2019 CVE Vulnerabilities

17,620 CVEs published in 2019.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2019-6732MEDIUM6.5This vulnerability allows remote attackers to disclose sensitive information on vulnerable installations of Foxit Phanto...
CVE-2019-6728MEDIUM6.5This vulnerability allows remote attackers to disclose sensitive information on vulnerable installations of Foxit Reader...
CVE-2019-6454MEDIUM5.5An issue was discovered in sd-bus in systemd 239. bus_process_object() in libsystemd/sd-bus/bus-objects.c allocates a va...
CVE-2019-5011MEDIUM5.5An exploitable privilege escalation vulnerability exists in the helper service CleanMyMac X, version 4.20, due to improp...
CVE-2019-3832MEDIUM5.5It was discovered the fix for CVE-2018-19758 (libsndfile) was not complete and still allows a read beyond the limits of ...
CVE-2019-6149MEDIUM6.7An unquoted search path vulnerability was identified in Lenovo Dynamic Power Reduction Utility prior to version 2.2.2.0 ...
CVE-2019-5616MEDIUM5.3CircuitWerkes Sicon-8, a hardware device used for managing electrical devices, ships with a web-based front-end controll...
CVE-2019-9752MEDIUM5.4An issue was discovered in Open Ticket Request System (OTRS) 5.x before 5.0.34, 6.x before 6.0.16, and 7.x before 7.0.4....
CVE-2019-6601MEDIUM5.5In BIG-IP 13.0.0, 12.1.0-12.1.3.7, 11.6.1-11.6.3.2, or 11.5.1-11.5.8, the Application Acceleration Manager (AAM) wamd pr...
CVE-2019-6600MEDIUM6.1In BIG-IP 14.0.0-14.0.0.2, 13.0.0-13.1.1.3, 12.1.0-12.1.3.7, 11.6.1-11.6.3.2, or 11.5.1-11.5.8, when remote authenticati...
CVE-2019-3711MEDIUM5.8RSA Authentication Manager versions prior to 8.4 P1 contain an Insecure Credential Management Vulnerability. A malicious...
CVE-2019-9741MEDIUM6.1An issue was discovered in net/http in Go 1.11.5. CRLF injection is possible if the attacker controls a url parameter, a...
CVE-2019-9740MEDIUM6.1An issue was discovered in urllib2 in Python 2.x through 2.7.16 and urllib in Python 3.x through 3.7.3. CRLF injection i...
CVE-2019-9737MEDIUM6.1Editor.md 1.5.0 has DOM-based XSS via vectors involving the '<EMBED SRC="data:image/svg+xml' substring.
CVE-2019-0275MEDIUM5.4SAML 1.1 SSO Demo Application in SAP NetWeaver Java Application Server (J2EE-APPS), versions 7.10 to 7.11, 7.20, 7.30, 7...
CVE-2019-0271MEDIUM6.5ABAP Server (used in NetWeaver and Suite/ERP) and ABAP Platform does not sufficiently validate an XML document accepted ...
CVE-2019-3615MEDIUM5.3Data Leakage Attacks vulnerability in the web interface in McAfee Database Security prior to the 4.6.6 March 2019 update...
CVE-2019-9721MEDIUM6.5A denial of service in the subtitle decoder in FFmpeg 3.2 and 4.1 allows attackers to hog the CPU via a crafted video fi...
CVE-2019-9718MEDIUM6.5In FFmpeg 3.2 and 4.1, a denial of service in the subtitle decoder allows attackers to hog the CPU via a crafted video f...
CVE-2019-9706MEDIUM5.5Vixie Cron before the 3.0pl1-133 Debian package allows local users to cause a denial of service (use-after-free and daem...
CVE-2019-9705MEDIUM5.5Vixie Cron before the 3.0pl1-133 Debian package allows local users to cause a denial of service (memory consumption) via...
CVE-2019-9704MEDIUM5.5Vixie Cron before the 3.0pl1-133 Debian package allows local users to cause a denial of service (daemon crash) via a lar...
CVE-2019-1707MEDIUM5.4A vulnerability in the web-based management interface of Cisco DNA Center could allow an authenticated, remote attacker ...
CVE-2019-1702MEDIUM6.1Multiple vulnerabilities in the web-based management interface of Cisco Enterprise Chat and Email could allow an unauthe...
CVE-2019-1690MEDIUM6.5A vulnerability in the management interface of Cisco Application Policy Infrastructure Controller (APIC) software could ...

Check if your code is affected by 2019 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now