2019 CVE Vulnerabilities

17,624 CVEs published in 2019.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2019-13226HIGH7deepin-clone before 1.1.3 uses a predictable path /tmp/.deepin-clone/mount/<block-dev-basename> in the Helper::temporary...
CVE-2019-10101HIGH8.1JetBrains Kotlin versions before 1.3.30 were resolving artifacts using an http connection during the build process, pote...
CVE-2019-5052HIGH8.8An exploitable integer overflow vulnerability exists when loading a PCX file in SDL2_image 2.0.4. A specially crafted fi...
CVE-2019-5051HIGH8.8An exploitable heap-based buffer overflow vulnerability exists when loading a PCX file in SDL2_image, version 2.0.4. A m...
CVE-2019-6631HIGH7.5On BIG-IP 11.5.1-11.6.4, iRules performing HTTP header manipulation may cause an interruption to service when processing...
CVE-2019-6629HIGH7.5On BIG-IP 14.1.0-14.1.0.5, undisclosed SSL traffic to a virtual server configured with a Client SSL profile may cause TM...
CVE-2019-13164HIGH7.8qemu-bridge-helper.c in QEMU 3.1 and 4.0.0 does not ensure that a network interface name (obtained from bridge.conf or a...
CVE-2019-6623HIGH7.5On BIG-IP 14.1.0-14.1.0.5, 14.0.0-14.0.0.4, 13.0.0-13.1.1.4, and 12.1.0-12.1.4, undisclosed traffic sent to BIG-IP iSess...
CVE-2019-10137HIGH8.1A path traversal flaw was found in spacewalk-proxy, all versions through 2.9, in the way the proxy processes cached clie...
CVE-2019-7258HIGH8.8Linear eMerge E3-Series devices allow Privilege Escalation.
CVE-2019-7254HIGH7.5Linear eMerge E3-Series devices allow File Inclusion.
CVE-2019-5443HIGH7.8A non-privileged user or program can put code and a config file in a known non-privileged path (under C:/usr/local/) tha...
CVE-2019-7262HIGH8.8Linear eMerge E3-Series devices allow Cross-Site Request Forgery (CSRF).
CVE-2019-7259HIGH8.8Linear eMerge E3-Series devices allow Authorization Bypass with Information Disclosure.
CVE-2019-7270HIGH8.8Linear eMerge 50P/5000P devices allow Cross-Site Request Forgery (CSRF).
CVE-2019-4292HIGH8.8IBM Security Guardium 10.5 could allow a remote attacker to upload arbitrary files, which could allow the attacker to ex...
CVE-2019-4140HIGH7.1IBM Tivoli Storage Manager Server (IBM Spectrum Protect 7.1 and 8.1) could allow a local user to replace existing databa...
CVE-2019-4088HIGH7.8IBM Spectrum Protect Servers 7.1 and 8.1 and Storage Agents could allow a local attacker to gain elevated privileges on ...
CVE-2019-7273HIGH8.8Optergy Proton/Enterprise devices allow Cross-Site Request Forgery (CSRF).
CVE-2019-6642HIGH8.8In BIG-IP 15.0.0, 14.0.0-14.1.0.5, 13.0.0-13.1.1.5, 12.1.0-12.1.4.2, and 11.5.2-11.6.4, BIG-IQ 6.0.0-6.1.0 and 5.1.0-5.4...
CVE-2019-13135HIGH8.8ImageMagick before 7.0.8-50 has a "use of uninitialized value" vulnerability in the function ReadCUTImage in coders/cut....
CVE-2019-7670HIGH7.2Prima Systems FlexAir, Versions 2.3.38 and prior. The application incorrectly neutralizes special elements that could mo...
CVE-2019-7669HIGH8.8Prima Systems FlexAir, Versions 2.3.38 and prior. Improper validation of file extensions when uploading files could allo...
CVE-2019-7666HIGH8.8Prima Systems FlexAir, Versions 2.3.38 and prior. The application allows improper authentication using the MD5 hash valu...
CVE-2019-7281HIGH8.8Prima Systems FlexAir, Versions 2.3.38 and prior. An unauthenticated user can send unverified HTTP requests, which may a...

Check if your code is affected by 2019 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now