2019 CVE Vulnerabilities

17,620 CVEs published in 2019.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2019-5890HIGH8.8An issue was discovered in OverIT Geocall 6.3 before build 2:346977. Weak authentication and session management allows a...
CVE-2019-5889HIGH7.5An log-management directory traversal issue was discovered in OverIT Geocall 6.3 before build 2:346977.
CVE-2019-10662HIGH8.8Grandstream UCM6204 before 1.0.19.20 devices allow remote authenticated users to execute arbitrary code via shell metach...
CVE-2019-10660HIGH8.8Grandstream GXV3611IR_HD before 1.0.3.23 devices allow remote authenticated users to execute arbitrary code via shell me...
CVE-2019-10659HIGH8.8Grandstream GXV3370 before 1.0.1.41 and WP820 before 1.0.3.6 devices allow remote authenticated users to execute arbitra...
CVE-2019-10658HIGH8.8Grandstream GWN7610 before 1.0.8.18 devices allow remote authenticated users to execute arbitrary code via shell metacha...
CVE-2019-10656HIGH8.8Grandstream GWN7000 before 1.0.6.32 devices allow remote authenticated users to execute arbitrary code via shell metacha...
CVE-2019-9922HIGH7.5An issue was discovered in the Harmis JE Messenger component 1.2.2 for Joomla!. Directory Traversal allows read access t...
CVE-2019-9920HIGH8.8An issue was discovered in the Harmis JE Messenger component 1.2.2 for Joomla!. It is possible to perform an action with...
CVE-2019-0225HIGH7.5A specially crafted url could be used to access files under the ROOT directory of the application on Apache JSPWiki 2.9....
CVE-2019-0222HIGH7.5In Apache ActiveMQ 5.0.0 - 5.15.8, unmarshalling corrupt MQTT frame can lead to broker Out of Memory exception making it...
CVE-2019-9166HIGH7.8Privilege escalation in Nagios XI before 5.5.11 allows local attackers to elevate privileges to root via write access to...
CVE-2019-9202HIGH8.8Nagios IM (component of Nagios XI) before 2.2.7 allows authenticated users to execute arbitrary code via API key issues.
CVE-2019-3710HIGH8.1Dell EMC Networking OS10 versions prior to 10.4.3 contain a cryptographic key vulnerability due to an underlying applica...
CVE-2019-1003048HIGH7.8A vulnerability in Jenkins PRQA Plugin 3.1.0 and earlier allows attackers with local file system access to the Jenkins h...
CVE-2019-1003043HIGH7.5A missing permission check in Jenkins Slack Notification Plugin 2.19 and earlier allows attackers with Overall/Read perm...
CVE-2019-9164HIGH8.8Command injection in Nagios XI before 5.5.11 allows an authenticated users to execute arbitrary remote commands via a ne...
CVE-2019-5739HIGH7.5Keep-alive HTTP and HTTPS connections can remain open and inactive for up to 2 minutes in Node.js 6.16.0 and earlier. No...
CVE-2019-5737HIGH7.5In Node.js including 6.x before 6.17.0, 8.x before 8.15.1, 10.x before 10.15.2, and 11.x before 11.10.1, an attacker can...
CVE-2019-7524HIGH8.8In Dovecot before 2.2.36.3 and 2.3.x before 2.3.5.1, a local attacker can cause a buffer overflow in the indexer-worker ...
CVE-2019-6542HIGH7.5ENTTEC Datagate MK2, Storm 24, Pixelator all firmware versions prior to (70044,70050,70060)_update_05032019-482 allows a...
CVE-2019-3869HIGH7.2When running Tower before 3.4.3 on OpenShift or Kubernetes, application credentials are exposed to playbook job runs via...
CVE-2019-1756HIGH7.2A vulnerability in Cisco IOS XE Software could allow an authenticated, remote attacker to execute commands on the underl...
CVE-2019-1754HIGH8.8A vulnerability in the authorization subsystem of Cisco IOS XE Software could allow an authenticated but unprivileged (l...
CVE-2019-1753HIGH8.8A vulnerability in the web UI of Cisco IOS XE Software could allow an authenticated but unprivileged (level 1), remote a...

Check if your code is affected by 2019 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now