2019 CVE Vulnerabilities

17,620 CVEs published in 2019.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2019-1677MEDIUM4.6A vulnerability in Cisco Webex Meetings for Android could allow an unauthenticated, local attacker to perform a cross-si...
CVE-2019-6517MEDIUM6.8BD FACSLyric Research Use Only, Windows 10 Professional Operating System, U.S. and Malaysian Releases, between November ...
CVE-2019-3825MEDIUM6.3A vulnerability was discovered in gdm before 3.31.4. When timed login is enabled in configuration, an attacker could byp...
CVE-2019-3823MEDIUM4.3libcurl versions from 7.34.0 to before 7.64.0 are vulnerable to a heap out-of-bounds read in the code handling the end-o...
CVE-2019-3820MEDIUM4.3It was discovered that the gnome-shell lock screen since version 3.15.91 did not properly restrict all contextual action...
CVE-2019-7400MEDIUM6.1Rukovoditel before 2.4.1 allows XSS.
CVE-2019-4038MEDIUM6.2IBM Security Identity Manager 6.0 and 7.0 could allow an attacker to create unexpected control flow paths through the ap...
CVE-2019-1000020MEDIUM6.5libarchive version commit 5a98dcf8a86364b3c2c469c85b93647dfb139961 onwards (version v2.8.0 onwards) contains a CWE-835: ...
CVE-2019-1000019MEDIUM6.5libarchive version commit bf9aec176c6748f0ee7a678c5f9f9555b9a757c1 onwards (release v3.0.2 onwards) contains a CWE-125: ...
CVE-2019-7317MEDIUM5.3png_image_free in png.c in libpng 1.6.x before 1.6.37 has a use-after-free because png_image_free_function is called und...
CVE-2019-3604MEDIUM4.8Cross-Site Request Forgery (CSRF) vulnerability in McAfee ePO (legacy) Cloud allows unauthenticated users to perform uni...
CVE-2019-7282MEDIUM5.9In NetKit through 0.17, rcp.c in the rcp client allows remote rsh servers to bypass intended access restrictions via the...
CVE-2019-6111MEDIUM5.9An issue was discovered in OpenSSH 7.9. Due to the scp implementation being derived from 1983 rcp, the server chooses wh...
CVE-2019-6110MEDIUM6.8In OpenSSH 7.9, due to accepting and displaying arbitrary stderr output from the server, a malicious server (or Man-in-T...
CVE-2019-6109MEDIUM6.8An issue was discovered in OpenSSH 7.9. Due to missing character encoding in the progress display, a malicious server (o...
CVE-2019-4040MEDIUM6.1IBM I 7.2 and 7.3 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript c...
CVE-2019-3913MEDIUM4.9Command manipulation in LabKey Server Community Edition before 18.3.0-61806.763 allows an authenticated remote attacker ...
CVE-2019-3912MEDIUM6.1An open redirect vulnerability in LabKey Server Community Edition before 18.3.0-61806.763 via the /__r1/ returnURL param...
CVE-2019-3911MEDIUM6.1Reflected cross-site scripting (XSS) vulnerability in LabKey Server Community Edition before 18.3.0-61806.763 allows an ...
CVE-2019-1566MEDIUM6.1The PAN-OS management web interface in PAN-OS 7.1.21 and earlier, PAN-OS 8.0.14 and earlier, and PAN-OS 8.1.5 and earlie...
CVE-2019-7154MEDIUM6.5The main function in tools/wasm2js.cpp in Binaryen 1.38.22 has a heap-based buffer overflow because Emscripten is misuse...
CVE-2019-7153MEDIUM6.5A NULL pointer dereference was discovered in wasm::WasmBinaryBuilder::processFunctions() in wasm/wasm-binary.cpp (when c...
CVE-2019-7152MEDIUM6.5A heap-based buffer over-read was discovered in wasm::WasmBinaryBuilder::processFunctions() in wasm/wasm-binary.cpp (whe...
CVE-2019-7151MEDIUM6.5A NULL pointer dereference was discovered in wasm::Module::getFunctionOrNull in wasm/wasm.cpp in Binaryen 1.38.22. A cra...
CVE-2019-7150MEDIUM5.5An issue was discovered in elfutils 0.175. A segmentation fault can occur in the function elf64_xlatetom in libelf/elf32...

Check if your code is affected by 2019 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now