /rss.xml p...
CVE-2019-25007HIGH7.5An issue was discovered in the streebog crate before 0.8.0 for Rust. The Streebog hash function can cause a panic.
CVE-2019-25006HIGH7.5An issue was discovered in the streebog crate before 0.8.0 for Rust. The Streebog hash function can produce the wrong an...
CVE-2019-25005HIGH7.5An issue was discovered in the chacha20 crate before 0.2.3 for Rust. A ChaCha20 counter overflow makes it easier for att...
CVE-2019-25003HIGH7.5An issue was discovered in the libsecp256k1 crate before 0.3.1 for Rust. Scalar::check_overflow allows a timing side-cha...
CVE-2019-25001HIGH7.5An issue was discovered in the serde_cbor crate before 0.10.2 for Rust. The CBOR deserializer can cause stack consumptio...
CVE-2019-16747HIGH7.5In MatrixSSL before 4.2.2 Open, the DTLS server can encounter an invalid pointer free (leading to memory corruption and ...
CVE-2019-16281HIGH7.5Ptarmigan before 0.2.3 lacks API token validation, e.g., an "if (token === apiToken) {return true;} return false;" code ...
CVE-2019-15080HIGH7.5An issue was discovered in a smart contract implementation for MORPH Token through 2019-06-05, an Ethereum token. A typo...
CVE-2019-15079HIGH7.5A typo exists in the constructor of a smart contract implementation for EAI through 2019-06-05, an Ethereum token. This ...
CVE-2019-15078HIGH7.5An issue was discovered in a smart contract implementation for AIRDROPX BORN through 2019-05-29, an Ethereum token. The ...
CVE-2019-11781HIGH8.8Improper input validation in portal component in Odoo Community 12.0 and earlier and Odoo Enterprise 12.0 and earlier, a...

Check if your code is affected by 2019 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now