2019 CVE Vulnerabilities

17,619 CVEs published in 2019.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2019-20444CRITICAL9.1HttpObjectDecoder.java in Netty before 4.1.44 allows an HTTP header that lacks a colon, which might be interpreted as a ...
CVE-2019-20217CRITICAL9.8D-Link DIR-859 1.05 and 1.06B01 Beta01 devices allow remote attackers to execute arbitrary OS commands via the urn: to t...
CVE-2019-20216CRITICAL9.8D-Link DIR-859 1.05 and 1.06B01 Beta01 devices allow remote attackers to execute arbitrary OS commands via the urn: to t...
CVE-2019-20215CRITICAL9.8D-Link DIR-859 1.05 and 1.06B01 Beta01 devices allow remote attackers to execute arbitrary OS commands via a urn: to the...
CVE-2019-5464CRITICAL9.8A flawed DNS rebinding protection issue was discovered in GitLab CE/EE 10.2 and later in the `url_blocker.rb` which coul...
CVE-2019-15585CRITICAL9.8Improper authentication exists in < 12.3.2, < 12.2.6, and < 12.1.12 for GitLab Community Edition (CE) and Enterprise Edi...
CVE-2019-8257CRITICAL9.8Adobe Acrobat and Reader versions 2019.012.20035 and earlier, 2019.012.20035 and earlier, 2017.011.30142 and earlier, 20...
CVE-2019-7131CRITICAL9.8Adobe Acrobat and Reader versions 2019.010.20064 and earlier, 2019.010.20064 and earlier, 2017.011.30110 and earlier ver...
CVE-2019-17095CRITICAL9.8A command injection vulnerability has been discovered in the bootstrap stage of Bitdefender BOX 2, versions 2.1.47.42 an...
CVE-2019-19825CRITICAL9.8On certain TOTOLINK Realtek SDK based routers, the CAPTCHA text can be retrieved via an {"topicurl":"setting/getSanvas"}...
CVE-2019-17096CRITICAL9.8A OS Command Injection vulnerability in the bootstrap stage of Bitdefender BOX 2 allows the manipulation of the `get_ima...
CVE-2019-20433CRITICAL9.1libaspell.a in GNU Aspell before 0.60.8 has a buffer over-read for a string ending with a single '\0' byte, if the encod...
CVE-2019-20427CRITICAL9.8In the Lustre file system before 2.12.3, the ptlrpc module has a buffer overflow and panic, and possibly remote code exe...
CVE-2019-16029CRITICAL9.1A vulnerability in the application programming interface (API) of Cisco Smart Software Manager On-Prem could allow an un...
CVE-2019-5183CRITICAL9An exploitable type confusion vulnerability exists in AMD ATIDXX64.DLL driver, versions 26.20.13031.10003, 26.20.13031.1...
CVE-2019-1353CRITICAL9.8An issue was found in Git before v2.24.1, v2.23.1, v2.22.2, v2.21.1, v2.20.2, v2.19.3, v2.18.2, v2.17.3, v2.16.6, v2.15....
CVE-2019-17570CRITICAL9.8An untrusted deserialization was found in the org.apache.xmlrpc.parser.XmlRpcResponseParser:addResult method of Apache X...
CVE-2019-19897CRITICAL9.8In IXP EasyInstall 6.2.13723, there is Remote Code Execution via the Agent Service. An unauthenticated attacker can comm...
CVE-2019-19896CRITICAL9.9In IXP EasyInstall 6.2.13723, there is Remote Code Execution via weak permissions on the Engine Service share. The defau...
CVE-2019-16517CRITICAL9.8An issue was discovered in ConnectWise Control (formerly known as ScreenConnect) 19.3.25270.7185. There is a CORS miscon...
CVE-2019-16153CRITICAL9.8A hard-coded password vulnerability in the Fortinet FortiSIEM database component version 5.2.5 and below may allow attac...
CVE-2019-19839CRITICAL9.8emfd in Ruckus Wireless Unleashed through 200.7.10.102.64 allows remote attackers to execute OS commands via a POST requ...
CVE-2019-19838CRITICAL9.8emfd in Ruckus Wireless Unleashed through 200.7.10.102.64 allows remote attackers to execute OS commands via a POST requ...
CVE-2019-19842CRITICAL9.8emfd in Ruckus Wireless Unleashed through 200.7.10.102.64 allows remote attackers to execute OS commands via a POST requ...
CVE-2019-19841CRITICAL9.8emfd in Ruckus Wireless Unleashed through 200.7.10.102.64 allows remote attackers to execute OS commands via a POST requ...

Check if your code is affected by 2019 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now