2019 CVE Vulnerabilities

17,624 CVEs published in 2019.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2019-4145HIGH7.1IBM Security Access Manager 9.0.1 through 9.0.6 could reveal highly sensitive in specialized conditions to a local user ...
CVE-2019-4135HIGH8.8IBM Security Access Manager 9.0.1 through 9.0.6 is affected by a security vulnerability that could allow authenticated u...
CVE-2019-12817HIGH7arch/powerpc/mm/mmu_context_book3s64.c in the Linux kernel before 5.1.15 for powerpc has a bug where unrelated processes...
CVE-2019-12957HIGH7.8In Xpdf 4.01.01, a buffer over-read could be triggered in FoFiType1C::convertToType1 in fofi/FoFiType1C.cc when the inde...
CVE-2019-7229HIGH8.3The ABB CP635 HMI uses two different transmission methods to upgrade its firmware and its software components: "Utilizat...
CVE-2019-7232HIGH8.8The ABB IDAL HTTP server is vulnerable to a buffer overflow when a long Host header is sent in a web request. The Host h...
CVE-2019-7230HIGH8.8The ABB IDAL FTP server mishandles format strings in a username during the authentication process. Attempting to authent...
CVE-2019-12936HIGH7.1BlueStacks App Player 2, 3, and 4 before 4.90 allows DNS Rebinding for attacks on exposed IPC functions.
CVE-2019-12935HIGH7.4Shopware before 5.5.8 has XSS via the Query String to the backend/Login or backend/Login/load/ URI.
CVE-2019-10720HIGH8.8BlogEngine.NET 3.3.7.0 and earlier allows Directory Traversal and Remote Code Execution via the theme cookie to the File...
CVE-2019-10270HIGH8.8An arbitrary password reset issue was discovered in the Ultimate Member plugin 2.39 for WordPress. It is possible (due t...
CVE-2019-1904HIGH8.8A vulnerability in the web-based UI (web UI) of Cisco IOS XE Software could allow an unauthenticated, remote attacker to...
CVE-2019-3735HIGH7.8Dell SupportAssist for Business PCs version 2.0 and Dell SupportAssist for Home PCs version 2.2, 2.2.1, 2.2.2, 2.2.3, 3....
CVE-2019-1878HIGH7.5A vulnerability in the Cisco Discovery Protocol (CDP) implementation for the Cisco TelePresence Codec (TC) and Collabora...
CVE-2019-1874HIGH8.8A vulnerability in the web-based management interface of Cisco Prime Service Catalog Software could allow an unauthentic...
CVE-2019-1869HIGH8.6A vulnerability in the internal packet-processing functionality of the Cisco StarOS operating system running on virtual ...
CVE-2019-1843HIGH8.6A vulnerability in the web-based management interface of the Cisco RV110W Wireless-N VPN Firewall, Cisco RV130W Wireless...
CVE-2019-1626HIGH8.8A vulnerability in the vManage web-based UI (Web UI) of the Cisco SD-WAN Solution could allow an authenticated, remote a...
CVE-2019-1625HIGH7.8A vulnerability in the CLI of Cisco SD-WAN Solution could allow an authenticated, local attacker to elevate lower-level ...
CVE-2019-1624HIGH8.8A vulnerability in the vManage web-based UI (Web UI) in the Cisco SD-WAN Solution could allow an authenticated, remote a...
CVE-2019-3787HIGH8.3Cloud Foundry UAA, versions prior to 73.0.0, falls back to appending “unknown.org” to a user's email address when one is...
CVE-2019-3737HIGH7.5Dell EMC Avamar ADMe Web Interface 1.0.50 and 1.0.51 are affected by an LFI vulnerability which may allow a malicious us...
CVE-2019-4364HIGH8IBM Maximo Asset Management 7.6 is vulnerable to CSV injection, which could allow a remote authenticated attacker to exe...
CVE-2019-3896HIGH7A double-free can happen in idr_remove_all() in lib/idr.c in the Linux kernel 2.6 branch. An unprivileged local attacker...
CVE-2019-11479HIGH7.5Jonathan Looney discovered that the Linux kernel default MSS is hard-coded to 48 bytes. This allows a remote peer to fra...

Check if your code is affected by 2019 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now