2019 CVE Vulnerabilities

17,620 CVEs published in 2019.

CVE IDSeverityCVSSDescription
CVE-2019-20360HIGH7.5A flaw in Give before 2.5.5, a WordPress plugin, allowed unauthenticated users to bypass API authentication methods and ...
CVE-2019-17151MEDIUM5.4This vulnerability allows remote attackers redirect users to an external resource on affected installations of Tencent W...
CVE-2019-17148HIGH7.8This vulnerability allows local attackers to escalate privileges on affected installations of Parallels Desktop Parallel...
CVE-2019-17147HIGH8.8This vulnerability allows remote attackers to execute arbitrary code on affected installations of TP-LINK TL-WR841N rout...
CVE-2019-17146CRITICAL9.8This vulnerability allows remote attackers to execute arbitrary code on affected installations of D-Link DCS-960L v1.07....
CVE-2019-18652MEDIUM6.1A DOM based XSS vulnerability has been identified on the WatchGuard XMT515 through 12.1.3, allowing a remote attacker to...
CVE-2019-6529MEDIUM4.9An attacker could specially craft an FTP request that could crash the PR100088 Modbus gateway versions prior to release ...
CVE-2019-14906CRITICAL9.8A flaw was found with the RHSA-2019:3950 erratum, where it did not fix the CVE-2019-13616 SDL vulnerability. This issue ...
CVE-2019-9465MEDIUM5.5In the Titan M handling of cryptographic operations, there is a possible information disclosure due to an unusual root c...
CVE-2019-6700MEDIUM6.5An information exposure vulnerability in the external authentication profile form of FortiSIEM 5.2.2 and earlier may all...
CVE-2019-18386HIGH8.7Systems management on Unisys ClearPath Forward Libra and ClearPath MCP Software Series can fault and have other unspecif...
CVE-2019-16154MEDIUM6.1An improper neutralization of input during web page generation in FortiAuthenticator WEB UI 6.0.0 may allow an unauthent...
CVE-2019-10776CRITICAL9.8In "index.js" file line 240, the run command executes the git command with a user controlled variable called remoteUrl. ...
CVE-2019-14819HIGH8.8A flaw was found during the upgrade of an existing OpenShift Container Platform 3.x cluster. Using CRI-O, the dockergc s...
CVE-2019-14879MEDIUM5.4A vulnerability was found in Moodle versions 3.7.x before 3.7.3, 3.6.x before 3.6.7 and 3.5.x before 3.5.9. When a cohor...
CVE-2019-14866HIGH7.3In all versions of cpio before 2.13 does not properly validate input files when generating TAR archives. When cpio is us...
CVE-2019-14854MEDIUM6.5OpenShift Container Platform 4 does not sanitize secret data written to static pod logs when the log level in a given op...
CVE-2019-14843HIGH8.8A flaw was found in Wildfly Security Manager, running under JDK 11 or 8, that authorized requests for any requester. Thi...
CVE-2019-14837CRITICAL9.1A flaw was found in keycloack before version 8.0.0. The owner of 'placeholder.org' domain can setup mail server on this ...
CVE-2019-14834LOW3.7A vulnerability was found in dnsmasq before version 2.81, where the memory leak allows remote attackers to cause a denia...
CVE-2019-6857HIGH7.5A CWE-754: Improper Check for Unusual or Exceptional Conditions vulnerability exists in Modicon M580, Modicon M340, Modi...
CVE-2019-6856HIGH7.5A CWE-754: Improper Check for Unusual or Exceptional Conditions vulnerability exists in Modicon M580, Modicon M340, Modi...
CVE-2019-6855HIGH7.3Incorrect Authorization vulnerability exists in EcoStruxure Control Expert (all versions prior to 14.1 Hot Fix), Unity P...
CVE-2019-6854HIGH7.8A CWE-287: Improper Authentication vulnerability exists in a folder within EcoStruxure Geo SCADA Expert (ClearSCADA) -wi...
CVE-2019-20348MEDIUM6.8OKER G232V1 v1.03.02.20161129 devices provide a root terminal on a UART serial interface without proper access control. ...

Check if your code is affected by 2019 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now