2019 CVE Vulnerabilities

17,620 CVEs published in 2019.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2019-2436MEDIUM5.5Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: Replication). Supported versions that...
CVE-2019-2434MEDIUM6.5Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: Parser). Supported versions that are ...
CVE-2019-2420MEDIUM4.9Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: Optimizer). Supported versions that a...
CVE-2019-6462MEDIUM6.5An issue was discovered in cairo 1.16.0. There is an infinite loop in the function _arc_error_normalized in the file cai...
CVE-2019-6461MEDIUM6.5An issue was discovered in cairo 1.16.0. There is an assertion problem in the function _cairo_arc_in_direction in the fi...
CVE-2019-0027MEDIUM5.4A persistent cross-site scripting (XSS) vulnerability in the Snort Rules configuration of Juniper ATP may allow authenti...
CVE-2019-0026MEDIUM5.4A persistent cross-site scripting (XSS) vulnerability in the Zone configuration of Juniper ATP may allow authenticated u...
CVE-2019-0025MEDIUM5.4A persistent cross-site scripting (XSS) vulnerability in RADIUS configuration menu of Juniper ATP may allow authenticate...
CVE-2019-0024MEDIUM5.4A persistent cross-site scripting (XSS) vulnerability in the Email Collectors menu of Juniper ATP may allow authenticate...
CVE-2019-0023MEDIUM5.4A persistent cross-site scripting (XSS) vulnerability in the Golden VM menu of Juniper ATP may allow authenticated user ...
CVE-2019-0018MEDIUM5.4A persistent cross-site scripting (XSS) vulnerability in the file upload menu of Juniper ATP may allow an authenticated ...
CVE-2019-0017MEDIUM6.5The Junos Space application, which allows Device Image files to be uploaded, has insufficient validity checking which ma...
CVE-2019-0016MEDIUM6.5A malicious authenticated user may be able to delete a device from the Junos Space database without the necessary privil...
CVE-2019-0015MEDIUM5.4A vulnerability in the SRX Series Service Gateway allows deleted dynamic VPN users to establish dynamic VPN connections ...
CVE-2019-0013MEDIUM6.5The routing protocol daemon (RPD) process will crash and restart when a specific invalid IPv4 PIM Join packet is receive...
CVE-2019-0011MEDIUM6.5The Junos OS kernel crashes after processing a specific incoming packet to the out of band management interface (such as...
CVE-2019-0009MEDIUM5.5On EX2300 and EX3400 series, high disk I/O operations may disrupt the communication between the routing engine (RE) and ...
CVE-2019-0005MEDIUM5.3On EX2300, EX3400, EX4600, QFX3K and QFX5K series, firewall filter configuration cannot perform packet matching on any I...
CVE-2019-0004MEDIUM5.5On Juniper ATP, the API key and the device key are logged in a file readable by authenticated local users. These keys ar...
CVE-2019-0003MEDIUM5.9When a specific BGP flowspec configuration is enabled and upon receipt of a specific matching BGP packet meeting a speci...
CVE-2019-3811MEDIUM5.2A vulnerability was found in sssd. If a user was configured with no home directory set, sssd would return '/' (the root ...
CVE-2019-6284MEDIUM6.5In LibSass 3.5.5, a heap-based buffer over-read exists in Sass::Prelexer::alternatives in prelexer.hpp.
CVE-2019-6283MEDIUM6.5In LibSass 3.5.5, a heap-based buffer over-read exists in Sass::Prelexer::parenthese_scope in prelexer.hpp.
CVE-2019-3803MEDIUM4.5Pivotal Concourse, all versions prior to 4.2.2, puts the user access token in a url during the login flow. A remote atta...
CVE-2019-6129MEDIUM6.5png_create_info_struct in png.c in libpng 1.6.36 has a memory leak, as demonstrated by pngcp. NOTE: a third party has st...

Check if your code is affected by 2019 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now