2019 CVE Vulnerabilities

17,620 CVEs published in 2019.

CVE IDSeverityCVSSDescription
CVE-2019-17558HIGH7.5Apache Solr 5.0.0 to Apache Solr 8.3.1 are vulnerable to a Remote Code Execution through the VelocityResponseWriter. A V...
CVE-2019-10774CRITICAL9.8php-shellcommand versions before 1.6.1 have a command injection vulnerability. Successful exploitation could lead to arb...
CVE-2019-4655MEDIUM4.3IBM MQ 9.1.0.0, 9.1.0.1, 9.1.0.2, 9.1.0.3, 9.1.1, 9.1.2, and 9.1.3 is vulnerable to a denial of service attack that woul...
CVE-2019-4623MEDIUM5.4IBM Cognos Analytics 11.0 and 11.1 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbit...
CVE-2019-4343MEDIUM6.5IBM Cognos Analytics 11.0 and 11.1 allows overly permissive cross-origin resource sharing which could allow an attacker ...
CVE-2019-4335MEDIUM5.5IBM Watson Studio Local 1.2.3 stores key files in the user's home directory which could be obtained by another local use...
CVE-2019-20139MEDIUM5.4In Nagios XI 5.6.9, XSS exists via the nocscreenapi.php host, hostgroup, or servicegroup parameter, or the schedulerepor...
CVE-2019-16535CRITICAL9.8In all versions of ClickHouse before 19.14, an OOB read, OOB write and integer underflow in decompression algorithms can...
CVE-2019-15024MEDIUM6.5In all versions of ClickHouse before 19.14.3, an attacker having write access to ZooKeeper and who is able to run a cust...
CVE-2019-20138HIGH7.5The HTTP Authentication library before 2019-12-27 for Nim has weak password hashing because the default algorithm for li...
CVE-2019-20096MEDIUM5.5In the Linux kernel before 5.1, there is a memory leak in __feat_register_sp() in net/dccp/feat.c, which may cause denia...
CVE-2019-20095MEDIUM5.5mwifiex_tm_cmd in drivers/net/wireless/marvell/mwifiex/cfg80211.c in the Linux kernel before 5.1.6 has some error-handli...
CVE-2019-20094HIGH8.8An issue was discovered in libsixel 1.8.4. There is a heap-based buffer overflow in the function gif_init_frame at fromg...
CVE-2019-20093MEDIUM5.5The PoDoFo::PdfVariant::DelayedLoad function in PdfVariant.h in PoDoFo 0.9.6 allows remote attackers to cause a denial o...
CVE-2019-20092MEDIUM5.5An issue was discovered in Bento4 1.5.1.0. There is a NULL pointer dereference in AP4_Descriptor::GetTag in mp42ts when ...
CVE-2019-20091MEDIUM5.5An issue was discovered in Bento4 1.5.1.0. There is a NULL pointer dereference in AP4_Descriptor::GetTag in mp42ts when ...
CVE-2019-20090HIGH7.8An issue was discovered in Bento4 1.5.1.0. There is a use-after-free in AP4_Sample::GetOffset in Core/Ap4Sample.h when c...
CVE-2019-20089HIGH7.8GoPro GPMF-parser 1.2.3 has an heap-based buffer over-read in GPMF_SeekToSamples in GPMF_parse.c for the size calculatio...
CVE-2019-20088HIGH7.8GoPro GPMF-parser 1.2.3 has a heap-based buffer over-read in GetPayload in GPMF_mp4reader.c.
CVE-2019-20087HIGH8.8GoPro GPMF-parser 1.2.3 has a heap-based buffer over-read in GPMF_seekToSamples in GPMF-parse.c for the "matching tags" ...
CVE-2019-20086HIGH8.8GoPro GPMF-parser 1.2.3 has a heap-based buffer over-read in GPMF_Next in GPMF_parser.c.
CVE-2019-20085HIGH7.5TVT NVMS-1000 devices allow GET /.. Directory Traversal
CVE-2019-20079HIGH7.8The autocmd feature in window.c in Vim before 8.1.2136 accesses freed memory.
CVE-2019-20076MEDIUM6.1On Netis DL4323 devices, XSS exists via the form2Ddns.cgi username parameter (DynDns settings of the Dynamic DNS Configu...
CVE-2019-20075MEDIUM6.1On Netis DL4323 devices, pingrtt_v6.html has XSS (Ping6 Diagnostic).

Check if your code is affected by 2019 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now