2019 CVE Vulnerabilities

17,620 CVEs published in 2019.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2019-11815HIGH8.1An issue was discovered in rds_tcp_kill_sock in net/rds/tcp.c in the Linux kernel before 5.0.8. There is a race conditio...
CVE-2019-4208HIGH7.1IBM TRIRIGA Application Platform 3.5.3 and 3.6.0 is vulnerable to an XML External Entity Injection (XXE) attack when pro...
CVE-2019-10869HIGH8.1Path Traversal and Unrestricted File Upload exists in the Ninja Forms plugin before 3.0.23 for WordPress (when the Uploa...
CVE-2019-11811HIGH7An issue was discovered in the Linux kernel before 5.0.4. There is a use-after-free upon attempted read access to /proc/...
CVE-2019-11810HIGH7.5An issue was discovered in the Linux kernel before 5.0.7. A NULL pointer dereference can occur when megasas_create_frame...
CVE-2019-5432HIGH7.5A specifically malformed MQTT Subscribe packet crashes MQTT Brokers using the mqtt-packet module versions < 3.5.1, 4.0.0...
CVE-2019-3565HIGH7.5Legacy C++ Facebook Thrift servers (using cpp instead of cpp2) would not error upon receiving messages with containers o...
CVE-2019-3564HIGH7.5Go Facebook Thrift servers would not error upon receiving messages with containers of fields of unknown type. As a resul...
CVE-2019-3559HIGH7.5Java Facebook Thrift servers would not error upon receiving messages with containers of fields of unknown type. As a res...
CVE-2019-3558HIGH7.5Python Facebook Thrift servers would not error upon receiving messages with containers of fields of unknown type. As a r...
CVE-2019-3552HIGH7.5C++ Facebook Thrift servers (using cpp2) would not error upon receiving messages with containers of fields of unknown ty...
CVE-2019-10249HIGH8.1All Xtext & Xtend versions prior to 2.18.0 were built using HTTP instead of HTTPS file transfer and thus the built artif...
CVE-2019-6619HIGH7.5On BIG-IP 14.0.0-14.1.0.1, 13.0.0-13.1.1.4, and 12.1.0-12.1.4, the Traffic Management Microkernel (TMM) may restart when...
CVE-2019-6616HIGH7.2On BIG-IP 14.0.0-14.1.0.1, 13.0.0-13.1.1.4, 12.1.0-12.1.4, 11.6.1-11.6.3.4, and 11.5.2-11.5.8, administrative users with...
CVE-2019-6158HIGH8.7An internal product security audit of Lenovo XClarity Administrator (LXCA) discovered HTTP proxy credentials being writt...
CVE-2019-3894HIGH8.8It was discovered that the ElytronManagedThread in Wildfly's Elytron subsystem in versions from 11 to 16 stores a Securi...
CVE-2019-6612HIGH7.5On BIG-IP 14.0.0-14.1.0.1, 13.0.0-13.1.1.4, 12.1.0-12.1.4, 11.6.1-11.6.3.4, and 11.5.2-11.5.8, DNS query TCP connections...
CVE-2019-6611HIGH7.5When BIG-IP 14.0.0-14.1.0.1, 13.0.0-13.1.1.4, 12.1.0-12.1.4, 11.6.1-11.6.3.4, and 11.5.2-11.5.8 are processing certain r...
CVE-2019-1859HIGH7.2A vulnerability in the Secure Shell (SSH) authentication process of Cisco Small Business Switches software could allow a...
CVE-2019-1836HIGH7.1A vulnerability in the system shell for Cisco Nexus 9000 Series Fabric Switches in Application Centric Infrastructure (A...
CVE-2019-1817HIGH7.5A vulnerability in the web proxy functionality of Cisco AsyncOS Software for Cisco Web Security Appliance could allow an...
CVE-2019-1816HIGH7.8A vulnerability in the log subscription subsystem of the Cisco Web Security Appliance (WSA) could allow an authenticated...
CVE-2019-1807HIGH7.6A vulnerability in the session management functionality of the web UI for the Cisco Umbrella Dashboard could allow an au...
CVE-2019-1724HIGH8.8A vulnerability in the session management functionality of the web-based interface for Cisco Small Business RV320 and RV...
CVE-2019-1715HIGH7.5A vulnerability in the Deterministic Random Bit Generator (DRBG), also known as Pseudorandom Number Generator (PRNG), us...

Check if your code is affected by 2019 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now