2019 CVE Vulnerabilities

17,620 CVEs published in 2019.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2019-2534HIGH7.1Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: Replication). Supported versions that...
CVE-2019-2435HIGH8.1Vulnerability in the MySQL Connectors component of Oracle MySQL (subcomponent: Connector/Python). Supported versions tha...
CVE-2019-6447HIGH8.1The ES File Explorer File Manager application through 4.1.9.7.4 for Android allows remote attackers to read arbitrary fi...
CVE-2019-0030HIGH7.2Juniper ATP uses DES and a hardcoded salt for password hashing, allowing for trivial de-hashing of the password file con...
CVE-2019-0029HIGH8.8Juniper ATP Series Splunk credentials are logged in a file readable by authenticated local users. Using these credential...
CVE-2019-0021HIGH7.1On Juniper ATP, secret passphrase CLI inputs, such as "set mcm", are logged to /var/log/syslog in clear text, allowing a...
CVE-2019-0014HIGH7.5On QFX and PTX Series, receipt of a malformed packet for J-Flow sampling might crash the FPC (Flexible PIC Concentrator)...
CVE-2019-0012HIGH7.5A Denial of Service (DoS) vulnerability in BGP in Juniper Networks Junos OS configured as a VPLS PE allows an attacker t...
CVE-2019-0010HIGH7.5An SRX Series Service Gateway configured for Unified Threat Management (UTM) may experience a system crash with the erro...
CVE-2019-0001HIGH7.5Receipt of a malformed packet on MX Series devices with dynamic vlan configuration can trigger an uncontrolled recursion...
CVE-2019-6257HIGH7.7A Server Side Request Forgery (SSRF) vulnerability in elFinder before 2.1.46 could allow a malicious user to access the ...
CVE-2019-6245HIGH8.8An issue was discovered in Anti-Grain Geometry (AGG) 2.4 as used in SVG++ (aka svgpp) 1.2.3. In the function agg::cell_a...
CVE-2019-6128HIGH8.8The TIFFFdOpen function in tif_unix.c in LibTIFF 4.0.10 has a memory leak, as demonstrated by pal2rgb.
CVE-2019-5747HIGH7.5An issue was discovered in BusyBox through 1.30.0. An out of bounds read in udhcp components (consumed by the DHCP clien...
CVE-2019-0542HIGH8.8A remote code execution vulnerability exists in Xterm.js when the component mishandles special characters, aka "Xterm Re...
CVE-2019-3581HIGH7.5Improper input validation in the proxy component of McAfee Web Gateway 7.8.2.0 and later allows remote attackers to caus...
CVE-2019-0582HIGH7.8A remote code execution vulnerability exists when the Windows Jet Database Engine improperly handles objects in memory, ...
CVE-2019-0543HIGH7.8An elevation of privilege vulnerability exists when Windows improperly handles authentication requests, aka "Microsoft W...
CVE-2019-0541HIGH8.8A remote code execution vulnerability exists in the way that the MSHTML engine inproperly validates input, aka "MSHTML E...
CVE-2019-0538HIGH7.8A remote code execution vulnerability exists when the Windows Jet Database Engine improperly handles objects in memory, ...
CVE-2019-5009HIGH7.2Vtiger CRM 7.1.0 before Hotfix2 allows uploading files with the extension "php3" in the logo upload field, if the upload...
CVE-2019-3500HIGH7.8aria2c in aria2 1.33.1, when --log is used, can store an HTTP Basic Authentication username and password in a file, whic...

Check if your code is affected by 2019 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now