2019 CVE Vulnerabilities

17,620 CVEs published in 2019.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2019-12957HIGH7.8In Xpdf 4.01.01, a buffer over-read could be triggered in FoFiType1C::convertToType1 in fofi/FoFiType1C.cc when the inde...
CVE-2019-7229HIGH8.3The ABB CP635 HMI uses two different transmission methods to upgrade its firmware and its software components: "Utilizat...
CVE-2019-7232HIGH8.8The ABB IDAL HTTP server is vulnerable to a buffer overflow when a long Host header is sent in a web request. The Host h...
CVE-2019-7230HIGH8.8The ABB IDAL FTP server mishandles format strings in a username during the authentication process. Attempting to authent...
CVE-2019-12936HIGH7.1BlueStacks App Player 2, 3, and 4 before 4.90 allows DNS Rebinding for attacks on exposed IPC functions.
CVE-2019-12935HIGH7.4Shopware before 5.5.8 has XSS via the Query String to the backend/Login or backend/Login/load/ URI.
CVE-2019-10720HIGH8.8BlogEngine.NET 3.3.7.0 and earlier allows Directory Traversal and Remote Code Execution via the theme cookie to the File...
CVE-2019-10270HIGH8.8An arbitrary password reset issue was discovered in the Ultimate Member plugin 2.39 for WordPress. It is possible (due t...
CVE-2019-1904HIGH8.8A vulnerability in the web-based UI (web UI) of Cisco IOS XE Software could allow an unauthenticated, remote attacker to...
CVE-2019-3735HIGH7.8Dell SupportAssist for Business PCs version 2.0 and Dell SupportAssist for Home PCs version 2.2, 2.2.1, 2.2.2, 2.2.3, 3....
CVE-2019-1878HIGH7.5A vulnerability in the Cisco Discovery Protocol (CDP) implementation for the Cisco TelePresence Codec (TC) and Collabora...
CVE-2019-1874HIGH8.8A vulnerability in the web-based management interface of Cisco Prime Service Catalog Software could allow an unauthentic...
CVE-2019-1869HIGH8.6A vulnerability in the internal packet-processing functionality of the Cisco StarOS operating system running on virtual ...
CVE-2019-1843HIGH8.6A vulnerability in the web-based management interface of the Cisco RV110W Wireless-N VPN Firewall, Cisco RV130W Wireless...
CVE-2019-1626HIGH8.8A vulnerability in the vManage web-based UI (Web UI) of the Cisco SD-WAN Solution could allow an authenticated, remote a...
CVE-2019-1625HIGH7.8A vulnerability in the CLI of Cisco SD-WAN Solution could allow an authenticated, local attacker to elevate lower-level ...
CVE-2019-1624HIGH8.8A vulnerability in the vManage web-based UI (Web UI) in the Cisco SD-WAN Solution could allow an authenticated, remote a...
CVE-2019-3787HIGH8.3Cloud Foundry UAA, versions prior to 73.0.0, falls back to appending “unknown.org” to a user's email address when one is...
CVE-2019-3737HIGH7.5Dell EMC Avamar ADMe Web Interface 1.0.50 and 1.0.51 are affected by an LFI vulnerability which may allow a malicious us...
CVE-2019-4364HIGH8IBM Maximo Asset Management 7.6 is vulnerable to CSV injection, which could allow a remote authenticated attacker to exe...
CVE-2019-3896HIGH7A double-free can happen in idr_remove_all() in lib/idr.c in the Linux kernel 2.6 branch. An unprivileged local attacker...
CVE-2019-11479HIGH7.5Jonathan Looney discovered that the Linux kernel default MSS is hard-coded to 48 bytes. This allows a remote peer to fra...
CVE-2019-11477HIGH7.5Jonathan Looney discovered that the TCP_SKB_CB(skb)->tcp_gso_segs value was subject to an integer overflow in the Linux ...
CVE-2019-11271HIGH7.8Cloud Foundry BOSH 270.x versions prior to v270.1.1, contain a BOSH Director that does not properly redact credentials w...
CVE-2019-12881HIGH7.8i915_gem_userptr_get_pages in drivers/gpu/drm/i915/i915_gem_userptr.c in the Linux kernel 4.15.0 on Ubuntu 18.04.2 allow...

Check if your code is affected by 2019 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now