2019 CVE Vulnerabilities

17,619 CVEs published in 2019.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2019-20478CRITICAL9.8In ruamel.yaml through 0.16.7, the load method allows remote code execution if the application calls this method with an...
CVE-2019-20477CRITICAL9.8PyYAML 5.1 through 5.1.2 has insufficient restrictions on the load and load_all functions because of a class deserializa...
CVE-2019-10791CRITICAL9.8promise-probe before 0.10.0 allows remote attackers to perform a command injection attack. The file, outputFile and opti...
CVE-2019-5613CRITICAL9.8In FreeBSD 12.0-RELEASE before 12.0-RELEASE-p13, a missing check in the ipsec packet processor allows reinjection of an ...
CVE-2019-4392CRITICAL9.8HCL AppScan Standard Edition 9.0.3.13 and earlier uses hard-coded credentials which can be exploited by attackers to get...
CVE-2019-20046CRITICAL9.8The Synergy Systems & Solutions PLC & RTU system has a vulnerability in HUSKY RTU 6049-E70 firmware versions 5.0 and pri...
CVE-2019-14514CRITICAL9.8An issue was discovered in Microvirt MEmu all versions prior to 7.0.2. A guest Android operating system inside the MEmu ...
CVE-2019-17137CRITICAL9.4This vulnerability allows network-adjacent attackers to bypass authentication on affected installations of NETGEAR AC120...
CVE-2019-20451CRITICAL9.8The HTTP API in Prismview System 9 11.10.17.00 and Prismview Player 11 13.09.1100 allows remote code execution by upload...
CVE-2019-20062CRITICAL9.8MFScripts YetiShare v3.5.2 through v4.5.4 might allow an attacker to reset a password by using a leaked hash (the hash n...
CVE-2019-15606CRITICAL9.8Including trailing white space in HTTP header values in Nodejs 10, 12, and 13 causes bypass of authorization based on he...
CVE-2019-15605CRITICAL9.8HTTP request smuggling in Node.js 10, 12, and 13 causes malicious payload delivery when transfer-encoding is malformed
CVE-2019-17268CRITICAL9.8The omniauth-weibo-oauth2 gem 0.4.6 for Ruby, as distributed on RubyGems.org, included a code-execution backdoor inserte...
CVE-2019-14063CRITICAL9.1Out of bound access due to Invalid inputs to dapm mux settings which results into kernel failure in Snapdragon Auto, Sna...
CVE-2019-14057CRITICAL9.1Buffer Over read of codec private data while parsing an mkv file due to lack of check of buffer size before read in Snap...
CVE-2019-10590CRITICAL9.8Out of bound access while parsing dts atom, which is non-standard as it does not have valid number of tracks in Snapdrag...
CVE-2019-10789CRITICAL9.8All versions of curling.js are vulnerable to Command Injection via the run function. The command argument can be control...
CVE-2019-20447CRITICAL9.8Jobberbase 2.0 has SQL injection via the PATH_INFO to the jobs-in endpoint.
CVE-2019-10788CRITICAL9.8im-metadata through 3.0.1 allows remote attackers to execute arbitrary commands via the "exec" argument. It is possible ...
CVE-2019-10787CRITICAL9.8im-resize through 2.3.2 allows remote attackers to execute arbitrary commands via the "exec" argument. The cmd argument ...
CVE-2019-10786CRITICAL9.8network-manager through 1.0.2 allows remote attackers to execute arbitrary commands via the "execSync()" argument.
CVE-2019-10784CRITICAL9.6phppgadmin through 7.12.1 allows sensitive actions to be performed without validating that the request originated from t...
CVE-2019-4675CRITICAL9.8IBM Security Identity Manager 7.0.1 contains hard-coded credentials, such as a password or cryptographic key, which it u...
CVE-2019-10783CRITICAL9.8All versions including 0.0.4 of lsof npm module are vulnerable to Command Injection. Every exported method used by the p...
CVE-2019-20445CRITICAL9.1HttpObjectDecoder.java in Netty before 4.1.44 allows a Content-Length header to be accompanied by a second Content-Lengt...

Check if your code is affected by 2019 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now