2019 CVE Vulnerabilities

17,620 CVEs published in 2019.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2019-5051HIGH8.8An exploitable heap-based buffer overflow vulnerability exists when loading a PCX file in SDL2_image, version 2.0.4. A m...
CVE-2019-6631HIGH7.5On BIG-IP 11.5.1-11.6.4, iRules performing HTTP header manipulation may cause an interruption to service when processing...
CVE-2019-6629HIGH7.5On BIG-IP 14.1.0-14.1.0.5, undisclosed SSL traffic to a virtual server configured with a Client SSL profile may cause TM...
CVE-2019-13164HIGH7.8qemu-bridge-helper.c in QEMU 3.1 and 4.0.0 does not ensure that a network interface name (obtained from bridge.conf or a...
CVE-2019-6623HIGH7.5On BIG-IP 14.1.0-14.1.0.5, 14.0.0-14.0.0.4, 13.0.0-13.1.1.4, and 12.1.0-12.1.4, undisclosed traffic sent to BIG-IP iSess...
CVE-2019-10137HIGH8.1A path traversal flaw was found in spacewalk-proxy, all versions through 2.9, in the way the proxy processes cached clie...
CVE-2019-7258HIGH8.8Linear eMerge E3-Series devices allow Privilege Escalation.
CVE-2019-7254HIGH7.5Linear eMerge E3-Series devices allow File Inclusion.
CVE-2019-5443HIGH7.8A non-privileged user or program can put code and a config file in a known non-privileged path (under C:/usr/local/) tha...
CVE-2019-7262HIGH8.8Linear eMerge E3-Series devices allow Cross-Site Request Forgery (CSRF).
CVE-2019-7259HIGH8.8Linear eMerge E3-Series devices allow Authorization Bypass with Information Disclosure.
CVE-2019-7270HIGH8.8Linear eMerge 50P/5000P devices allow Cross-Site Request Forgery (CSRF).
CVE-2019-4292HIGH8.8IBM Security Guardium 10.5 could allow a remote attacker to upload arbitrary files, which could allow the attacker to ex...
CVE-2019-4140HIGH7.1IBM Tivoli Storage Manager Server (IBM Spectrum Protect 7.1 and 8.1) could allow a local user to replace existing databa...
CVE-2019-4088HIGH7.8IBM Spectrum Protect Servers 7.1 and 8.1 and Storage Agents could allow a local attacker to gain elevated privileges on ...
CVE-2019-7273HIGH8.8Optergy Proton/Enterprise devices allow Cross-Site Request Forgery (CSRF).
CVE-2019-6642HIGH8.8In BIG-IP 15.0.0, 14.0.0-14.1.0.5, 13.0.0-13.1.1.5, 12.1.0-12.1.4.2, and 11.5.2-11.6.4, BIG-IQ 6.0.0-6.1.0 and 5.1.0-5.4...
CVE-2019-13135HIGH8.8ImageMagick before 7.0.8-50 has a "use of uninitialized value" vulnerability in the function ReadCUTImage in coders/cut....
CVE-2019-7670HIGH7.2Prima Systems FlexAir, Versions 2.3.38 and prior. The application incorrectly neutralizes special elements that could mo...
CVE-2019-7669HIGH8.8Prima Systems FlexAir, Versions 2.3.38 and prior. Improper validation of file extensions when uploading files could allo...
CVE-2019-7666HIGH8.8Prima Systems FlexAir, Versions 2.3.38 and prior. The application allows improper authentication using the MD5 hash valu...
CVE-2019-7281HIGH8.8Prima Systems FlexAir, Versions 2.3.38 and prior. An unauthenticated user can send unverified HTTP requests, which may a...
CVE-2019-7280HIGH8.8Prima Systems FlexAir, Versions 2.3.38 and prior. The session-ID is of an insufficient length and can be exploited by br...
CVE-2019-4322HIGH7.8IBM DB2 for Linux, UNIX and Windows (includes DB2 Connect Server) 9.7, 10.1, 10.5, and 11.1 is vulnerable to a buffer ov...
CVE-2019-4298HIGH7.1IBM Robotic Process Automation with Automation Anywhere 11 uses a high privileged PostgreSQL account for database access...

Check if your code is affected by 2019 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now