2019 CVE Vulnerabilities

17,620 CVEs published in 2019.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2019-3804HIGH7.5It was found that cockpit before version 184 used glib's base64 decode functionality incorrectly resulting in a denial o...
CVE-2019-3606HIGH7.7Data Leakage Attacks vulnerability in the web portal component when in an MDR pair in McAfee Network Security Management...
CVE-2019-9061HIGH8.8An issue was discovered in CMS Made Simple 2.2.8. In the module ModuleManager (in the file action.installmodule.php), it...
CVE-2019-9058HIGH7.2An issue was discovered in CMS Made Simple 2.2.8. In the administrator page admin/changegroupperm.php, it is possible to...
CVE-2019-9057HIGH8.8An issue was discovered in CMS Made Simple 2.2.8. In the module FilePicker, it is possible to reach an unserialize call ...
CVE-2019-7642HIGH7.5D-Link routers with the mydlink feature have some web interfaces without authentication requirements. An attacker can re...
CVE-2019-0204HIGH7.8A specifically crafted Docker image running under the root user can overwrite the init helper binary of the container ru...
CVE-2019-7613HIGH7.5Winlogbeat versions before 5.6.16 and 6.6.2 had an insufficient logging flaw. An attacker able to inject certain charact...
CVE-2019-7611HIGH8.1A permission issue was found in Elasticsearch versions before 5.6.15 and 6.6.1 when Field Level Security and Document Le...
CVE-2019-4046HIGH7.5IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 is vulnerable to a denial of service, caused by improper handlin...
CVE-2019-3879HIGH8.1It was discovered that in the ovirt's REST API before version 4.3.2.1, RemoveDiskCommand is triggered as an internal com...
CVE-2019-3857HIGH8.8An integer overflow flaw which could lead to an out of bounds write was discovered in libssh2 before 1.8.1 in the way SS...
CVE-2019-3856HIGH8.8An integer overflow flaw, which could lead to an out of bounds write, was discovered in libssh2 before 1.8.1 in the way ...
CVE-2019-10012HIGH7.5Jenzabar JICS (aka Internet Campus Solution) before 9 allows remote attackers to upload and execute arbitrary .aspx code...
CVE-2019-3863HIGH7.5A flaw was found in libssh2 before 1.8.1 creating a vulnerability on the SSH client side. A server could send a multiple...
CVE-2019-3841HIGH7.4Kubevirt/virt-cdi-importer, versions 1.4.0 to 1.5.3 inclusive, were reported to disable TLS certificate validation when ...
CVE-2019-3827HIGH7An incorrect permission check in the admin backend in gvfs before version 1.39.4 was found that allows reading and modif...
CVE-2019-1766HIGH7.5A vulnerability in the web-based management interface of Session Initiation Protocol (SIP) Software for Cisco IP Phone 8...
CVE-2019-1765HIGH8.1A vulnerability in the web-based management interface of Session Initiation Protocol (SIP) Software for Cisco IP Phone 8...
CVE-2019-1764HIGH8.1A vulnerability in the web-based management interface of Session Initiation Protocol (SIP) Software for Cisco IP Phone 8...
CVE-2019-1763HIGH7.5A vulnerability in the web-based management interface of Session Initiation Protocol (SIP) Software for Cisco IP Phone 8...
CVE-2019-1716HIGH7.5A vulnerability in the web-based management interface of Session Initiation Protocol (SIP) Software for Cisco IP Phone 7...
CVE-2019-4052HIGH7.5IBM API Connect 2018.1 and 2018.4.1.2 apis can be leveraged by unauthenticated users to discover login ids of registered...
CVE-2019-9924HIGH7.8rbash in Bash before 4.4-beta2 did not prevent the shell user from modifying BASH_CMDS, thus allowing the user to execut...
CVE-2019-9923HIGH7.5pax_decode_header in sparse.c in GNU Tar before 1.32 had a NULL pointer dereference when parsing certain archives that h...

Check if your code is affected by 2019 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now