2019 CVE Vulnerabilities

17,620 CVEs published in 2019.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2019-1683HIGH7.4A vulnerability in the certificate handling component of the Cisco SPA112, SPA525, and SPA5X5 Series IP Phones could all...
CVE-2019-9126HIGH7.5An issue was discovered on D-Link DIR-825 Rev.B 2.10 devices. There is an information disclosure vulnerability via reque...
CVE-2019-9122HIGH8.8An issue was discovered on D-Link DIR-825 Rev.B 2.10 devices. They allow remote attackers to execute arbitrary commands ...
CVE-2019-9082HIGH8.8ThinkPHP before 3.2.4, as used in Open Source BMS v1.1.1 and other products, allows Remote Command Execution via public/...
CVE-2019-9077HIGH7.8An issue was discovered in GNU Binutils 2.32. It is a heap-based buffer overflow in process_mips_specific in readelf.c v...
CVE-2019-9075HIGH7.8An issue was discovered in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.32. I...
CVE-2019-9070HIGH7.8An issue was discovered in GNU libiberty, as distributed in GNU Binutils 2.32. It is a heap-based buffer over-read in d_...
CVE-2019-9003HIGH7.5In the Linux kernel before 4.20.5, attackers can trigger a drivers/char/ipmi/ipmi_msghandler.c use-after-free and OOPS b...
CVE-2019-6340HIGH8.1Some field types do not properly sanitize data from non-form sources in Drupal 8.5.x before 8.5.11 and Drupal 8.6.x befo...
CVE-2019-1681HIGH7.5A vulnerability in the TFTP service of Cisco Network Convergence System 1000 Series software could allow an unauthentica...
CVE-2019-1664HIGH7.8A vulnerability in the hxterm service of Cisco HyperFlex Software could allow an unauthenticated, local attacker to gain...
CVE-2019-1662HIGH8.2A vulnerability in the Quality of Voice Reporting (QOVR) service of Cisco Prime Collaboration Assurance (PCA) Software c...
CVE-2019-1659HIGH7.4A vulnerability in the Identity Services Engine (ISE) integration feature of Cisco Prime Infrastructure (PI) could allow...
CVE-2019-8980HIGH7.5A memory leak in the kernel_read_file function in fs/exec.c in the Linux kernel through 4.20.11 allows attackers to caus...
CVE-2019-3475HIGH7.8A local privilege escalation vulnerability in the famtd component of Micro Focus Filr 3.0 allows a local attacker authen...
CVE-2019-1003025HIGH8.8A exposure of sensitive information vulnerability exists in Jenkins Cloud Foundry Plugin 2.3.1 and earlier in AbstractCl...
CVE-2019-1003024HIGH8.8A sandbox bypass vulnerability exists in Jenkins Script Security Plugin 1.52 and earlier in RejectASTTransformsCustomize...
CVE-2019-3924HIGH7.5MikroTik RouterOS before 6.43.12 (stable) and 6.42.12 (long-term) is vulnerable to an intermediary vulnerability. The so...
CVE-2019-8912HIGH7.8In the Linux kernel through 4.20.11, af_alg_release() in crypto/af_alg.c neglects to set a NULL value for a certain stru...
CVE-2019-8389HIGH8.1A file-read vulnerability was identified in the Wi-Fi transfer feature of Musicloud 1.6. By default, the application run...
CVE-2019-8383HIGH7.8An issue was discovered in AdvanceCOMP through 2.1. An invalid memory address occurs in the function adv_png_unfilter_8 ...
CVE-2019-8381HIGH7.8An issue was discovered in Tcpreplay 4.3.1. An invalid memory access occurs in do_checksum in checksum.c. It can be trig...
CVE-2019-8379HIGH7.8An issue was discovered in AdvanceCOMP through 2.1. A NULL pointer dereference exists in the function be_uint32_read() l...
CVE-2019-8377HIGH7.8An issue was discovered in Tcpreplay 4.3.1. A NULL pointer dereference occurred in the function get_ipv6_l4proto() locat...
CVE-2019-8376HIGH7.8An issue was discovered in Tcpreplay 4.3.1. A NULL pointer dereference occurred in the function get_layer4_v6() located ...

Check if your code is affected by 2019 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now