2019 CVE Vulnerabilities

17,619 CVEs published in 2019.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2019-10546CRITICAL9.8Buffer overflow can occur in WLAN firmware while parsing beacon/probe_response frames during roaming in Snapdragon Auto,...
CVE-2019-10526CRITICAL9.8Out of bound write in WLAN driver due to NULL character not properly placed after SSID name in Snapdragon Auto, Snapdrag...
CVE-2019-14893CRITICAL9.8A flaw was discovered in FasterXML jackson-databind in all versions before 2.9.10 and 2.10.0, where it would permit poly...
CVE-2019-19608CRITICAL9.8A SQL injection vulnerability in in the web conferencing component of Mitel MiCollab AWV before 8.1.2.2 could allow an u...
CVE-2019-19607CRITICAL9.8A SQL injection vulnerability in the web conferencing component of Mitel MiCollab AWV before 8.1.2.2 could allow an unau...
CVE-2019-18903CRITICAL9.8A Use After Free vulnerability in wicked of SUSE Linux Enterprise Server 12, SUSE Linux Enterprise Server 15; openSUSE L...
CVE-2019-18902CRITICAL9.8A Use After Free vulnerability in wicked of SUSE Linux Enterprise Server 12, SUSE Linux Enterprise Server 15; openSUSE L...
CVE-2019-14892CRITICAL9.8A flaw was discovered in jackson-databind in versions before 2.9.10, 2.8.11.5 and 2.6.7.3, where it would permit polymor...
CVE-2019-20489CRITICAL9.8An issue was discovered on NETGEAR WNR1000V4 1.1.0.54 devices. The web management interface (setup.cgi) has an authentic...
CVE-2019-20488CRITICAL9.8An issue was discovered on NETGEAR WNR1000V4 1.1.0.54 devices. Multiple actions within the web management interface (set...
CVE-2019-10804CRITICAL9.8serial-number through 1.3.0 allows execution of arbritary commands. The "cmdPrefix" argument in serialNumber function is...
CVE-2019-10803CRITICAL9.8push-dir through 0.4.1 allows execution of arbritary commands. Arguments provided as part of the variable "opt.branch" i...
CVE-2019-10802CRITICAL9.8giting version prior to 0.0.8 allows execution of arbritary commands. The first argument "repo" of function "pull()" is ...
CVE-2019-10801CRITICAL9.8enpeem through 2.2.0 allows execution of arbitrary commands. The "options.dir" argument is provided to the "exec" functi...
CVE-2019-15609CRITICAL9.8The kill-port-process package version < 2.2.0 is vulnerable to a Command Injection vulnerability.
CVE-2019-17275CRITICAL9.8OnCommand Cloud Manager versions prior to 3.8.0 are susceptible to arbitrary code execution by remote attackers.
CVE-2019-19994CRITICAL9.8An issue was discovered in Selesta Visual Access Manager (VAM) 4.15.0 through 4.29. It allows blind Command Injection. A...
CVE-2019-5138CRITICAL9.9An exploitable command injection vulnerability exists in encrypted diagnostic script functionality of the Moxa AWK-3131A...
CVE-2019-12511CRITICAL9.8In NETGEAR Nighthawk X10-R9000 prior to 1.0.4.26, an attacker may execute arbitrary system commands as root by sending a...
CVE-2019-12510CRITICAL9.1In NETGEAR Nighthawk X10-R900 prior to 1.0.4.26, an attacker may bypass all authentication checks on the device's "NETGE...
CVE-2019-10796CRITICAL9.8rpi through 0.0.3 allows execution of arbritary commands. The variable pinNumbver in function GPIO within src/lib/gpio.j...
CVE-2019-20481CRITICAL9.8In MIELE XGW 3000 ZigBee Gateway before 2.4.0, the Password Change Function does not require knowledge of the old passwo...
CVE-2019-18183CRITICAL9.8pacman before 5.2 is vulnerable to arbitrary command injection in lib/libalpm/sync.c in the apply_deltas() function. Thi...
CVE-2019-18182CRITICAL9.8pacman before 5.2 is vulnerable to arbitrary command injection in conf.c in the download_with_xfercommand() function. Th...
CVE-2019-4640CRITICAL9.8IBM Security Secret Server 10.7 processes patches, image backups and other updates without sufficiently verifying the or...

Check if your code is affected by 2019 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now